Securing Legacy Utility Substations with Garland Technology and Radiflow

   May 05, 2025 | Daniela Shimoni

 

Securing legacy utility substations is challenging due to outdated infrastructure and unmanaged switches. This use case highlights how Garland Technology’s TAPs and Radiflow’s OT security platform enable passive traffic capture and real-time threat detection without disrupting operations. Together, they provide a scalable, non-intrusive solution for enhancing cybersecurity across critical infrastructure.

Challenges & Objectives

OT networks, especially in utility substations, are often comprised of outdated, legacy equipment. This reliance on legacy equipment comes from the focus on production uptime. It’s extremely hard to take a substation offline for network and security updates, so over the years the ‘if it’s not broken, don’t fix it’ attitude has taken hold. Unfortunately, with cybercriminals targeting critical infrastructure environments, utilities must now find a way to add security solutions, like OT risk and anomaly detection, across their OT networks. But with unmanaged switches and other legacy devices in place, deploying such solutions can be very difficult, if not impossible.

Proposed Solution

Garland Technology’s Network TAPs are purpose-built hardware devices, designed to reliably deliver network traffic to OT security monitoring tools. When unmanaged switches are present, using a Network TAP is the best way to gain access to the OT network traffic in each substation. This traffic is then forwarded to Radiflow sensors for risk-driven OT anomaly detection and threat management. Together, Garland’s dependable hardware and Radiflow’s advanced monitoring create a cohesive security solution that protects utility substations.

  1. A single Portable Copper Aggregator TAP will be deployed at each substation, making a complete copy of the traffic from the unmanaged switch.
  2. Radiflow sensor analyzes the full traffic feed in real time, applying risk-driven anomaly detection to generate prioritized alerts and manage OT threats

Benefits

  • Built-in unidirectional data diode functionality secures traffic capture and enables integrated
    security monitoring.
  • Easy to deploy at scale across geographically dispersed substations.
  • TAPs are invisible to adversaries due to having no IP or MAC Address.
  • Remains operational during power loss, ensuring continuous protection.

 

Radiflow iSID’s network maps provide drill-down visibility into all devices along with their full properties and connections

Additional Resources

Request Demo Contact Us