site-logo
site-logo
site-logo

PRESS RELEASE 

Shieldworkz, Announces Media Scan, a Deterministic Removable Media and File Security Solution for OT Environments 

New OT-native security solution provides deterministic inspection and fail-closed control for files entering and leaving industrial environments

Shieldworkz, a provider of OT and industrial cybersecurity solutions, today announced the launch of Media Scan, an OT-native removable media security and file security solution designed to protect industrial environments from threats introduced through USB drives, external storage, engineering files, firmware updates, and other file-transfer channels. 

Built specifically for operational technology (OT) environments, Media Scan is designed to move beyond traditional threat detection by enforcing a security decision on every file. Each file is processed through a fixed, deterministic inspection pipeline and receives one of three outcomes: Clean, Hold, or Blocked

The solution follows a fail-closed security model. When a file cannot be inspected because of an unsupported format, inspection error, connectivity issue, or other condition, it is placed on hold rather than being allowed into the protected environment. 

Industrial Media Scanning Checkpoint

Removable media continues to represent a significant security challenge for industrial organizations. 

USB drives, laptops, external hard drives, contractor devices, vendor equipment, firmware packages, engineering files, and portable storage can all become pathways for malware and other malicious content to enter an OT environment. This risk becomes particularly important in air-gapped and isolated OT networks. Even when an industrial network is disconnected from corporate or public networks, a removable device can create a physical bridge into the environment. Traditional antivirus and malware detection technologies can identify known or suspicious threats, but detection alone does not always provide an enforceable control over what happens next. For industrial organizations, the requirement is often more direct: a file should not enter the OT environment until it has been inspected and approved. 

Media Scan was designed around this principle. 

“A file that has not been inspected has not been trusted. It has simply been ignored,” said by our customers, Shieldworkz. “Media Scan brings deterministic inspection and enforcement to removable media and file transfers, helping organizations establish a consistent security control at the point where files enter or leave their OT environment.” 

New OT-native security solution provides deterministic inspection and fail-closed control for files entering and leaving industrial environments

Shieldworkz, a provider of OT and industrial cybersecurity solutions, today announced the launch of Media Scan, an OT-native removable media security and file security solution designed to protect industrial environments from threats introduced through USB drives, external storage, engineering files, firmware updates, and other file-transfer channels. 

Built specifically for operational technology (OT) environments, Media Scan is designed to move beyond traditional threat detection by enforcing a security decision on every file. Each file is processed through a fixed, deterministic inspection pipeline and receives one of three outcomes: Clean, Hold, or Blocked

The solution follows a fail-closed security model. When a file cannot be inspected because of an unsupported format, inspection error, connectivity issue, or other condition, it is placed on hold rather than being allowed into the protected environment. 

Fail-Closed OT Security 

A key characteristic of Media Scan is its fail-closed architecture

In many security environments, an inspection failure can become an operational exception. In OT environments, that approach can create an unintended security gap.  Media Scan takes the opposite approach. 

When the system cannot complete an inspection or cannot establish a trusted result, the file remains on Hold

This design is intended to prevent unknown or unverified files from bypassing the security process because of an operational or technical failure. 

For organizations operating air-gapped OT networks, Media Scan can also support core inspection functions without requiring continuous external connectivity. 

Built for Industrial File Formats 

Industrial environments do not deal exclusively with conventional office documents and executable files. Engineering teams regularly work with configuration files, project files, firmware packages, PLC-related files, machine configurations, and other specialized formats. 

Media Scan supports 500+ file formats, including OT and engineering file types such as: .bin, .s7p, .acd, .rsp, .prj, .dat, .cfg, .xml, and other industrial file formats associated with platforms from vendors including Siemens, Rockwell, Schneider, ABB, and others

This OT-oriented file support is intended to help security teams apply a consistent industrial file security policy without excluding the file types needed for plant operations and engineering workflows.

Security for USB Drives and Removable Media 

For many industrial organizations, the security process around USB devices is still highly dependent on manual procedures. 

