How the platform works, the scenarios it's used in and what the service covers. If your question isn't here, write to us — we reply within 24 hours.
How DIANA works, what it monitors and what it takes to set up.
DIANA is a cybersecurity and compliance management platform. It monitors your network, devices, cloud and — where present — OT environments, spots vulnerabilities and anomalies, and keeps the documentation for audits and certifications ready to go.
DIANA integrates with the data sources you already have (logs, firewalls, EDR, SIEM, cloud, NAS…); where those are missing, it provides them itself through its own modules (monitored assets, suspicious events, vulnerabilities, per-host risk score).
Network monitoring requires a hardware probe, available as an option if you don't already have network infrastructure ready to supply the necessary data (e.g. a mirror/SPAN port). For everything else, DIANA works mostly passively on your existing data sources.
No. The monitoring is silent: it observes without actively intervening on networks, devices or production lines.
Yes. DIANA doesn't replace the tools you already use: it integrates with your existing data sources to bring them together in a single view.
That's not a problem. If you're missing the tools you need, DIANA can supply them directly through its own modules. Alternatively, a team of experts helps you assess and choose the solutions that best fit your specific needs, so you don't have to work out what you need on your own.
Yes, it is designed for that scenario too. The dedicated OT Cybersecurity section is currently being rolled out: get in touch for more information on availability.
ISO/IEC 27001, NIS2, GDPR, ISO 42001, the AI Act, CRA, IEC 62443, as well as customer and supplier audits and customisable internal standards.
Yes, it covers hybrid or multi-vendor IT infrastructures, including partly cloud-based ones.
Data is hosted on cloud infrastructure in Europe. You can request an installation on your own infrastructure.
By how critical the context is (for example the production process the asset supports, not just the technical score of the vulnerability), so you focus first on what really matters.
DIANA raises an alert and tells you what to do about it, without requiring advanced security skills to interpret. Where you need a hand, a team of experts is always ready to help you resolve the problem.
No. DIANA is designed for companies without an in-house team too: it automates the analysis and prioritisation that would otherwise call for specialist skills.
Alerts appear on the dashboard and are sent by email to the contacts you choose. You can set different recipients for each severity level, so your systems administrator only gets what actually concerns them.
It depends on what you want to monitor. Network monitoring requires nothing on individual machines. For detailed visibility on endpoints and servers, a lightweight agent is installed, and it doesn't get in the way of the people using them.
The scenarios companies most often start from.
Yes. DIANA automatically maps devices, systems and connections — shadow IT included — even as a first step, ahead of any other security or compliance goal.
Yes. It detects unexpected access, changed configurations or new devices on the network, and flags the anomaly along with what to do about it.
Yes. Vulnerabilities are prioritised by real context (how critical the process or asset involved is), not just by technical score — useful when the resources to act are limited.
Yes. It gathers evidence and tracks compliance status continuously, so the documentation is already there instead of being rebuilt by hand when the audit approaches.
Yes. It maps remote access, detects unusual or unauthorised connections and checks access policies automatically.
Yes. In OT settings the monitoring is passive on PLC, SCADA and HMI: it observes the line without interrupting it, including on legacy or multi-vendor plants.
Yes. It is also built for growing organisations that need to automate checks, evidence collection and reporting as people, systems and regulatory obligations change — without scaling up manual work in proportion.
Yes. Many companies start with no specific regulatory driver, simply needing visibility over their own security: it's one of the most common starting points.
Yes, and it's one of the most common scenarios. DIANA shows you where you stand against the standard or the questionnaire, what's missing, and gathers the evidence to attach to your response. The same applies when the client cites no standard but imposes its own guidelines, or when it adds requirements stricter than the standard itself.
Yes. You can see which devices are added or changed, which updates have been applied and when, and who has connected remotely to your systems. It isn't there to check up on your provider: it's there so you know the state of your infrastructure without having to ask every time.
Yes. By monitoring the part of the plant you supplied, you have a documented record of its condition. If something goes wrong on the line, you have objective data on what happened and where, instead of an argument between suppliers.
What the subscription covers, how to try it and how activation works.
Every module of the platform, on any plan: no features are locked behind a higher tier. The only thing that changes is the maximum number of monitored devices.
A hardware probe for network monitoring is available as an option, for anyone without network infrastructure already able to supply the necessary data. It is not included in the base subscription.
Yes, in two different ways, made for different moments in your evaluation:
Our team handles the initial installation and configuration. Timings vary with the complexity and size of the infrastructure to be monitored.
You can move up to the next plan.
The subscription is monthly. You'll find the available plans further up this page.
Yes, support is included.
Yes, that's one of the main use cases: DIANA was built for people who have to manage security without dedicated in-house resources.
Yes. DIANA gives you the picture and the order of priority; the timing is yours. Some customers deal with high-severity issues straight away and group the rest into periodic maintenance, others prefer to act on everything immediately. The tool adapts to the way you work, not the other way around.
DIANA monitors continuously, around the clock, and the alert is logged and sent the moment it occurs. Support requests are picked up by our team during service hours. If your situation calls for extended on-call cover, we'll agree on it as part of the contract.
No, and that's exactly the point: DIANA exists for companies that have to manage security without dedicated resources, in-house or external.
Get in touch with our team. We'll get back to you within 24 hours.