Skip to content
CIAS MultiSphera
Security

Security and compliance

The basic protections are always included; CyberShield adds advanced features for stricter policies. What MultiSphera protects, and with which mechanisms.

Subscription

CyberShield

Advanced security features, for stricter policies.

  • Mandatory two-factor authentication, password expiry and history
  • Operations log with a hash chain, to detect tampering
  • Export to SIEM of security events
  • Company CA certificates, time windows, single session, per-user permissions
  • Encryption of the channel to the devices with the new generation of CIAS terminal servers (coming in 2027)

Always included, even without CyberShield: authentication, HTTPS, deny-by-default permissions, attempt lockout, event log for 24 months, security advisories and patches.

At expiry: 30 days of notice and 30 days of grace, then the advanced features are switched off. Surveillance continues.

Always included, or with CyberShield

The basic protections are always included. CyberShield adds the features required by stricter security policies. The 90-day trial licence includes everything.

FeatureAlways includedWith CyberShield
Authentication, passwords stored with bcrypt, CSRF protection, HTTPSyesyes
Deny-by-default permissions, per roleyesyes
WebSocket over TLS and installation certificateyesyes
Lockout after failed attempts, sign-out after inactivityyesyes
Event log for 24 months and archiveyesyes
Security advisories and updatesyesyes
Mandatory two-factor authentication, password expiry and historynoyes
Operations log with a hash chain, export to SIEMnoyes
TLS certificates issued by the company CAnoyes
Time windows, single session, per-user permissionsnoyes
Encryption of the channel to the devices, with the new generation of CIAS terminal servers (coming in 2027)noyes
Principles

Security by design

Encrypted communications, a certificate for each installation, deny-by-default permissions, a retained event log. NIST/FIPS-approved cryptographic algorithms, such as AES-256-GCM, SHA-256, HKDF-SHA256 and ECDHE P-256.

On the site network

No cloud service is needed for surveillance. Events and logs stay in the installation.

Denied by default

Anyone who is not an administrator sees only what their role explicitly allows.

Encrypted in transit

HTTPS, WebSocket over TLS, CIAS04 over TLS 1.3 with mutual authentication.

Traceable

Event log kept online for 24 months, then in a verified archive.

Device channel

From terminal server to server, encrypted Coming in 2027

With the new generation of CIAS terminal servers and the new firmware, each terminal server will have its own key and the channel to the server will be encrypted. Previous-generation terminal servers do not encrypt the channel.

Channel encryption will be part of CyberShield.

Key exchange
ECDHE P-256, authenticated with a pre-shared key dedicated to each terminal server
Encryption
AES-256-GCM
Key derivation
HKDF-SHA256
Replays
protection against message replay
Allowed terminal servers
list of identifiers signed by CIAS, with protection against rollback to earlier versions
Network

Designed for the site network

MultiSphera is designed for the site’s local network and must not be exposed to the Internet.

  • Operator workstations: web interface over HTTPS and real-time updates over encrypted WebSocket (TLS).
  • Remote access: through the company network or a VPN, never by exposing the server to the Internet.
  • Terminal servers: CIAS terminal servers on the site network; with the new generation the encrypted channel is coming.
  • Third-party systems: CIAS02, CIAS03 and CIAS04 plugins, the latter over TLS 1.3 with mutual authentication; WebAPI over HTTPS.
  • CIAS portal: optional connection; activation and updates also with files.
Access

Who gets in, and what they can do

  • Roles: Administrator, Operator, Installer, No access
  • Permissions: per module, menu and action, denied by default
  • Lockout: after repeated failed sign-in attempts
  • Automatic sign-out: after inactivity, with a configurable time
  • With CyberShield: mandatory two-factor authentication (app or e-mail), password expiry and history, single session, sign-in time windows
Event log

Events kept, not lost

  • 24 months online, then a local archive month by month
  • SHA-256 fingerprints and a chain of archive manifests
  • No deletion before the month is archived and read back
  • Restore of an archived month from the Event log page
  • With CyberShield an operations log with a hash chain and export to SIEM
Updates

Security patches for everyone

Even without a subscription

Security advisories and updates are available for every installation, with or without Sphera+.

Signed

Packages and advisories signed with Ed25519, identical online and offline.

Your data stays with you

The diagnostic package for support is pseudonymised and is sent only if an administrator authorises it.

Compliance

MultiSphera is designed to support the security requirements of the NIS2 directive and the Cyber Resilience Act: controlled access, attempt lockout, encryption, activity logging, security updates for everyone. The details are in the product’s technical documentation.