Blog · Explainers

How does Sentinel protect operational technology on a robot site, and what does the EN-200 do?

An explainer on OT security the way Sirdar practises it: the five industrial protocols Sentinel reads, what the EN-200 edge node is, and how an investigation at Port of Halvard went from first observation to a proposed containment.

Sentinel protects a site by knowing every device on it, reading the industrial protocols those devices speak and enforcing a policy on what each one may do. The EN-200 is the 1U fanless edge node that does the reading on the site network. Sentinel decodes Modbus TCP, OPC UA, EtherNet/IP, PROFINET and DNP3, with a median of 1.8 seconds from detection to alert. When something breaks policy, Sentinel blocks it, records the evidence and proposes a containment that a person approves.

Soren Avelar · CTO, Sirdar Systems · · 4 min read

Last updated

What is different about securing operational technology?

The devices cannot defend themselves, and stopping them has physical consequences.

A PLC that controls a crane does not run endpoint software. It speaks an industrial protocol to whatever addresses it, and it was designed to obey. Security on that segment has to come from a device that watches the traffic, understands the protocol well enough to know a read from a write and can enforce a rule without taking the crane offline. That is what Sentinel was built to do for Sirdar's own robots, and what it does for the rest of the site.

Which protocols does Sentinel read?

Five, natively: Modbus TCP, OPC UA, EtherNet/IP, PROFINET and DNP3.

Reading the protocol matters because the difference between normal and hostile is often one function code. In Modbus TCP, function code 0x10 writes multiple registers. A gateway that has only ever read from a controller suddenly attempting 0x10 against it is a specific, decodable event, not a vague anomaly.

What is the EN-200?

The edge node that sits on the site network and does the observing.

The Sentinel Edge Node EN-200 is a 1U appliance with two 10GbE SFP+ ports and four 1GbE ports. It is fanless, runs from minus ten to 55 °C and draws about 12 W. It is installed in the site's OT cabinet, sees the segments it is attached to and reports to the Sentinel console. A Halvard-sized site runs one; larger sites run more.

What does an investigation look like from the inside?

A timeline, with every entry attributed to a source.

At Port of Halvard Berth 3 the Sentinel console held an open investigation on the crane PLC segment, OT-VLAN 310, which was still open at the time of writing. Its timeline:

  • 08:11:58, observed by EN-200 HLV3-01. Gateway GW-B3-02 opened 14 Modbus TCP sessions to hosts it had never addressed in 90 days.
  • 08:12:02, matched by Sentinel policy. Function code 0x10 attempted against crane controllers PLC-B3-04 and PLC-B3-05.
  • 08:12:03, blocked. Writes denied by the Berth 3 OT allow-list; reads allowed to continue for evidence.
  • 08:12:41, alerted. A high-severity alert raised and correlated with an earlier medium alert about a new Modbus master on the same gateway.
  • 08:13:10, assigned. The investigation claimed by the partner of record's security desk, Northgate Technologies.
  • 08:13:55, proposed. Containment: isolate GW-B3-02 and quarantine the east segment.

Detection to alert on this investigation was 1.6 seconds.

Why block the writes but keep the reads?

Because the writes are the harm and the reads are the evidence.

Denying 0x10 protected the controllers immediately. Allowing reads to continue let Sentinel record what the gateway was trying to learn, which is what the partner's analyst needed to decide whether the gateway was compromised or misconfigured. A policy that cut everything at 08:12:03 would have been safer for one minute and blinder for the rest of the day.

What does "propose a containment" mean?

Sentinel writes the plan; a person approves it.

The proposed action named its target (GW-B3-02) and four steps: isolate the gateway from the segment and the WAN, quarantine the east segment while keeping the crane PLCs reachable from the fleet controller only, pause the two Kinetic units on that segment where they stood, and snapshot the gateway's memory to the evidence store. It stated its impact (two of six Kinetic units paused, crane operations continuing under manual control) and that it was reversible. The same pause appeared in Aether as a safety-hold exception, so the operations side saw it in the same minute.

Which Sentinel version does this describe, and what about 4.0?

Sentinel 3.8 is the current release; Sentinel 4.0 is in preview.

The Berth 3 console runs 3.8. Sentinel 4.0 entered preview on 2026-03-12 and is not sold. Partners with the Security Operations specialization have access to the preview; customers should plan on 3.8 for new deployments until Sirdar announces otherwise.

What should a site do first?

Enrol everything, then write the allow-list.

Sentinel's value on OT starts with knowing every device. Kinetic units and Halo nodes arrive enrolled from the factory. Third-party gateways and controllers are enrolled during deployment, which is why Sirdar's Deployment service and a Sentinel Health check appear on most partner quotes. The allow-list for each segment is written with the people who run the equipment. After that, Sentinel watches, and the median from detection to alert is 1.8 seconds.

Last updated 2026-09-30.

Questions and answers

Which industrial protocols does Sentinel understand?
Modbus TCP, OPC UA, EtherNet/IP, PROFINET and DNP3, decoded to the function-code level so that a write can be told from a read.
What is the Sentinel EN-200?
A 1U fanless edge node with two 10GbE SFP+ and four 1GbE ports, rated from minus ten to 55 °C at about 12 W, installed on the site network to observe OT segments.
Does Sentinel stop a robot during a security event?
It can propose it. At Berth 3 the proposed containment paused the two Kinetic units on the affected segment; the pause appeared in Aether as a safety hold for the operator.
Is Sentinel 4.0 available?
Sentinel 4.0 is in preview and not sold. Sentinel 3.8 is the current release and the one new sites deploy.
How fast does Sentinel alert?
The median from detection to alert is 1.8 seconds. The Berth 3 investigation described here took 1.6 seconds.

#Sentinel #OT security #EN-200 #Explainers