Frequently asked questions — DIANA Security Platform

Everything people ask us

How the platform works, the scenarios it's used in and what the service covers. If your question isn't here, write to us — we reply within 24 hours.

Categories
  1. 01 Technical 16
  2. 02 Use cases 11
  3. 03 Service delivery 11

01 Technical

How DIANA works, what it monitors and what it takes to set up.

01 What is DIANA?

DIANA is a cybersecurity and compliance management platform. It monitors your network, devices, cloud and — where present — OT environments, spots vulnerabilities and anomalies, and keeps the documentation for audits and certifications ready to go.

02 How does the monitoring work?

DIANA integrates with the data sources you already have (logs, firewalls, EDR, SIEM, cloud, NAS…); where those are missing, it provides them itself through its own modules (monitored assets, suspicious events, vulnerabilities, per-host risk score).

03 Do I have to install anything on my systems?

Network monitoring requires a hardware probe, available as an option if you don't already have network infrastructure ready to supply the necessary data (e.g. a mirror/SPAN port). For everything else, DIANA works mostly passively on your existing data sources.

04 Is the monitoring invasive? Does it slow down the network or my systems?

No. The monitoring is silent: it observes without actively intervening on networks, devices or production lines.

05 Does it integrate with the tools I already have (SIEM, EDR, firewall)?

Yes. DIANA doesn't replace the tools you already use: it integrates with your existing data sources to bring them together in a single view.

06 What if I don't already have the right tools (logs, firewall, SIEM…)?

That's not a problem. If you're missing the tools you need, DIANA can supply them directly through its own modules. Alternatively, a team of experts helps you assess and choose the solutions that best fit your specific needs, so you don't have to work out what you need on your own.

07 Does it also work on OT/industrial environments (PLC, SCADA, HMI)?

Yes, it is designed for that scenario too. The dedicated OT Cybersecurity section is currently being rolled out: get in touch for more information on availability.

08 Which standards and regulations does it support?

ISO/IEC 27001, NIS2, GDPR, ISO 42001, the AI Act, CRA, IEC 62443, as well as customer and supplier audits and customisable internal standards.

09 Does it work on cloud, on-premise or hybrid environments?

Yes, it covers hybrid or multi-vendor IT infrastructures, including partly cloud-based ones.

10 How is the collected data handled? Where is it hosted?

Data is hosted on cloud infrastructure in Europe. You can request an installation on your own infrastructure.

11 How are vulnerabilities and risks prioritised?

By how critical the context is (for example the production process the asset supports, not just the technical score of the vulnerability), so you focus first on what really matters.

12 What happens when an anomaly or a threat is detected?

DIANA raises an alert and tells you what to do about it, without requiring advanced security skills to interpret. Where you need a hand, a team of experts is always ready to help you resolve the problem.

13 Do I need a dedicated IT or security team to use it?

No. DIANA is designed for companies without an in-house team too: it automates the analysis and prioritisation that would otherwise call for specialist skills.

14
15 Who receives the alerts, and how?

Alerts appear on the dashboard and are sent by email to the contacts you choose. You can set different recipients for each severity level, so your systems administrator only gets what actually concerns them.

16 Do I need to install anything on company computers?

It depends on what you want to monitor. Network monitoring requires nothing on individual machines. For detailed visibility on endpoints and servers, a lightweight agent is installed, and it doesn't get in the way of the people using them.

02 Use cases

The scenarios companies most often start from.

01 Can I use DIANA just to get an inventory of every device on the company network?

Yes. DIANA automatically maps devices, systems and connections — shadow IT included — even as a first step, ahead of any other security or compliance goal.

02 Can I use DIANA to know straight away if someone accesses my systems in an unusual way?

Yes. It detects unexpected access, changed configurations or new devices on the network, and flags the anomaly along with what to do about it.

03 Can I use DIANA to work out which vulnerabilities to fix first?

Yes. Vulnerabilities are prioritised by real context (how critical the process or asset involved is), not just by technical score — useful when the resources to act are limited.

