BLOG

Date
19-08-2026

OT Cybersecurity

Where Data Diodes Actually Get Deployed: 6 Proven OT Use Cases

It is easy to understand what a data diode is in the abstract, hardware that enforces one-way data flow, and much harder to know where one actually belongs in your environment. The gap between the concept and the deployment is where most operators get stuck. A diode is only useful where the data flow is genuinely one-directional, and recognizing those places in your own network is the real skill.

This guide walks through six proven use cases where data diodes deliver clear value in operational technology environments, with the North American context, NERC CIP for utilities, IEC 62443 for industrial operators, and the realities of remote and distributed sites, in mind. Each use case explains the flow, why one-way hardware fits, and what to watch for. It is written for OT security engineers and asset owners deciding where a diode earns its place.

The unifying principle across all six: a data diode fits wherever operational data needs to leave a protected zone but nothing legitimately needs to come back in. If you can identify a boundary where every genuine data flow is outbound, you have found a candidate for one-way hardware.

 

1. Historian Replication

This is the most common data diode deployment, and for good reason. Process historians such as OSIsoft PI collect enormous volumes of operational data inside the OT network, and business users, analysts, and enterprise systems all want access to it. The naive approach exposes the historian to the corporate network, creating an inbound path into OT.

A diode solves this cleanly. The historian data replicates one-way, out of the OT zone to a mirrored historian or analytics platform on the IT side, where business users query it freely. The production historian inside OT is never exposed to inbound traffic. Because the replication is continuous and the receiving copy is complete, users lose nothing except the ability to reach back into the control network, which they never needed.

Watch for: historian replication across a strictly one-way path usually needs vendor replication software on each side of the diode. The hardware alone does not understand the historian's protocol. Budget for the software and the integration, not just the appliance.

 

2. SIEM and SOC Log Export

Security monitoring creates a paradox in OT. To monitor industrial systems for threats, you need their logs and events in your SIEM, but connecting OT systems to a SIEM can create exactly the inbound exposure you are trying to defend against. Operators are rightly reluctant to open a path from a monitoring platform into a control network.

A diode resolves the tension. Logs, events, and telemetry flow one-way out of the OT environment to the SIEM or SOC, giving your security team full visibility, while the source systems remain physically unreachable from the monitoring side. You get the monitoring coverage without the monitoring becoming an attack path. This is increasingly a default pattern for operators building OT visibility without compromising segmentation.

 

3. Remote Substation Monitoring

Transmission and distribution utilities need to monitor substations remotely, but a substation OT network is a high-value target that must stay isolated. Historically these two needs were in tension: monitoring meant connectivity, and connectivity meant exposure.

A data diode at the substation boundary lets monitoring and OPC data flow out to the control center or corporate users while guaranteeing no inbound path into the substation network. For utilities under NERC CIP, this pattern does double duty: it enables the remote monitoring the business needs and provides the deterministic, hardware-enforced segmentation that strengthens the NERC CIP compliance position. It is one of the clearest examples of security and operational need aligning rather than competing.

 

4. Protective Relay Isolation

This is a newer and more sophisticated use case, and a telling one. Protective relays are the equipment that protects the grid, tripping breakers to prevent damage during faults. Transmission operators need to monitor these relays remotely, but they generally do not need to control them over the network, and the consequence of a compromised relay is severe.

The emerging pattern places protective relays on small, separate networks within each substation, with a data diode between the relay network and the main substation network. Monitoring data flows out; nothing reaches back in to the protection equipment. It is a clear illustration of the principle that the highest-consequence assets benefit most from physical, one-way isolation, protecting the equipment that protects everything else.

 

5. Distributed Renewable Sites: Solar and Wind

Renewable generation has multiplied the number of remote, often unmanned, OT sites an operator runs. A solar farm or wind farm generates valuable telemetry, inverter output, turbine performance, grid export figures, meteorological data, that IT analytics and forecasting platforms need. But these sites are frequently unmanned, running legacy controllers, with no one on hand to manage evolving firewall policy.