Employees, contractors, and vendors may bring removable media containing software updates, technical documents, engineering files, firmware, or configuration data into a facility. 

Media Scan provides an inspection and enforcement layer that can be incorporated into these workflows.

USB malware scanning 

Removable media protection 

Secure USB file transfer 

USB drive security for OT environments 

Vendor media inspection 

Firmware file security 

Engineering file inspection 

Contractor media security 

Air-gapped network file security 

This enables organizations to establish a consistent security policy regardless of who brings the file or where the file originated. 

Complete Audit Trail for Every File

Media Scan creates an audit record for each file that passes through the platform.

The record can include the file source, format, inspection stages, timestamp, security verdict, and final disposition.

For security and compliance teams, this creates a traceable record of file-transfer activity rather than relying on manually maintained logs or retrospective investigations.

The audit trail can also support compliance evidence and security investigations by showing what was inspected, when it was inspected, and what decision was made.

Audit Record Fields

Source
Format
Inspect
CDR
Verdict
Disposition
FILEscada_config_v14.xml
SOURCEUSB-042 · Engineering Workstation
FORMATXML
STAGESInspection → CDR → Verdict
TIMESTAMP2026-08-14 09:42:11 UTC
DISPOSITIONAllowed → OT Historian
ALLOWEDBLOCKED

Designed for OT Cybersecurity and Compliance

Modern industrial cybersecurity programs increasingly require organizations to demonstrate that security controls are not merely deployed but consistently enforced.

Media Scan is designed with requirements and guidance associated with IEC 62443, NIST SP 800-82, ISO 27001, and NIS2 in mind.

By providing deterministic file inspection, controlled transfer workflows, per-file audit records, and fail-closed enforcement, Media Scan can help organizations strengthen their OT cybersecurity compliance and demonstrate control over removable media and file-transfer processes.

Compliance Frameworks

IEC 62443
Industrial automation and control systems security
NIST SP 800-82
Guide to operational technology security
ISO 27001
Information security management systems
NIS2
EU network and information security directive

Integration With Existing Security Infrastructure

Media Scan is designed to operate alongside existing enterprise security and operational systems.

Integration Capabilities

Active Directory
SIEM platforms
ITSM workflows
SFTP and Managed File Transfer environments
API-based integrations
Exportable audit logs
Custom enterprise workflows

This enables security teams to incorporate OT file security into their existing cybersecurity architecture rather than maintaining a completely isolated process.

Designed for High-Volume Industrial Environments

Media Scan is designed for operational environments where security controls must operate without creating unnecessary workflow bottlenecks.

Platform Capacity

500+
File formats
10,000+
Files per day
<5s
Sub-five-second average inspection time
17+
Parallel scanning engines
4
Deployment models
99.9%+
Availability target

The inspection pipeline is parallelized to support high-volume file processing while maintaining the security controls required for industrial environments.

Why Media Scan Is Different

Media Scan is built around a fundamental distinction between detection and control.

Traditional antivirus and scanning solutions are primarily designed to identify malicious or suspicious content. Media Scan is designed to establish an enforceable decision about every file crossing an OT security boundary.

Platform Architecture

Deterministic inspection
Consistent, repeatable file verdicts on every pass.
Fail-closed enforcement
Files are blocked by default unless explicitly cleared.
Multi-engine scanning
17+ engines evaluate every file in parallel.
Content Disarm and Reconstruction
Rebuilds files to strip embedded threats.
OT-focused threat intelligence
Signatures tuned to industrial file formats and protocols.
Industrial file format support
Coverage across 500+ engineering and OT formats.
Removable media security
Controlled inspection of USB and portable media.
Per-file audit logging
A traceable record for every file, every time.
Air-gapped deployment capabilities
Operates fully disconnected from external networks.
IT-OT boundary inspection
Enforced checkpoints where IT and OT networks meet.

Together, these capabilities provide organizations with a security framework designed specifically for controlling file movement in industrial environments.

Get in Touch with Shieldworks

For press inquiries, interview requests, or media assets, reach out to the team in your region. We typically respond within one business day.