New State Treasury Breach report Treasury report
Yellow Cube Architecture Map

Cybersecurity Architecture

Where each Yellow Cube product sits on the network — from the OT bus and PLCs, through the air gap, into enterprise IT, cloud and internet. Pairs with our Product Matrix, which weighs the same portfolio by contribution to your security posture. Click any product below for what it is and why it sits there. Dashed boxes are third-party platforms already common in the estate (identity providers, etc.) — not part of the Yellow Cube portfolio.

Product Matrix

Product placement across the whole stack, read bottom-up: OT buses and PLCs at the base, through the air gap, into enterprise IT, out to the internet and cloud. Each network is drawn as one L2 segment; the spine on the left is how they interconnect. Click any product for what it is and why it sits there — and to highlight it everywhere it appears.

Yellow Cube portfolio
Your existing provider — not ours
or Equivalent options — choose one
L2 segment · hosts hang off it
Routed north ↑
{{ row.level }}
{{ row.domain }}
{{ row.icon }}
{{ row.name }}
{{ row.note }}
{{ row.busLabel }}
{{ h.icon }}{{ h.name }}
{{ slot.icon }}
{{ slot.label }}
{{ slot.choiceNote }}
{{ it.sep }}
{{ row.icon }}
{{ row.level }}
{{ row.name }}
{{ row.note }}
{{ slot.icon }}
{{ slot.label }}
{{ slot.choiceNote }}
{{ it.sep }}
Across every layer
Cutout · L4 Office network

Where the agents actually sit

The same host stack twice — a virtualised server and a user workstation — opened up. Highlighted rows are where a Yellow Cube component is installed or where telemetry is taken. The workstation carries the full agent; the server carries it per guest, never on the hypervisor fabric.

{{ iconServer }}
IT server (virtualised)
Rack
HW
Server hardware · NIC · BMC
Virt
Hypervisor · vSwitch — no agent on the fabric
Kernel
Guest OS kernel — EDR kernel driver / ETW hooks
OS
OS services — EDR/XDR agent + log forwarder
Apps
App · DB · file shares — Varonis reads the shares
{{ iconUp }}Agent telemetry and syslog leave to the XDR collector, then the 24×7 SOC.
{{ iconTap }}Switch SPAN mirrors this host's traffic to the NDR sensor — nothing installed for it.
{{ iconMonitor }}
IT workstation
Desk
HW
Laptop · TPM · USB ports
Kernel
Windows kernel — EDR driver + USB device control
OS
OS services — EDR/XDR agent, insider-risk agent, DNS client
Apps
Browser · mail client · line-of-business apps
User
Sign-in — SSO, MFA, badge tap
{{ iconUp2 }}Same agent, same console as the server — one policy, two host classes.
{{ iconTap2 }}DNS is filtered at the resolver before the packet leaves the segment.
Server NIC
Workstation NIC
{{ iconNet }}
The wire between them
L2 segment
Switch
Core switch — SPAN / mirror port or in-line TAP
Mirrored copy
NDR sensor — a copy of the traffic, nothing installed
{{ s.sep }}
{{ iconTap3 }}The sensor is passive: it never sits in the path, so it cannot drop a packet or stop a line.
Both feeds land in the same XDR case: the agent says what ran on the host, the sensor says what crossed the wire. The SOC needs both to close a case.
{{ iconEye2 }}
The gap the agents leave
{{ b.t }}
Purdue levels are indicative — real zone boundaries follow the customer's segmentation, not the model.
Yellow Cube Cyberdefense · Full product matrix
{{ sel.vendor }}
{{ sel.name }}
{{ sel.icon }} {{ sel.cat }}

{{ sel.what }}

Sits at
{{ sel.where }}
Highlighted at
{{ sel.zones }}
Complementary vendor — not part of the Yellow Cube portfolio.
Vendor site ↗

From the PLC to the cloudYellow Cube secures every level of the Purdue model with one specialist vendor per domain, so your network architecture decides where the controls belong, not a vendor’s product catalogue.

Architecture Map

Purdue L5 · Cloud & Internet

SaaS tenants, public cloud and the mobile fleet that never touches the office LAN.

