A USB stick used to install an update in a factory can, at any moment, become an entry point into the OT environment. If it is infected, malware can travel from the workstation to SCADA or control systems and, in certain configurations, disrupt production processes. The risk is far from theoretical: according to the SANS 2025 ICS/OT Cybersecurity Budgetsurvey, compromised portable storage media accounted for 15.2% of the initial attack vectors reported in ICS/OT incidents.
That is why, in critical infrastructure, separating IT and OT environments must be complemented by strict control over the data crossing that boundary. The requirement is all the more relevant under NIS2: the directive has already been transposed into Romanian law, and the organizations in scope are now entering the phase in which security requirements are enforced and audited. In OT, many systems must remain isolated and continuously available, yet they still need patches, firmware, software and maintenance work. As a result, removable media such as USB drives, SSDs, HDDs and memory cards remain a common way of transferring data.
In practice, this media is often checked on an IT system before being brought into the OT zone. The process works, but it leaves room for human error and does not always guarantee that the files moving from one environment to the other are safe. With OPSWAT MetaDefender Kiosk, Datanet Systems offers a dedicated checkpoint before removable media reaches the protected zone, where its content can be scanned, analyzed and sanitized in line with the organization’s policies.
MetaDefender Kiosk: Control at the Point of Entry

OPSWAT MetaDefender Kiosk is designed as a removable media security station, placed at the boundary between the untrusted environment and the critical infrastructure. For the user, the workflow is simple: the storage device is inserted into the Kiosk, its content is analyzed and verified, and the files that meet the security policies can then be transferred to the target system.
This allows organizations to turn a process that normally relies on manual checks into a standardized, controlled workflow for transferring data into critical environments. MetaDefender Kiosk can scan a wide range of media and file types and, depending on the configuration, can process more than 17,000 files per minute. The platform is available in several hardware and software configurations to suit different use cases.
„OPSWAT MetaDefender Kiosk has broad applicability in organizations that operate critical infrastructure, in both the civilian and the defense sectors. It is a proven, certified solution used by more than 2,100 organizations worldwide. It combines scanning technologies from leading vendors with mechanisms such as multiscanning, Deep CDR and sandboxing, delivering a high level of protection for data transfers into OT environments. For organizations that need to keep their OT environments isolated while still transferring patches, software or data safely, MetaDefender Kiosk is an important checkpoint in the security architecture.” said George Laurențiu, Presales Consultant, Datanet Systems.
Defense in depth: multiple layers of analysis before a file reaches OT
One of the key advantages of MetaDefender Kiosk is its defense-in-depth approach. Rather than relying on a single detection mechanism, the solution combines several analysis and sanitization technologies.
- Multiscanning with 30+ anti-malware engines – MetaDefender can scan files with more than 30 anti-malware engines, reducing dependence on a single vendor and increasing the likelihood of identifying malicious files.
- Deep CDR (Content Disarm and Reconstruction) – For files that need to be used further in the OT environment, detecting malware is not always the only option. Deep CDR™ technology analyzes the content and rebuilds the file in a safe form, removing potentially dangerous elements while keeping the content usable. It supports more than 200 file formats and can also process nested archives.
- File-based vulnerability detection – Files and applications can also be checked for known vulnerabilities, allowing organizations to identify risks that a conventional antivirus scan would not necessarily detect.
- Sandbox and advanced analysis – For threats that are harder to identify, MetaDefender can use sandboxing and emulation to analyze file behavior and flag suspicious activity.
- DLP and policy control – The solution can also integrate Data Loss Prevention mechanisms, scanning policies and controls over how removable media is used.
The Kiosk management platform also allows administrators to define rules on who can transfer data, which file types are accepted and under what conditions they can reach the OT environment.
From Kiosk to a complete IT/OT protection architecture
MetaDefender Kiosk can serve as the central control point for removable media, but it can also be integrated into a broader protection architecture. For example, mechanisms such as Media Firewall, Managed File Transfer, Transfer Guard and Optical Diode can complement the process when an organization needs to strictly control transfers between zones with different security levels.
Another example is removable media validation: once a device has been scanned and approved, validation mechanisms allow an endpoint in the protected zone to verify that it has gone through the authorized process before accepting it. In this way, the air gap is no longer just a physical separation; it becomes part of an architecture in which every data transfer is subject to defined, verifiable controls.
MetaDefender Kiosk: multiple form factors for different scenarios
MetaDefender Kiosk is a product series available in several form factors and configurations, designed for different use cases, from permanent checkpoints in critical infrastructure to field maintenance operations. The range includes Kiosk Tower 5, built for high-volume scanning deployments with support for a wide range of storage media; Kiosk Mini 5, a compact form factor; and Kiosk Mobile, designed for portable use in harsh conditions.
Regardless of the hardware configuration, Kiosk App is the common software component across the range, providing the scanning, analysis and sanitization functions for removable media. For organizations that already have compatible hardware, Kiosk App can be deployed on its own, offering the same security approach without the need for dedicated Kiosk equipment.
Where can MetaDefender Kiosk be used?
The solution fits wherever data needs to be transferred into a critical or isolated environment without the storage media becoming a weak link in the security chain.

Some examples:
- Manufacturing and industry – transferring patches, firmware and software to PLCs, HMIs and SCADA systems;
- Energy and utilities – protecting access points to industrial systems and control infrastructure;
- Transportation – checking media used for the maintenance of operational systems;
- Defense and government infrastructure – controlled transfer between zones with different security levels;
- Maintenance and third-party vendor access – checking media brought in by subcontractors before it is connected to critical systems.
In all of these scenarios, the goal is the same: data must be able to flow, but never without strict control.
OPSWAT prin Datanet Systems
Datanet Systems is an OPSWAT technology partner and provides services for deploying MetaDefender solutions in IT/OT architectures. From selecting the right configuration and installing the equipment to configuring scanning and sanitization policies and integrating with existing security mechanisms, Datanet can tailor the solution to each organization’s specific requirements. MetaDefender Kiosk thus becomes an integrated component of the process of securing critical environments, not just a device for scanning USB sticks. For more information, please contact us at sales@datanets.ro.

Cisco AI Defense: why AI security...