Product placement across the whole stack, read bottom-up: OT buses and PLCs at the base, through the air gap, into enterprise IT, out to the internet and cloud. Each network is drawn as one L2 segment; the spine on the left is how they interconnect. Click any product for what it is and why it sits there — and to highlight it everywhere it appears.
Where the agents actually sit
The same host stack twice — a virtualised server and a user workstation — opened up. Highlighted rows are where a Yellow Cube component is installed or where telemetry is taken. The workstation carries the full agent; the server carries it per guest, never on the hypervisor fabric.
{{ sel.what }}
Architecture Map
Purdue L5 · Cloud & Internet
SaaS tenants, public cloud and the mobile fleet that never touches the office LAN.
- Cloud posture (CSPM)
- WithSecure Elements Cloud Security or Cynet AutoXDR CSPM or Stellar Cyber Cloud Sensors or OPSWAT MetaDefender Cloud
- Identity & MFA
- Imprivata SSO + MFA or Microsoft Entra ID or Google Workspace identity
- Supply chain integrity
- OPSWAT Software Supply Chain or Cymulate Exposure Validation or Group-IB Attack Surface Management
- Mobile devices
- iVerify Mobile EDR or WithSecure Elements Mobile Protection
- Cloud mailbox
- IronScales Email detection & response + MailStore Email archive
Boundary · Internet perimeter
- DDoS & edge
- A10 Networks Thunder TPS
- Perimeter firewall
- Stormshield SNS firewall
- DNS security
- Whalebone DNS security
Purdue L4 · DMZ · IT DMZ
Published, internet-facing services. The office endpoint stack plus edge and identity controls.
- WAF + load balancer
- A10 Networks Thunder ADC + WAF
- Identity security (ITDR)
- Varonis ITDR or Imprivata PAM
- Agent on published servers
- Cynet AutoXDR agent or WithSecure Elements EDR or Group-IB Managed XDR or Stellar Cyber Server Sensor
- File uploads in
- OPSWAT MetaDefender ICAP Server or OPSWAT MetaDefender Core
Boundary · Internal segmentation
- DMZ ↔ office firewall
- Stormshield SNS firewall
- DNS security
- Whalebone DNS security
Purdue L4 · Office network
One L2 office network: servers, workstations, the SPAN port and the log path out to the SOC.
- Endpoint agent — servers & workstations
- Cynet AutoXDR agent or WithSecure Elements EDR or Group-IB Managed XDR
- NDR sensor on SPAN / TAP
- Stellar Cyber NDR sensor or Group-IB Network Traffic Analysis or OPSWAT MetaDefender NDR
- Log collection → SOC
- Stellar Cyber Open XDR platform or Cynet AutoXDR agent
- Patch & vulnerability management
- WithSecure Elements or Cynet AutoXDR agent
- Endpoint security posture (ESPM)
- WithSecure Elements or Cynet AutoXDR agent
- Data & insider risk
- Varonis Data Detection & Response or Teramind Insider threat management
Purdue L3.5 · Air gap
Electronic or optical separation. Telemetry leaves OT northbound; nothing routes back in.
- One-way transfer
- OPSWAT NetWall Unidirectional Gateway or Waterfall Security Unidirectional Security Gateway
- Media & contractor laptops
- OPSWAT MetaDefender Kiosk + OPSWAT MetaDefender Drive or OPSWAT Managed File Transfer
Purdue L3–L2 · OT control network
SCADA, historians, HMIs and engineering workstations. Windows hosts here still take an agent — where the OEM allows it.
- Industrial firewall — zone control
- Stormshield SNS industrial firewall or OPSWAT Industrial Firewall
- Agent on HMI / engineering WS
- Cynet AutoXDR agent or WithSecure Elements EDR or OPSWAT MetaDefender Endpoint
- OT asset visibility
- OPSWAT MetaDefender OT Security or OPSWAT MetaDefender NDR
- Vendor remote access
- OPSWAT MetaDefender OT Access or Imprivata PAM
Boundary · Cell segmentation
- Control ↔ bus
- Stormshield SNS industrial firewall
Purdue L1–L0 · OT bus / PLC network
Fieldbus and controllers. Nothing is installed down here — protection is in-line and transparent.