Cloud posture (CSPM)
WithSecure Elements Cloud Security or Cynet AutoXDR CSPM or Stellar Cyber Cloud Sensors or OPSWAT MetaDefender Cloud
Identity & MFA
Imprivata SSO + MFA or Microsoft Entra ID or Google Workspace identity
Supply chain integrity
OPSWAT Software Supply Chain or Cymulate Exposure Validation or Group-IB Attack Surface Management
Mobile devices
iVerify Mobile EDR or WithSecure Elements Mobile Protection
Cloud mailbox
IronScales Email detection & response + MailStore Email archive

Boundary · Internet perimeter

DDoS & edge
A10 Networks Thunder TPS
Perimeter firewall
Stormshield SNS firewall
DNS security
Whalebone DNS security

Purdue L4 · DMZ · IT DMZ

Published, internet-facing services. The office endpoint stack plus edge and identity controls.

WAF + load balancer
A10 Networks Thunder ADC + WAF
Identity security (ITDR)
Varonis ITDR or Imprivata PAM
Agent on published servers
Cynet AutoXDR agent or WithSecure Elements EDR or Group-IB Managed XDR or Stellar Cyber Server Sensor
File uploads in
OPSWAT MetaDefender ICAP Server or OPSWAT MetaDefender Core

Boundary · Internal segmentation

DMZ ↔ office firewall
Stormshield SNS firewall
DNS security
Whalebone DNS security

Purdue L4 · Office network

One L2 office network: servers, workstations, the SPAN port and the log path out to the SOC.

Endpoint agent — servers & workstations
Cynet AutoXDR agent or WithSecure Elements EDR or Group-IB Managed XDR
NDR sensor on SPAN / TAP
Stellar Cyber NDR sensor or Group-IB Network Traffic Analysis or OPSWAT MetaDefender NDR
Log collection → SOC
Stellar Cyber Open XDR platform or Cynet AutoXDR agent
Patch & vulnerability management
WithSecure Elements or Cynet AutoXDR agent
Endpoint security posture (ESPM)
WithSecure Elements or Cynet AutoXDR agent
Data & insider risk
Varonis Data Detection & Response or Teramind Insider threat management

Purdue L3.5 · Air gap

Electronic or optical separation. Telemetry leaves OT northbound; nothing routes back in.

One-way transfer
OPSWAT NetWall Unidirectional Gateway or Waterfall Security Unidirectional Security Gateway
Media & contractor laptops
OPSWAT MetaDefender Kiosk + OPSWAT MetaDefender Drive or OPSWAT Managed File Transfer

Purdue L3–L2 · OT control network

SCADA, historians, HMIs and engineering workstations. Windows hosts here still take an agent — where the OEM allows it.

Industrial firewall — zone control
Stormshield SNS industrial firewall or OPSWAT Industrial Firewall
Agent on HMI / engineering WS
Cynet AutoXDR agent or WithSecure Elements EDR or OPSWAT MetaDefender Endpoint
OT asset visibility
OPSWAT MetaDefender OT Security or OPSWAT MetaDefender NDR
Vendor remote access
OPSWAT MetaDefender OT Access or Imprivata PAM

Boundary · Cell segmentation

Control ↔ bus
Stormshield SNS industrial firewall

Purdue L1–L0 · OT bus / PLC network

Fieldbus and controllers. Nothing is installed down here — protection is in-line and transparent.

In front of the PLC
OPSWAT Industrial Firewall or Stormshield SNS industrial firewall
Field devices
By design No agent possible

Cross-cutting

Yellow Cube 24×7 Managed SOC + Cymulate Exposure Validation + CYBER RANGES Cyber range training

WithSecure Elements Cloud Security

CSPM

Continuous posture and misconfiguration checks across M365, Entra, Azure and AWS — in the same console as the endpoint agents below.

SaaS. No in-network component.

OPSWAT MetaDefender Cloud

Cloud file analysis

Multiscanning, Deep CDR and sandboxing offered as a cloud API for files entering the organisation.

SaaS API, called by apps and gateways.

