A ContainerLab-based environment of fully virtualised IT and OT networks. Build the topology, run the attack, break the design, and find out what happens before any of it touches a real plant.
The lab is not a product you buy. It is how we de-risk the work. The same virtualised environment serves engineering, security and training.
Test functions, topologies and security mechanisms before they are built. Prove a network or security design works as expected under real conditions, so changes go in with confidence, not hope.
Simulate failure scenarios and attack vectors safely. Run vulnerability assessments and incident-response exercises against realistic OT, with zero risk to anything in production.
The environment behind our courses and company-specific training: where segmentation, secure remote access and monitoring become tangible on a network that behaves like the real one.
See the courses →name: ot-design-and-defend topology: nodes: gw: { kind: mikrotik_ros, image: routeros } sw-dist: { kind: mikrotik_ros, image: routeros } sw-acc1: { kind: mikrotik_ros, image: routeros } jumphost: { kind: linux, image: proxmox } schneider-plc4: { kind: linux, image: ot/plc-sim } wago-plc2a: { kind: linux, image: ot/plc-sim } links: - endpoints: [ gw:ether1, sw-dist:ether1 ] - endpoints: [ sw-dist:ether2, sw-acc1:ether1 ] - endpoints: [ sw-acc1:ether2, schneider-plc4:eth1 ] - endpoints: [ sw-acc1:ether3, wago-plc2a:eth1 ]
The lab is built on ContainerLab, an open-source tool for orchestrating container-based network labs. A topology is a plain YAML file: the nodes, the links and the images they run. One command brings the entire network up.
No proprietary black box, and no hardware to rack. A topology comes up in minutes, and because it is code, it can be versioned, reviewed and reproduced exactly.
Customisable, industry-specific environments: ready-made starting points, or shaped to your own requirements.
Geographically distributed sites and the WAN that links them: the world of energy, water and gas utilities.
An industrial control network with the controllers, HMIs and SCADA layer of a real plant floor.
A clinical network with medical technology: where uptime and segmentation are not negotiable.
A corporate environment: data centre, campus and the IT side of an IT/OT environment.
One of our ready-made topologies: a water treatment plant modelled the way it really runs. A supervisory zone, an L3 firewall segmenting the OT VLANs, and the controllers that move water from intake to distribution. Spin it up, then break it, defend it, or rehearse a change.
We'll spin up an environment that mirrors your network, and show you what it can do before you commit a change to anything real.
Request a demo