24/7 incident response phone: 24/7 incident response · +34 902 540 891

Getting files out of the plant without opening the plant

SMBFileTransferService moves files between the industrial and corporate networks automatically, encrypted and auditable, without leaving a direct path open between the two.

The problem

New technologies and new ways of working have made it essential for production information to reach the business: reports, historians, the data behind decisions made outside the plant. That transfer is no longer optional.

The delicate part is not moving the file, it is how it moves. A permanent network share, a script with the credentials inside it, or a firewall rule opened "temporarily" turn that exchange into a way in to the industrial network.

What it is

SMBFileTransferService is a tool developed by Titanium that automates file transfer between the OT and IT networks. It installs as just another Windows service: there is no separate console to maintain, and it is monitored with the same tools already watching the rest of the estate.

How it works

Information travels encrypted using the SMB v3 protocol, and the transfer user authenticates against the OT Active Directory or against a local user, whichever suits the plant's architecture.

The part that matters is who calls whom: the service itself initiates the connection, so the direction of communication is settled by design rather than by a firewall rule. That is what makes it possible to respect the separation between zones in the IEC 62443 zones and conduits model instead of punching through it.

Every action is written to system log files, so there is a reviewable trail of what moved, when and under which user.

Why not a script

A scheduled copy script does the same job on day one. What it does not do is survive: it stores credentials, nobody remembers who wrote it, it breaks silently and it leaves no trail. Here there are no automation scripts to maintain, and because the direction of the connection is known and fixed, firewall rules are simple to write and to justify in an audit.

Capabilities

What it brings

Automatic

The transfer happens on its own, with nobody having to remember to launch it and no automation scripts to maintain.

Encrypted with SMB v3

Information travels encrypted using version 3 of the SMB protocol, not in the clear across a network share.

Authenticated

The transfer user is validated against the OT Active Directory or against a local user, depending on the plant's architecture.

Controlled direction

The service initiates the connection, so it decides which way it opens. Aligned with the IEC 62443 zones and conduits model.

Auditable

It records every action in system log files: what was transferred, when and under which user.

Monitorable

Being a Windows service, it fits into the supervision the plant already runs, with no new tooling.

Titanium · Legal information
Titanium · Legal information
Titanium · Legal information