Stellar Cyber Cloud Sensors

Cloud telemetry

Pulls cloud audit, identity and SaaS logs into the Open XDR data lake so cloud events correlate with network and endpoint events.

Cloud tenant + on-prem collector.

Stellar Cyber Server Sensor

Host telemetry sensor

Software sensor for supported Windows and Linux servers, forwarding system events and host telemetry as Interflow so Open XDR can correlate activity with the rest of the stack.

Agent on each published server in the IT DMZ.

Imprivata SSO + MFA

Identity & access

Single sign-on, badge tap and MFA built for shared workstations and shift work — clinical, shopfloor and control-room patterns included.

Cloud identity service + endpoint client.

OPSWAT Software Supply Chain

Supply chain integrity

SBOM generation, vendor package scanning and sanitisation before third-party software, updates or firmware are accepted into the estate.

Release gate / CI pipeline.

Cymulate Exposure Validation

Security validation

Safely attacks your own controls to prove the stack blocks what it claims — per zone, including the OT boundary.

Light agents across zones.

Group-IB Attack Surface Management

External exposure & supply chain

Continuously maps what you expose to the internet — shadow assets, exposed services, leaked credentials and the third parties in your supply chain — and scores what to fix first.

External, nothing to install.

Microsoft Entra ID

Identity provider

The identity platform most customers already run. It issues the tokens everything above trusts — our identity products layer on top of it, they do not replace it.

Cloud identity provider.

The customer's own platform — not supplied by Yellow Cube.

Google Workspace identity

Identity provider

The Google-side equivalent: the directory and token issuer the rest of the stack authenticates against.

Cloud identity provider.

The customer's own platform — not supplied by Yellow Cube.

iVerify Mobile EDR

Mobile defence

Detects mercenary spyware, jailbreaks, malicious profiles and configuration drift on iOS and Android — real detection, not just MDM compliance.

App on the device. No network position.

WithSecure Elements Mobile Protection

Mobile AV

Malware, phishing and browsing protection for managed phones and tablets, reported in the same Elements console as the desktops.

App on the device.

Whalebone DNS security

DNS filtering

Resolver-level blocking of phishing, malware and C2 domains. Covers guests, IoT and anything you cannot install software on.

Network resolver, or roaming client on mobiles.

IronScales Email detection & response

Email security

Post-delivery phishing detection and one-click remediation inside M365 or Google, with user reporting that trains the model.

API-integrated with the mailbox — no MX change.

MailStore Email archive

Retention & evidence

Tamper-proof journal archive of every mail — legal hold, e-discovery and the evidence trail auditors ask for.

Server in the office network.

A10 Networks Thunder ADC + WAF

Load balancer + web app firewall

Terminates TLS and balances published services, then enforces OWASP-class protection, bot defence and API guardrails on the same appliance — one insertion point for the WAF policy and for full-visibility decryption.

DMZ, in-line in front of the web tier.

A10 Networks Thunder TPS

DDoS mitigation

Volumetric and application-layer DDoS scrubbing at the internet edge, before the firewall's state table becomes the bottleneck.

Internet perimeter, in-line or on-demand.

Stormshield SNS firewall

NGFW

Perimeter and internal segmentation with IPS and application control — the same policy engine as the industrial SNi40 further down, managed together.

Internet perimeter and between internal zones.

Varonis ITDR

Identity threat detection

Watches Active Directory and Entra for privilege abuse, Kerberos attacks, stale admin paths and the blast radius each account carries.

Collector in the DMZ or office network.

Imprivata PAM

PAM

Vaults credentials and records privileged sessions to servers, jump hosts and OT assets — the audit trail for who did what.

Jump host in the DMZ.

Cynet AutoXDR agent

EDR / XDR agent

One agent covering NGAV, EDR, deception and automated response, with a 24×7 MDR team behind it. The pragmatic default where the security team is small.

Installed on every Windows, Linux and macOS host.

WithSecure Elements EDR

EDR agent

Endpoint detection and response with Elevate-to-expert escalation. Same agent family as the mobile and cloud modules — one vendor across three layers.

Installed on every server and workstation.

Group-IB Managed XDR

Managed XDR

Agent plus network sensors driven by Group-IB's own threat intelligence and incident-response practice. Strong where attribution and IR matter.

