Cybersecurity Architecture

Where each Yellow Cube product sits on the network — from the OT bus and PLCs, through the air gap, into enterprise IT, cloud and internet. Pairs with our Product Matrix, which weighs the same portfolio by contribution to your security posture. Click any product below for what it is and why it sits there. Dashed boxes are third-party platforms already common in the estate (identity providers, etc.) — not part of the Yellow Cube portfolio.

Purdue Model — What Goes Where

Product placement across the whole stack, read bottom-up: OT buses and PLCs at the base, through the air gap, into enterprise IT, out to the internet and cloud. Each network is drawn as one L2 segment; the spine on the left is how they interconnect. Click any product for what it is and why it sits there — and to highlight it everywhere it appears.

Yellow Cube portfolio
Your existing provider — not ours
or Equivalent options — choose one
L2 segment · hosts hang off it
Routed north ↑
{{ row.level }}
{{ row.domain }}
{{ row.icon }}
{{ row.name }}
{{ row.note }}
{{ row.busLabel }}
{{ h.icon }}{{ h.name }}
{{ slot.icon }}
{{ slot.label }}
{{ slot.choiceNote }}
{{ it.sep }}
{{ row.icon }}
{{ row.level }}
{{ row.name }}
{{ row.note }}
{{ slot.icon }}
{{ slot.label }}
{{ slot.choiceNote }}
{{ it.sep }}
Across every layer
Cutout · L4 Office network

Where the agents actually sit

The same host stack twice — a virtualised server and a user workstation — opened up. Highlighted rows are where a Yellow Cube component is installed or where telemetry is taken. The workstation carries the full agent; the server carries it per guest, never on the hypervisor fabric.

{{ iconServer }}
IT server (virtualised)
Rack
HW
Server hardware · NIC · BMC
Virt
Hypervisor · vSwitch — no agent on the fabric
Kernel
Guest OS kernel — EDR kernel driver / ETW hooks
OS
OS services — EDR/XDR agent + log forwarder
Apps
App · DB · file shares — Varonis reads the shares
{{ iconUp }}Agent telemetry and syslog leave to the XDR collector, then the 24×7 SOC.
{{ iconTap }}Switch SPAN mirrors this host's traffic to the NDR sensor — nothing installed for it.
{{ iconMonitor }}
IT workstation
Desk
HW
Laptop · TPM · USB ports
Kernel
Windows kernel — EDR driver + USB device control
OS
OS services — EDR/XDR agent, insider-risk agent, DNS client
Apps
Browser · mail client · line-of-business apps
User
Sign-in — SSO, MFA, badge tap
{{ iconUp2 }}Same agent, same console as the server — one policy, two host classes.
{{ iconTap2 }}DNS is filtered at the resolver before the packet leaves the segment.
Server NIC
Workstation NIC
{{ iconNet }}
The wire between them
L2 segment
Switch
Core switch — SPAN / mirror port or in-line TAP
Mirrored copy
NDR sensor — a copy of the traffic, nothing installed
{{ s.sep }}
{{ iconTap3 }}The sensor is passive: it never sits in the path, so it cannot drop a packet or stop a line.
Both feeds land in the same XDR case: the agent says what ran on the host, the sensor says what crossed the wire. The SOC needs both to close a case.
{{ iconEye2 }}
The gap the agents leave
{{ b.t }}
Purdue levels are indicative — real zone boundaries follow the customer's segmentation, not the model.
Yellow Cube Cyberdefense · Full product matrix
{{ sel.vendor }}
{{ sel.name }}
{{ sel.icon }} {{ sel.cat }}

{{ sel.what }}

Sits at
{{ sel.where }}
Highlighted at
{{ sel.zones }}
Complementary vendor — not part of the Yellow Cube portfolio.
Vendor site ↗

From the PLC to the cloud — Yellow Cube secures every level of the Purdue model with one specialist vendor per domain, so your network architecture decides where the controls belong, not a vendor’s product catalogue.

FAQ

Where does each Yellow Cube product sit in the Purdue model?

Yellow Cube places its portfolio across the whole stack, read bottom-up: Purdue L1–L0 is the OT bus, carrying PLCs, RTUs, drives and sensors; L3–L2 is the OT control network with SCADA, historians, HMIs and engineering workstations; L3.5 is the air gap; L4 covers the office network and the IT DMZ; L5 is cloud, SaaS and the mobile fleet. Firewall boundaries sit between them — internet perimeter, internal segmentation and cell segmentation. Every network is drawn as a single L2 segment with its hosts hanging off it, so what you are reading is a network position, not a product category.

Nothing can be installed on a PLC — so how does Yellow Cube protect Purdue L0–L1?

It does not try to put software there. PLCs, RTUs, drives and sensors take no agent, by design, so everything protecting them is in-line, transparent and upstream. In practice that means an industrial firewall in front of the cell, the machine or the individual PLC: OPSWAT's Industrial Firewall, which learns the normal traffic pattern and then enforces it with protocol-specific inspection for Modbus TCP, S7, DNP3, EtherNet/IP and BACnet, or Stormshield's ruggedised SNi range on DIN rail with hardware bypass. That is exactly why the firewall in front of the cell carries so much of the weight at this level.

How does telemetry cross the air gap without opening a route back into OT?

At Purdue L3.5 the path is deliberately one-way. The primary option is OPSWAT's NetWall Unidirectional Gateway, a paired-appliance gateway with protocol emulation so historians, OPC servers and file shares replicate northbound as if the link were bidirectional — telemetry leaves OT, and nothing routes back in. Waterfall Security's Unidirectional Security Gateway appears as an equivalent where a regulator already expects it, though that is the customer's own platform rather than part of the Yellow Cube portfolio. Removable media and contractor laptops take a different route entirely: a MetaDefender Kiosk acts as the airlock door, scanning and sanitising every USB stick and file before it is released into the OT side.

Do we have to replace the customer's existing identity provider or firewalls?

No. The dashed boxes in this architecture are third-party platforms most estates already run — Microsoft Entra ID or Google Workspace as the identity provider, for example — and they are explicitly not supplied by Yellow Cube. Yellow Cube's identity products layer on top of the provider the customer already has rather than replacing it, because that platform issues the tokens everything else trusts. Where two products are joined by “or”, they are equivalent options for the same position: choose one, do not stack both.

What in the portfolio covers the whole stack rather than one Purdue level?

Three things are cross-cutting rather than tied to a single level. Yellow Cube's own 24×7 Managed SOC watches IT and OT out of hours, working from the telemetry that the agents and sensors in this architecture produce. Cymulate Exposure Validation safely attacks the deployed controls to prove each zone blocks what it claims, including the OT boundary. CYBER RANGES adds live-fire exercises on realistic IT and OT scenarios, so a blue team learns this architecture under pressure rather than during an incident.

Let’s Build Smarter Cyber Defenses Together

Partnerships are the foundation of everything we do — built on trust, expertise, and shared success. Whether you’re looking to grow your business, strengthen your cybersecurity offerings, or bring innovative solutions to new markets, Yellow Cube is ready to be your committed, long-term ally.