What is OT cybersecurity?
OT cybersecurity protects operational technology environments — industrial control systems, PLCs, SCADA and plant networks — from cyber threats while preserving operational and safety requirements. CyberDragon treats OT as first-class: passive capture at the industrial DMZ, protocol-native parsing, and correlation with enterprise identity events.
How does passive OT monitoring work?
CyberDragon Edge uses SPAN/TAP or mirror-port capture with libpcap — it observes Modbus, DNP3, OPC-UA and MQTT traffic without injecting packets or installing agents on controllers. Events buffer locally when links fail, then transport securely to Core for correlation and evidence.
What is OT SIEM?
OT SIEM correlates industrial protocol events, zone policy and enterprise telemetry in timelines meaningful to both SOC analysts and plant engineers — not flat syslog tags. CyberDragon’s indigenous SIEM/SOAR plane includes kill-chain windows, MITRE ATT&CK and ICS ATT&CK mapping, and OT safety guardrails on response workflows.
How does enterprise-to-OT detection work?
When identity or endpoint compromise precedes plant-floor protocol abuse, CyberDragon signals an explicit Enterprise→OT pivot — linking corporate campaigns to Modbus writes, DNP3 commands or OPC-UA session changes in cascading W15 / W60 / W24 correlation windows.
What OT protocols are supported?
Modbus TCP/RTU, DNP3, OPC-UA and MQTT at the Edge, deployed at IEC 62443 Level 3 / industrial DMZ. See the OT-native capture page for parser behavior, limitations and deployment diagrams.
What is IEC 62443?
IEC 62443 is the international standard for industrial automation and control system security, organized by zones, conduits and system requirements (SR). CyberDragon maps live events to SR controls and exports evidence — alignment support, not a claim that your site is certified.
What is post-quantum cryptography (PQC)?
PQC refers to cryptographic algorithms designed to resist attacks from cryptographically relevant quantum computers. CyberDragon ships hybrid ML-DSA-65 + Ed25519 JWTs today for sessions, API calls and Edge→Core transport — Vault-backed signing material, live in production tenants.
What is ML-DSA?
ML-DSA (Module-Lattice-Based Digital Signature Algorithm) is the NIST FIPS 204 standard derived from CRYSTALS-Dilithium. CyberDragon uses ML-DSA-65 alongside Ed25519 in hybrid tokens so operators retain a quantum-resistant signature path without a future migration project.
How does Threat Atlas work?
Threat Atlas aggregates public IoT/ICS advisories, malware context and vulnerability feeds into operator-facing boards — threat, malware and ICS views — so analysts contextualize plant risk alongside SIEM/SOAR incidents. It is an awareness layer; volumetric series follow public source cadence.
How does CyberDragon handle threat intelligence?
In-flight enrichment from OTX, Abuse.ch, ThreatFox, MITRE TAXII, GreyNoise and mirrored NVD/CISA KEV/OSV corpora — correlated to OT events before analysts triage. Feeds are configurable; air-gapped tenants can operate from offline mirrors.