Skip to content

Industrial Outcomes

L2Proxy is designed around operating outcomes rather than packet volume. It helps plant owners control remote work, protect consequential operations, reduce investigation time, and demonstrate what occurred without asking every stakeholder to interpret protocol trees.

Raymon industrial operation control model from physical process to evidenced outcome

Figure — Industrial operation control model: Raymon evaluates operation context, intent, and outcome—not only connectivity.

Outcomes by industrial responsibility

Stakeholder Practical outcome
Operations Understand which asset and operation were involved and whether activity was permitted or blocked
Control and protection engineering Express permitted commands, values, sequences, prerequisites, and equipment states as reviewable policy
Maintenance management Limit a remote user to the equipment and operations required for an approved task
OT cybersecurity Connect authenticated identity and session activity to decoded industrial behavior and policy results
Asset owner Retain a searchable record of access, operations, deviations, and enforcement decisions
Audit and investigation Trace a readable industrial event back to the session, rule decision, and detailed protocol evidence

Remote work with industrial least privilege

Traditional remote access can establish who connected and which network was reachable. L2Proxy Connect adds the industrial question: What did that user attempt to do after connecting?

A customer can distinguish monitoring from control, restrict access to assigned equipment, apply value and sequence conditions, record approved activity, and block a specific prohibited operation without treating every authenticated session as equally trusted.

Protection aligned with equipment

Policies can begin with equipment that plant teams already understand: breakers, transformers, relays, reclosers, regulators, capacitor banks, busbars, and DER interties. Their points, operating ranges, commands, expected states, and prerequisites provide the context for practical baseline protection.

Examples include:

  • permit monitoring while restricting control;
  • require a valid Select-Before-Operate sequence;
  • prevent a setpoint outside an approved engineering range;
  • detect a command without expected status feedback;
  • constrain maintenance actions to the assigned user and session;
  • record restart, recovery, alarm, and configuration-change sequences.

Faster, more defensible policy engineering

The Equipment and Protection Library, Guided Policy Composer, reusable industrial rule templates, contextual autocomplete, inline help, and expression validation reduce the effort required to move from an operating requirement to a reviewable policy. Generated policy remains manageable, testable, and traceable through its deployment lifecycle.

Evidence in the language of the plant

L2Proxy preserves detailed protocol facts while presenting equipment, point, operation, direction, category, severity, criticality, tags, and a readable industrial description. With L2Proxy Connect, the same evidence can include authenticated user and session context.

This helps answer:

  • Who performed or attempted the operation?
  • Which equipment and point were affected?
  • Was the activity monitoring, control, maintenance, or configuration?
  • Which policy matched and what decision was made?
  • What protocol evidence supports that conclusion?

Controlled adoption in operating plants

Customers can begin with passive observation and recorded decisions, validate policy against representative traffic, and activate blocking only after operational review. L2Proxy Connect and standalone services can coexist, allowing each access path and industrial boundary to use the enforcement model appropriate to its risk and ownership.

Continue with Product Architecture, L2Proxy Connect, or Deployment Choices.