Agent on hosts + sensor on the network.

OPSWAT MetaDefender ICAP Server

Upload inspection

Every file uploaded through the reverse proxy is multiscanned and sanitised with Deep CDR before it reaches the application.

DMZ, beside the load balancer.

OPSWAT MetaDefender Core

File sanitisation engine

The scanning and Deep CDR engine that ICAP, managed file transfer and the Kiosks all call. Deploy once, reuse at every file entry point.

Server in the DMZ or office network.

Stellar Cyber NDR sensor

NDR

Passive sensor on a SPAN or TAP: east-west traffic, lateral movement and the unmanaged assets no agent will ever report.

SPAN/TAP port on the core switch.

Group-IB Network Traffic Analysis

NDR

Traffic analysis with in-line file detonation, tied to Group-IB intelligence on the actors targeting your sector.

SPAN/TAP, plus a copy of mail flow.

OPSWAT MetaDefender NDR

NDR

Network detection tuned for converged IT/OT traffic — understands industrial protocols as well as enterprise ones.

SPAN/TAP on either side of the boundary.

Stellar Cyber Open XDR platform

Log collection & correlation

Collects logs from every layer of this diagram, normalises them and does the correlation the SOC actually works from — vendor-agnostic by design.

Collector on-prem, platform in the cloud.

Varonis Data Detection & Response

Data security

Finds the sensitive data, fixes over-broad permissions, and alerts on abnormal access to file shares, SharePoint and mail.

Collector next to the file and mail servers.

Teramind Insider threat management

Insider risk & DLP

User activity monitoring, session recording and DLP for the accounts that already hold legitimate access.

Agent on workstations and terminal servers.

Stormshield SNS industrial firewall

OT firewall

The SNi range of ruggedised industrial firewalls — DIN-rail and rack models with protocol IPS and hardware bypass, sized to the cell rather than to one fixed appliance.

Between control zones, cells and machines.

OPSWAT Industrial Firewall

OT firewall / IPS

Learning mode records the normal traffic pattern, then enforces it — protocol-specific DPI for Modbus TCP, S7, DNP3, EtherNet/IP and BACnet. Designed to sit between Purdue L2 and L3.5.

In front of a cell, a machine or a single PLC.

OPSWAT MetaDefender OT Security

OT asset visibility

Passive and safe active discovery of every OT asset, its firmware level and its known vulnerabilities — the inventory the risk assessment needs.

Sensor in the control network.

OPSWAT MetaDefender OT Access

Secure remote access

Brokered, time-boxed and session-recorded vendor access to OT assets — without a VPN tunnel into the control network.

Broker at the IT/OT edge.

OPSWAT MetaDefender Endpoint

Posture & AV for OT hosts

Lightweight posture, patch and malware checks for hosts where the OEM will not certify a full EDR agent.

HMI and engineering workstations.

OPSWAT NetWall Unidirectional Gateway

Unidirectional gateway

One-way gateway with protocol emulation, so historians, OPC servers and file shares replicate northbound as if the link were bidirectional.

L3.5, paired appliances.

Waterfall Security Unidirectional Security Gateway

Unidirectional gateway

Hardware-enforced one-way replication with a long track record in energy and water, and the regulator familiarity that comes with it.

L3.5, paired appliances.

The customer's own platform — not supplied by Yellow Cube.

OPSWAT MetaDefender Kiosk

Removable media control

The airlock door: every USB stick and contractor file is scanned and sanitised at the kiosk before it is released into the OT side.

Physically at the entrance to the OT area.

OPSWAT Managed File Transfer

Controlled file entry

The supervised path for files that must cross the boundary — scanned, sanitised, approved and logged, with no shared drive in between.

Either side of the air gap.

OPSWAT MetaDefender Drive

Offline device inspection

Boots a contractor laptop or commissioning machine from a trusted drive and scans it offline, before it ever joins the OT network.

Portable, used at the air gap.

CYBER RANGES Cyber range training

Skills & exercises

Live-fire exercises on realistic IT and OT scenarios — the way a blue team learns this diagram under pressure.

