Cybersecurity project

Removable Media Security: A Persistent Challenge

Please use the form at the bottom of this page to let us know if this solution would be within your area of expertise.

The Growing Threat of Removable Media

Removable media—USB drives, external hard drives, SD cards, optical discs—remain a persistent attack vector in cybersecurity. According to the Honeywell 2025 Cyber Threat Report, one in four major security incidents in late 2024 and early 2025 were traced directly to malicious activity triggered by USB plug-and-play events. Data from the Honeywell 2024 USB Threat Report indicates that 51% of malware attacks were specifically designed for USB devices, representing a nearly 6x increase since 2019. The Ontinue 2025 Threat Report observed a 27% increase in USB-delivered malware in the first half of 2025 compared to late 2024, noting that many organizations still lack strong controls over removable media.
Network-based defenses such as firewalls protect the perimeter but do not address threats introduced physically inside secure networks. Removable drives move continuously between systems designed to be isolated, carrying software updates, diagnostic files, and data transfers essential to operations. Each device can also carry malware capable of propagating through critical systems within seconds.

A technician updates software via flash drive; a contractor connects diagnostic equipment; a supplier delivers a patch on removable media; an engineer transfers data between air-gapped networks: Routine maintenance activities can become the origin of significant security incidents.

The Decontamination Stations Solution

We are supporting a company that has deployed over 3,000 decontamination stations across 250+ organizations internationally. The solution consists of standalone appliances that scan, detect, and neutralize threats on removable media before connection to protected networks.

The appliances function independently of existing IT infrastructure and require no software installation on endpoint systems. Users insert media into the station, which performs automated scanning using multiple antivirus and antimalware engines running simultaneously. Known threats are detected through signature-based scanning. Unknown threats are identified through static analysis, with optional dynamic analysis and sandboxing capabilities. The system also detects BadUSB attacks—malicious code embedded in device firmware rather than stored files. Scanning typically completes in under one minute.

Physical hardening includes anti-intrusion strips, proprietary screws, and Kensington lock compatibility. The operating system is a hardened Linux distribution. Stations are designed, built, and assembled in France.

Organizations deploy these systems to address specific operational requirements:

  • Secure file transfer between untrusted and trusted network zones
  • Media sanitization at facility entry points
  • Policy enforcement for removable device usage across distributed operations
  • Offline and air-gapped environments where network connectivity is unavailable

System Components

Scanning stations

Available in four configurations: Console (desktop), Totem (floor-standing), Satellite (wall-mounted), and Mobile (ruggedized tablet meeting MIL-STD-810G and ATEX certifications for hazardous environments)

Management server

Centralized administration, logging, antivirus updates, and reporting across all stations. Deployment options include on-premise, cloud-hosted, and air-gapped configurations

Hardware Agent (optional)

Protects USB devices at the electronic and software layers, including BadUSB protection. The SecLab S-XU box holds ANSSI First Level Security Certification

Workstation Protect Agent (optional)

Software installed on workstations and industrial computers that verifies removable media has been scanned and certified by a station, blocking access to uncertified devices

Technical Capabilities

  • File transfer and USB key-to-key copying for direct transfer between drives
  • Military-grade data wiping
  • Support for encrypted containers and partitions (BitLocker, encrypted archives)
  • Multiple partition scanning
  • Configurable scanning policies by file type, extension, and size
  • Real-time log export to SIEM platforms via syslog API
  • Network file transfer via NFS, SAMBA, or SFTP after decontamination
  • User authentication on stations
  • Multilingual interface support
  • Connectivity options: 4G, 5G, WiFi, wired

Is This a Fit?