Use case · OT / IT convergence

Getting the floor and the back office to talk, without rebuilding the network.

No inbound ports on the OT network, no re-addressing, no proprietary protocol to adopt. Meddle attaches to what already exists — PLCs, SCADA, MES, ERP — with outbound-only traffic and one asset model shared between both worlds.

Connected sourcesOT and IT on one model
PLCs · OPC-UA and S734 assets
Meters · Modbus TCP12 assets
MES · SQL database1 source
ERP · API1 source
Inbound ports opened on the OT network0
Which assets are sending data right now?
  • Outbound only
    no inbound port to open towards the floor
  • 44 connectors
    standard protocols, any brand, no lock-in
  • One model
    the same asset, under the same name, for OT and IT
The problem

Why the two worlds stay separate

  • Security stops the project, and rightly so

    Opening an inbound port towards the factory network is a request no IT lead should approve. Most projects stall here, and they stall for a good reason.

  • Every system has its own name for the same machine

    The PLC calls it a tag, the MES a code, the ERP a cost centre. Until a shared identity exists, cross-referencing means maintaining a mapping table by hand.

  • History is hostage to the format

    Data locked in a proprietary SCADA is readable for as long as that software stays under maintenance. That is the constraint you pay for years later, when you need a long comparison.

The method

Three steps, from the floor to the back office

Connect without exposing

The agent lives inside the OT network and opens the connection outwards itself. No inbound port, no NAT to revisit, no change to existing addressing.

Normalise onto one model

PLC tags, database rows and API responses become the same key-value format and receive asset identity: site, line, machine. From there on, the systems are talking about the same thing.

Give it back in an open form

History stays at original granularity and is exportable at any time. Technology lock-in becomes a choice rather than a condition.

What you can ask

Plain-language questions, answers from your own plants

  • Which assets are sending data now, and which have gone quiet?
    The state of every connected source with its last received value. A source that stops transmitting shows immediately, rather than as a gap in the month-end report.
  • Does the ERP production order match what the line actually made?
    The declared figure in the back office against the machine's real part count, on the same asset and the same period.
  • What traffic leaves the OT network towards Meddle?
    Outbound connections broken down by source and destination — the answer you need when the question comes from security.
  • Can we export the whole of last year's history?
    Yes, at the granularity it was collected and in the format you need. It is an ordinary feature, not an exit procedure.
Why it clears security

The questions the IT lead asks

  • Outbound traffic only. The connection always starts from inside the OT network. There is nothing to publish, nothing to expose and no perimeter firewall exception to maintain.
  • Role-based permissions and an audit trail. Every read and write is traced with user and timestamp, and environments stay separate. Writing to machines is its own permission, not a side effect of read access.
  • Data in Europe, NIS-2 ready. European cloud, on-premise in your own data centre, or hybrid with processing at the edge — the same architecture in all three cases.

Let's start with one line and one IT source.

A guided pilot connecting a production line and the back office: within weeks you can see the two worlds cross without touching the network configuration.

FAQ

Frequently asked questions

  • Do we have to open inbound ports on the OT network?

    No. The connection is always opened from the inside out, so there is nothing to expose and no inbound rule to create on the firewall. It is the first question security asks, and it is why the architecture is built this way.

  • Do we need to replace our existing SCADA or MES?

    No. Meddle reads them as sources, alongside the PLCs. The value is in cross-referencing what currently lives in separate systems, not in replacing them.

  • Does it work with PLCs from different brands?

    Yes: OPC-UA, Siemens S7, Modbus TCP/RTU, Logix and MQTT cover the mixed estates that are the norm. For most PLCs no hardware gateway is required.

  • What happens if the outbound connection drops?

    Edge processing continues and data is queued locally, then transmitted when the link returns. A network outage does not produce a hole in the history.

  • If we change platform one day, does the data stay ours?

    Yes. Standard protocols in, exportable history out, at original granularity. No lock-in is a property of the architecture, not a sales promise.

Let's look at how your network connects, without changing it.

In a guided demo we start from your architecture and your constraints, not from an example.

Book a demo