- In front of the PLC
- OPSWAT Industrial Firewall or Stormshield SNS industrial firewall
- Field devices
- By design No agent possible
Cross-cutting
Yellow Cube 24×7 Managed SOC + Cymulate Exposure Validation + CYBER RANGES Cyber range training
WithSecure Elements Cloud Security
CSPM
Continuous posture and misconfiguration checks across M365, Entra, Azure and AWS — in the same console as the endpoint agents below.
SaaS. No in-network component.
OPSWAT MetaDefender Cloud
Cloud file analysis
Multiscanning, Deep CDR and sandboxing offered as a cloud API for files entering the organisation.
SaaS API, called by apps and gateways.
Stellar Cyber Cloud Sensors
Cloud telemetry
Pulls cloud audit, identity and SaaS logs into the Open XDR data lake so cloud events correlate with network and endpoint events.
Cloud tenant + on-prem collector.
Stellar Cyber Server Sensor
Host telemetry sensor
Software sensor for supported Windows and Linux servers, forwarding system events and host telemetry as Interflow so Open XDR can correlate activity with the rest of the stack.
Agent on each published server in the IT DMZ.
Imprivata SSO + MFA
Identity & access
Single sign-on, badge tap and MFA built for shared workstations and shift work — clinical, shopfloor and control-room patterns included.
Cloud identity service + endpoint client.
OPSWAT Software Supply Chain
Supply chain integrity
SBOM generation, vendor package scanning and sanitisation before third-party software, updates or firmware are accepted into the estate.
Release gate / CI pipeline.
Cymulate Exposure Validation
Security validation
Safely attacks your own controls to prove the stack blocks what it claims — per zone, including the OT boundary.
Light agents across zones.
Group-IB Attack Surface Management
External exposure & supply chain
Continuously maps what you expose to the internet — shadow assets, exposed services, leaked credentials and the third parties in your supply chain — and scores what to fix first.
External, nothing to install.
Microsoft Entra ID
Identity provider
The identity platform most customers already run. It issues the tokens everything above trusts — our identity products layer on top of it, they do not replace it.
Cloud identity provider.
The customer's own platform — not supplied by Yellow Cube.
Google Workspace identity
Identity provider
The Google-side equivalent: the directory and token issuer the rest of the stack authenticates against.
Cloud identity provider.
The customer's own platform — not supplied by Yellow Cube.
iVerify Mobile EDR
Mobile defence
Detects mercenary spyware, jailbreaks, malicious profiles and configuration drift on iOS and Android — real detection, not just MDM compliance.
App on the device. No network position.
WithSecure Elements Mobile Protection
Mobile AV
Malware, phishing and browsing protection for managed phones and tablets, reported in the same Elements console as the desktops.
App on the device.
Whalebone DNS security
DNS filtering
Resolver-level blocking of phishing, malware and C2 domains. Covers guests, IoT and anything you cannot install software on.
Network resolver, or roaming client on mobiles.
IronScales Email detection & response
Email security
Post-delivery phishing detection and one-click remediation inside M365 or Google, with user reporting that trains the model.
API-integrated with the mailbox — no MX change.
MailStore Email archive
Retention & evidence
Tamper-proof journal archive of every mail — legal hold, e-discovery and the evidence trail auditors ask for.
Server in the office network.
A10 Networks Thunder ADC + WAF
Load balancer + web app firewall
Terminates TLS and balances published services, then enforces OWASP-class protection, bot defence and API guardrails on the same appliance — one insertion point for the WAF policy and for full-visibility decryption.
DMZ, in-line in front of the web tier.
A10 Networks Thunder TPS
DDoS mitigation
Volumetric and application-layer DDoS scrubbing at the internet edge, before the firewall's state table becomes the bottleneck.
Internet perimeter, in-line or on-demand.
Stormshield SNS firewall
NGFW
Perimeter and internal segmentation with IPS and application control — the same policy engine as the industrial SNi40 further down, managed together.
Internet perimeter and between internal zones.
Varonis ITDR
Identity threat detection
Watches Active Directory and Entra for privilege abuse, Kerberos attacks, stale admin paths and the blast radius each account carries.
Collector in the DMZ or office network.
Imprivata PAM
PAM
Vaults credentials and records privileged sessions to servers, jump hosts and OT assets — the audit trail for who did what.
Jump host in the DMZ.
Cynet AutoXDR agent
EDR / XDR agent
One agent covering NGAV, EDR, deception and automated response, with a 24×7 MDR team behind it. The pragmatic default where the security team is small.
