Les failles dans Media amovibles menacent le fonctionnement des entreprises
Data is critical to this organization’s operations. Data and system files are required throughout the network tiers and high-risk zones to support operational, security, and other critical tasks, and in many cases must move across air-gapped environments. Isolation is an essential safety control in nuclear environments, helping maintain operational integrity while protecting people, assets, and the environment.
In our estate, removable media and transient devices are an unavoidable conduit between secure and less-trusted domains in order to perform updates and diagnostics.
Head of OT Cyber Security and Cyber Assurance
To meet security protocols and protect the environment, the organization previously relied on multiple manual checks and traditional procedures involving staff oversight and documentation.
Several key concerns needed to be addressed:
Sécurité des fichiers
Malicious files can covertly infiltrate nuclear facilities and undermine secure operations. Supply-chain risks, including tampered software, altered firmware, and corrupted third-party data, can further increase exposure to cyber infiltration and potential sabotage.
Removable Media Proble
USB drives, SD cards, and similar devices can introduce malware, enable unauthorized data extraction, and bypass existing network security safeguards. They also create auditability challenges and pose risks to the integrity of content stored on removable media.
Risques liés aux dispositifs transitoires
Laptops, maintenance devices, and contractor systems can introduce threats, unverified configurations, or hidden access paths when connected to secure networks.
Réglementation nucléaire
Compliance with strict regulatory requirements is a core driver for ensuring robust operational and cybersecurity safeguards around file security and removable media protection. In the nuclear sector, this extends beyond regulatory compliance. Organizations have a responsibility to maintain the highest levels of security, as even minor disruptions or deviations can have significant safety, environmental, and national-security consequences.
Processus opérationnels
Previously, the organization’s facilities operated with varying procedures, vendors, and legacy practices. Multiple manual checks made it difficult to scale processes while maintaining quality and compliance. Staff often needed to physically scan and transport media across large facilities several times, creating delays, operational fatigue, and an increased risk of human error. Teams urgently needed a standardized approach that could be applied consistently across all sites.
Manual release controls for files entering operational environments helped prevent outbreaks but added additional burden and increased the risk of mistakes in critical security and safety processes.
Strengthening Global Controls
We required greater control, security, and visibility into files as they cross all the boundaries. We needed to modernize and simplify our procedures and orchestrate many of the processes that are currently in place.
Head of OT Cyber Security and Cyber Assurance
Leadership has come to the conclusion that modernization, simplification, and better orchestration of their existing procedures were inevitable. To address these challenges, the organization selected OPSWAT because its integrated platform provided a comprehensive solution capable of securing files, removable media, and transient devices across their operational environments.
By deploying the integrated OPSWAT platform across all global facilities, the organization ensured that every file entering the nuclear environment was subject to zero-trust inspection workflows. Regardless of source or entry point: removable media, transient devices, onsite staff, or external third parties, all files were then processed through multi-layered defense controls to detect known and unknown threats targeting their environment.

This was achieved by implementing MetaDefender Kiosk™ (as integrated sheep dips) and MetaDefender Drive™ at established checkpoints for scanning removable media and transient devices before they entered the environment.
Each solution leverages a powerful set of technologies to keep malicious content out of the environment, including:
- Multiscanning avec plusieurs moteurs anti-malware
- Full archive inspection and extraction
- Deep CDR™ Technology
- Contrôles du pays d'origine
- File vulnerability scanning
- Intelligent reputation services
This multi-layered approach enforced consistent file security standards at the required performance level while maintaining operational efficiency, even when multiple engines were applied during scanning.

Le travail de chacun est déjà suffisamment difficile sans avoir à passer une demi-heure à attendre que votre USB soit analysée. Mais OPSWAT fait OPSWAT cela, même avec plusieurs moteurs, le puissant kit qui se cache derrière maintient cette efficacité.
Head of OT Cyber Security and Cyber Assurance
MetaDefender Kiosk delivered quick, reliable verification of all removable media, closing a significant security gap around USB devices. The MetaDefender Drive deployment served as a supply chain assurance tool used to scan vendor laptops before they were granted access.
With the MetaDefender Validation Endpoint, we’ve eliminated trust-based assumptions by ensuring only approved encrypted USBs and clean, scanned, unaltered files were allowed on critical endpoints.
Head of OT Cyber Security and Cyber Assurance
The OPSWAT solutions delivered orchestrated and flexible scanning through both free-standing and mobile kiosk formats, fitting seamlessly into business and security workflows.
Key Capabilities:
- Gestion centralisée pour un déploiement et un contrôle cohérents
- Formats de kiosques flexibles qui s'adaptent aux exigences opérationnelles
- Audit simplifié et visibilité dans tous les environnements
- Mise en œuvre facile avec une formation minimale requise
- Réduction du temps d'intégration pour les nouveaux utilisateurs et les nouvelles équipes

Consacrer quelques minutes à une analyse réduit considérablement le risque de problèmes système graves. Le temps nécessaire à l'analyse est minime comparé aux semaines qui pourraient être nécessaires pour récupérer après une panne majeure.
Head of OT Cyber Security and Cyber Assurance
The deployment has been strongly endorsed across the organization, from frontline teams to senior leadership.
Élargir le partenariat stratégique
The organization expanded its investment with OPSWAT to include the MetaDefender Managed File Transfer™ solution to drive efficiency and reduce operational risks in users’ daily tasks.
Files will be ingested from USB devices, internal file transfers, and third-party uploads into MFT, where they will be continuously scanned for threats and any suspicious files will be detonated within the solution’s inline sandbox capability.
Additional technical controls such as release management and supervisor approval will ensure outbreak prevention before file access is granted or securely transferred across domains.
The solution will function as a secure global file exchange platform for both internal teams and external partners, enabling security to support the business while enhancing productivity.

Notre partenariat avec OPSWAT transformé la manière dont nous sécurisons et gérons les fichiers dans l'ensemble de nos opérations nucléaires mondiales, nous offrant le contrôle, la visibilité et la cohérence dont nous avons besoin. Nous sommes impatients de voir où cette relation nous mènera et comment elle continuera à renforcer notre collaboration.
Head of OT Cyber Security and Cyber Assurance
Driven by a mission to protect the world’s critical infrastructure, OPSWAT’s integrated solutions protect sensitive IT and OT environments from cyberattacks, ensure operational continuity, and support regulatory compliance. To learn more about these solutions and how they can secure critical infrastructure networks, get in touch with an expert today.