That management burden is exactly what a diode removes. Unlike a firewall, whose rules someone has to keep correct over time, a diode enforces one-way flow in hardware. At a centralized substation or aggregation point on the site, it lets production telemetry flow outward to enterprise analytics while the control network stays isolated, with no ongoing policy to maintain. Hardware enforcement is especially valuable precisely where there is no one on site to manage a software control.

Watch for: at large renewable sites, telemetry is usually aggregated at a site-level collection point before it reaches the diode, rather than running a diode per inverter or turbine. Confirm protocol support too: OPC-UA, MQTT, and Modbus often need proxy or replication software to cross a one-way boundary cleanly.

 

6. Cloud and Enterprise Analytics Feeds

As operators push OT data into cloud platforms for analytics, machine learning, and cross-site benchmarking, they face the same core problem at a larger scale: the cloud needs the data, but the OT network must not be reachable from the cloud. A breach of a cloud analytics platform must not become a path back into the plant.

A diode sits at the OT-to-cloud boundary, passing operational data one-way to historians, MES, BI tools, and analytics engines that can process it freely. The entire data pipeline operates with no return path into the OT zone. For operators with geographically distributed facilities, this architecture repeats at each site, with data flowing outward from each secure zone to central monitoring or cloud infrastructure. It is what lets an operator embrace data-driven operations without surrendering segmentation.

 

Use Case Summary

 

Use Case

What Flows One-Way

Primary Driver

Historian replication

Process historian data to IT analytics

Business access

SIEM / SOC log export

Security logs and events to monitoring

OT visibility

Remote substation monitoring

OPC and monitoring data to control center

NERC CIP + ops

Protective relay isolation

Relay monitoring data outward

High-consequence asset

Solar / wind sites

Production and met telemetry to analytics

Unmanned remote sites

Cloud / enterprise analytics

OT data to cloud and BI platforms

Data-driven ops

 

What All Six Have in Common

Look across the use cases and the same shape recurs: valuable operational data trapped inside a zone that must stay isolated, and a business or security need to get that data out without opening a way in. That is the exact problem a data diode is built for, and it is far more common in OT than most teams realize when they first consider one-way hardware.

The corollary is just as important. Where a genuine bidirectional need exists, remote control, patch delivery, interactive access, a diode is the wrong tool, and forcing it there creates operational pain. The skill is separating the one-way flows, which are numerous, from the genuinely two-way ones, which are fewer than most assume, and applying the right control to each. Once you have identified the right flows, choosing the right data diode vendor is the next step.

 

Frequently Asked Questions

What is the most common data diode use case?

Historian replication is the most common. Process historian data replicates one-way from the OT network to a mirrored copy on the IT side, giving business users full access to operational data while the production historian stays physically unreachable from inbound traffic. SIEM log export and remote monitoring are close behind.

Do data diodes work at remote and unmanned sites?

Yes, and unmanned sites are among the strongest use cases. Because a diode enforces one-way flow physically, there is no software policy to maintain on site, which is ideal where no one is present to manage evolving firewall rules. Solar farms, wind farms, and remote substations are common deployments, usually with telemetry aggregated at a site collection point before the diode.

Can a data diode send OT data to the cloud?

Yes. A diode at the OT-to-cloud boundary passes operational data one-way to cloud historians, analytics, and BI platforms, which process it freely, while ensuring no return path into the OT zone. This lets operators use cloud analytics without making the plant reachable from the cloud. Distributed operators repeat the pattern at each site.

What do all data diode use cases have in common?

Every one involves data that must leave a protected zone while nothing legitimately needs to come back in. If you can identify a boundary where all genuine flows are outbound, monitoring, logging, telemetry, historian data, it is a candidate for a data diode. Boundaries with real bidirectional needs require a firewall or controlled channel instead.

 

Talk to an OT Security Expert

If you can see one of these patterns in your own environment but are not sure how to deploy a diode around it, we can help. Book a free consultation with one of our OT security engineers, and we will assess where one-way hardware fits your architecture, for operators across the US and Canada.

 Book Your Free Consultation 

BOOK YOUR CONSULTATION