Installed on every Windows, Linux and macOS host.
WithSecure Elements EDR
EDR agent
Endpoint detection and response with Elevate-to-expert escalation. Same agent family as the mobile and cloud modules — one vendor across three layers.
Installed on every server and workstation.
Group-IB Managed XDR
Managed XDR
Agent plus network sensors driven by Group-IB's own threat intelligence and incident-response practice. Strong where attribution and IR matter.
Agent on hosts + sensor on the network.
OPSWAT MetaDefender ICAP Server
Upload inspection
Every file uploaded through the reverse proxy is multiscanned and sanitised with Deep CDR before it reaches the application.
DMZ, beside the load balancer.
OPSWAT MetaDefender Core
File sanitisation engine
The scanning and Deep CDR engine that ICAP, managed file transfer and the Kiosks all call. Deploy once, reuse at every file entry point.
Server in the DMZ or office network.
Stellar Cyber NDR sensor
NDR
Passive sensor on a SPAN or TAP: east-west traffic, lateral movement and the unmanaged assets no agent will ever report.
SPAN/TAP port on the core switch.
Group-IB Network Traffic Analysis
NDR
Traffic analysis with in-line file detonation, tied to Group-IB intelligence on the actors targeting your sector.
SPAN/TAP, plus a copy of mail flow.
OPSWAT MetaDefender NDR
NDR
Network detection tuned for converged IT/OT traffic — understands industrial protocols as well as enterprise ones.
SPAN/TAP on either side of the boundary.
Stellar Cyber Open XDR platform
Log collection & correlation
Collects logs from every layer of this diagram, normalises them and does the correlation the SOC actually works from — vendor-agnostic by design.
Collector on-prem, platform in the cloud.
Varonis Data Detection & Response
Data security
Finds the sensitive data, fixes over-broad permissions, and alerts on abnormal access to file shares, SharePoint and mail.
Collector next to the file and mail servers.
Teramind Insider threat management
Insider risk & DLP
User activity monitoring, session recording and DLP for the accounts that already hold legitimate access.
Agent on workstations and terminal servers.
Stormshield SNS industrial firewall
OT firewall
The SNi range of ruggedised industrial firewalls — DIN-rail and rack models with protocol IPS and hardware bypass, sized to the cell rather than to one fixed appliance.
Between control zones, cells and machines.
OPSWAT Industrial Firewall
OT firewall / IPS
Learning mode records the normal traffic pattern, then enforces it — protocol-specific DPI for Modbus TCP, S7, DNP3, EtherNet/IP and BACnet. Designed to sit between Purdue L2 and L3.5.
In front of a cell, a machine or a single PLC.
OPSWAT MetaDefender OT Security
OT asset visibility
Passive and safe active discovery of every OT asset, its firmware level and its known vulnerabilities — the inventory the risk assessment needs.
Sensor in the control network.
OPSWAT MetaDefender OT Access
Secure remote access
Brokered, time-boxed and session-recorded vendor access to OT assets — without a VPN tunnel into the control network.
Broker at the IT/OT edge.
OPSWAT MetaDefender Endpoint
Posture & AV for OT hosts
Lightweight posture, patch and malware checks for hosts where the OEM will not certify a full EDR agent.
HMI and engineering workstations.
OPSWAT NetWall Unidirectional Gateway
Unidirectional gateway
One-way gateway with protocol emulation, so historians, OPC servers and file shares replicate northbound as if the link were bidirectional.
L3.5, paired appliances.
Waterfall Security Unidirectional Security Gateway
Unidirectional gateway
Hardware-enforced one-way replication with a long track record in energy and water, and the regulator familiarity that comes with it.
L3.5, paired appliances.
The customer's own platform — not supplied by Yellow Cube.
OPSWAT MetaDefender Kiosk
Removable media control
The airlock door: every USB stick and contractor file is scanned and sanitised at the kiosk before it is released into the OT side.
Physically at the entrance to the OT area.
OPSWAT Managed File Transfer
Controlled file entry
The supervised path for files that must cross the boundary — scanned, sanitised, approved and logged, with no shared drive in between.
Either side of the air gap.
OPSWAT MetaDefender Drive
Offline device inspection
Boots a contractor laptop or commissioning machine from a trusted drive and scans it offline, before it ever joins the OT network.