04 Can I use DIANA to get ready for an audit (NIS2, ISO 27001, GDPR)?

Yes. It gathers evidence and tracks compliance status continuously, so the documentation is already there instead of being rebuilt by hand when the audit approaches.

05 Can I use DIANA to manage who accesses my systems remotely (suppliers, maintenance staff)?

Yes. It maps remote access, detects unusual or unauthorised connections and checks access policies automatically.

06 Can I use DIANA to monitor a production line without stopping it?

Yes. In OT settings the monitoring is passive on PLC, SCADA and HMI: it observes the line without interrupting it, including on legacy or multi-vendor plants.

07 Can I use DIANA to automate work in my IT department?

Yes. It is also built for growing organisations that need to automate checks, evidence collection and reporting as people, systems and regulatory obligations change — without scaling up manual work in proportion.

08 Can I use DIANA without already knowing what I need, just to start understanding my level of risk?

Yes. Many companies start with no specific regulatory driver, simply needing visibility over their own security: it's one of the most common starting points.

09 A client has sent me a security questionnaire. Can DIANA help?

Yes, and it's one of the most common scenarios. DIANA shows you where you stand against the standard or the questionnaire, what's missing, and gathers the evidence to attach to your response. The same applies when the client cites no standard but imposes its own guidelines, or when it adds requirements stricter than the standard itself.

10 Can I use DIANA to see what my external IT provider is doing?

Yes. You can see which devices are added or changed, which updates have been applied and when, and who has connected remotely to your systems. It isn't there to check up on your provider: it's there so you know the state of your infrastructure without having to ask every time.

11 I build or install machines and production lines at my customers' sites. Can I use DIANA to protect myself?

Yes. By monitoring the part of the plant you supplied, you have a documented record of its condition. If something goes wrong on the line, you have objective data on what happened and where, instead of an argument between suppliers.

03 Service delivery

What the subscription covers, how to try it and how activation works.

01 What does a DIANA subscription include?

Every module of the platform, on any plan: no features are locked behind a higher tier. The only thing that changes is the maximum number of monitored devices.

02 Is extra hardware needed? Is it included in the price?

A hardware probe for network monitoring is available as an option, for anyone without network infrastructure already able to supply the necessary data. It is not included in the base subscription.

03 Can I try DIANA before buying?

Yes, in two different ways, made for different moments in your evaluation:

  • Free security assessment book a call with our team through the contact form. We analyse your infrastructure's context and give you a first picture of how exposed to risk you are, with no commitment.
  • Free platform trial get direct access to DIANA for 14 days, to see in practice how it monitors your infrastructure before deciding whether to take out a plan.
04 How does activation work after purchase?

Our team handles the initial installation and configuration. Timings vary with the complexity and size of the infrastructure to be monitored.

05 What happens if I exceed the number of devices on my plan?

You can move up to the next plan.

06 Is the subscription monthly or annual?

The subscription is monthly. You'll find the available plans further up this page.

07 Is support included in the subscription?

Yes, support is included.

08 Is it suitable for small companies with no IT team?

Yes, that's one of the main use cases: DIANA was built for people who have to manage security without dedicated in-house resources.

09 Do I decide when to act?

Yes. DIANA gives you the picture and the order of priority; the timing is yours. Some customers deal with high-severity issues straight away and group the rest into periodic maintenance, others prefer to act on everything immediately. The tool adapts to the way you work, not the other way around.

10 What happens if DIANA detects a problem at night or over the weekend?

DIANA monitors continuously, around the clock, and the alert is logged and sent the moment it occurs. Support requests are picked up by our team during service hours. If your situation calls for extended on-call cover, we'll agree on it as part of the contract.

11 Do I need a dedicated IT team?

No, and that's exactly the point: DIANA exists for companies that have to manage security without dedicated resources, in-house or external.

Find out your security and compliance level

Get in touch with our team. We'll get back to you within 24 hours.

Address Via Canelli 57, 10127 — Turin, Italy
Response Response within 24 hours
Request a free demo