Hosted platform.

Yellow Cube 24×7 Managed SOC

Managed detection & response

The team that watches everything above out of hours, across IT and OT, on the telemetry the agents and sensors here produce.

Yellow Cube SOC, fed by the collectors.

Cynet AutoXDR CSPM

Cloud posture

Cloud security posture management inside the same AutoXDR console as the endpoint agents — misconfigurations, exposed storage and identity drift in one place.

Agentless, connected to the cloud tenant.

WithSecure Elements

Endpoint posture, patching & vulnerability management

One agent and one console for endpoint protection, third-party patching and vulnerability management, with posture scoring across the estate.

Servers and workstations on the office network.

By design No agent possible

Field devices

PLCs, RTUs, drives and sensors cannot run security agents. Everything protecting them is in-line, transparent and upstream — which is why the firewall in front of the cell matters so much.

Purdue L0–L1.

FAQ

01 Where does each Yellow Cube product sit in the Purdue model?

Yellow Cube places its portfolio across the whole stack, read bottom-up: Purdue L1–L0 is the OT bus, carrying PLCs, RTUs, drives and sensors; L3–L2 is the OT control network with SCADA, historians, HMIs and engineering workstations; L3.5 is the air gap; L4 covers the office network and the IT DMZ; L5 is cloud, SaaS and the mobile fleet. Firewall boundaries sit between them — internet perimeter, internal segmentation and cell segmentation.Every network is drawn as a single L2 segment with its hosts hanging off it, so what you are reading is a network position, not a product category.

02 How does Yellow Cube protect Purdue L0–L1 devices that cannot run a security agent?

Protection for PLCs, RTUs, drives and sensors that cannot run a security agent is placed in the network, upstream of those devices.In practice that means an industrial firewall in front of the cell, the machine or the individual PLC: OPSWAT's Industrial Firewall, which learns the normal traffic pattern and then enforces it with protocol-specific inspection for Modbus TCP, S7, DNP3, EtherNet/IP and BACnet, or Stormshield's ruggedised SNi range on DIN rail with hardware bypass. That is exactly why the firewall in front of the cell carries so much of the weight at this level.

03 How does telemetry cross the air gap without opening a route back into OT?

At Purdue L3.5 the path is deliberately one-way. The primary option is OPSWAT's NetWall Unidirectional Gateway, a paired-appliance gateway with protocol emulation so historians, OPC servers and file shares replicate northbound as if the link were bidirectional — telemetry leaves OT, and nothing routes back in.Waterfall Security's Unidirectional Security Gateway appears as an equivalent where a regulator already expects it, though that is the customer's own platform rather than part of the Yellow Cube portfolio. Removable media and contractor laptops take a different route entirely: a MetaDefender Kiosk acts as the airlock door, scanning and sanitising every USB stick and file before it is released into the OT side.

04 Do we have to replace the customer's existing identity provider or firewalls?

No. The dashed boxes in this architecture are third-party platforms most estates already run — Microsoft Entra ID or Google Workspace as the identity provider, for example — and they are explicitly not supplied by Yellow Cube. Yellow Cube's identity products layer on top of the provider the customer already has rather than replacing it, because that platform issues the tokens everything else trusts.Where two products are joined by “or”, they are equivalent options for the same position: choose one, do not stack both.

05 What in the portfolio covers the whole stack rather than one Purdue level?

Three things are cross-cutting rather than tied to a single level. Yellow Cube's own 24×7 Managed SOC watches IT and OT out of hours, working from the telemetry that the agents and sensors in this architecture produce. Cymulate Exposure Validation safely attacks the deployed controls to prove each zone blocks what it claims, including the OT boundary.CYBER RANGES adds live-fire exercises on realistic IT and OT scenarios, so a blue team learns this architecture under pressure rather than during an incident.

Let’s Build Smarter Cyber Defenses Together

Partnerships are the foundation of everything we do — built on trust, expertise, and shared success. Whether you’re looking to grow your business, strengthen your cybersecurity offerings, or bring innovative solutions to new markets, Yellow Cube is ready to be your committed, long-term ally.

Get in touch with Yellow Cube