Portable, used at the air gap.
CYBER RANGES Cyber range training
Skills & exercises
Live-fire exercises on realistic IT and OT scenarios — the way a blue team learns this diagram under pressure.
Hosted platform.
Yellow Cube 24×7 Managed SOC
Managed detection & response
The team that watches everything above out of hours, across IT and OT, on the telemetry the agents and sensors here produce.
Yellow Cube SOC, fed by the collectors.
Cynet AutoXDR CSPM
Cloud posture
Cloud security posture management inside the same AutoXDR console as the endpoint agents — misconfigurations, exposed storage and identity drift in one place.
Agentless, connected to the cloud tenant.
WithSecure Elements
Endpoint posture, patching & vulnerability management
One agent and one console for endpoint protection, third-party patching and vulnerability management, with posture scoring across the estate.
Servers and workstations on the office network.
By design No agent possible
Field devices
PLCs, RTUs, drives and sensors cannot run security agents. Everything protecting them is in-line, transparent and upstream — which is why the firewall in front of the cell matters so much.
Purdue L0–L1.
FAQ
01 Where does each Yellow Cube product sit in the Purdue model? +
Yellow Cube places its portfolio across the whole stack, read bottom-up: Purdue L1–L0 is the OT bus, carrying PLCs, RTUs, drives and sensors; L3–L2 is the OT control network with SCADA, historians, HMIs and engineering workstations; L3.5 is the air gap; L4 covers the office network and the IT DMZ; L5 is cloud, SaaS and the mobile fleet. Firewall boundaries sit between them — internet perimeter, internal segmentation and cell segmentation.Every network is drawn as a single L2 segment with its hosts hanging off it, so what you are reading is a network position, not a product category.
02 How does Yellow Cube protect Purdue L0–L1 devices that cannot run a security agent? +
Protection for PLCs, RTUs, drives and sensors that cannot run a security agent is placed in the network, upstream of those devices.In practice that means an industrial firewall in front of the cell, the machine or the individual PLC: OPSWAT's Industrial Firewall, which learns the normal traffic pattern and then enforces it with protocol-specific inspection for Modbus TCP, S7, DNP3, EtherNet/IP and BACnet, or Stormshield's ruggedised SNi range on DIN rail with hardware bypass. That is exactly why the firewall in front of the cell carries so much of the weight at this level.
03 How does telemetry cross the air gap without opening a route back into OT? +
At Purdue L3.5 the path is deliberately one-way. The primary option is OPSWAT's NetWall Unidirectional Gateway, a paired-appliance gateway with protocol emulation so historians, OPC servers and file shares replicate northbound as if the link were bidirectional — telemetry leaves OT, and nothing routes back in.Waterfall Security's Unidirectional Security Gateway appears as an equivalent where a regulator already expects it, though that is the customer's own platform rather than part of the Yellow Cube portfolio. Removable media and contractor laptops take a different route entirely: a MetaDefender Kiosk acts as the airlock door, scanning and sanitising every USB stick and file before it is released into the OT side.
04 Do we have to replace the customer's existing identity provider or firewalls? +
No. The dashed boxes in this architecture are third-party platforms most estates already run — Microsoft Entra ID or Google Workspace as the identity provider, for example — and they are explicitly not supplied by Yellow Cube. Yellow Cube's identity products layer on top of the provider the customer already has rather than replacing it, because that platform issues the tokens everything else trusts.Where two products are joined by “or”, they are equivalent options for the same position: choose one, do not stack both.
05 What in the portfolio covers the whole stack rather than one Purdue level? +
Three things are cross-cutting rather than tied to a single level. Yellow Cube's own 24×7 Managed SOC watches IT and OT out of hours, working from the telemetry that the agents and sensors in this architecture produce. Cymulate Exposure Validation safely attacks the deployed controls to prove each zone blocks what it claims, including the OT boundary.CYBER RANGES adds live-fire exercises on realistic IT and OT scenarios, so a blue team learns this architecture under pressure rather than during an incident.
Let’s Build Smarter Cyber Defenses Together
Partnerships are the foundation of everything we do — built on trust, expertise, and shared success. Whether you’re looking to grow your business, strengthen your cybersecurity offerings, or bring innovative solutions to new markets, Yellow Cube is ready to be your committed, long-term ally.
Get in touch with Yellow Cube