// DHD · HANS STUDY · ONTARIO, CANADA

How the DHD works

Most of my engagements run through the DHD, a small hardened device that I ship to your site. You plug it into a switch port and it dials home: it opens an outbound-only connection to my network, and I do the work through it. That's where the name comes from. Nothing gets installed on your servers or workstations. When the engagement is over, you unplug it and send it back.

What it is and what it isn't

A purpose-built device configured to CIS benchmarks. It gives me the access an engagement needs, from a box you can see, label, and pull out of the rack. It isn't a remote-access agent installed on your servers, a VPN account added to your firewall, or a piece of software that stays behind after the work is done. It's hardware, and it leaves when the work is finished.

What gets plugged in where

The DHD sits wherever your policy allows: a spare switch port, a management VLAN, or a DMZ. One network cable in, and for most sites, nothing else. From there it connects out to my network over your internet connection or, where that's a better fit, its own 5G cellular link. The path runs one way, from the DHD to me, for the length of the engagement.

How the connection is secured

The DHD only makes outbound connections to my network. It doesn't accept inbound connections, so there's no port to open on your firewall and nothing on your network waiting to be reached.

Its storage and its connection are both encrypted with current industry-standard encryption, which protects the data on it if a DHD is lost in transit or physically tampered with.

It can use your internet connection or its own 5G cellular link, with a SIM I supply. On controls, CCTV, and access control networks, the cellular option keeps the DHD off your corporate internet entirely.

Who can reach it and how access is logged

Access runs through my side of the connection only; nobody else is granted a way in. Every session is logged on the DHD itself and on my logging servers. If you want the access logs for the engagement, ask, and you'll get them.

Using it on OT, CCTV, and access control networks

The DHD has been used on regulated sites. Where a site requires remote access to pass through an approved jump host, I work with your team to bring the DHD within your approval criteria, or we agree on another arrangement that fits your rules before anything is plugged in. Placement is your call. It goes where your policy allows, whether that's a DMZ, a management VLAN, or a single port on the network under review, and change control for the connection follows your process, not mine.

When the engagement ends

Unplug it and the engagement stops there. After every engagement the storage in the DHD is replaced and the device is reimaged before it goes to anyone else, so nothing from your network travels to the next site.

Managed DHD for ongoing support

For managed network and server care, the managed DHD stays on site for ongoing monitoring and management rather than a single engagement. It follows the same outbound-only design and the same logging, and because it can run over 5G, it suits controls and security-system networks that shouldn't depend on the corporate internet.

Questions IT and security teams ask

Do we need to install anything?

Not for most engagements. The DHD carries what the work needs.

Do we need to open firewall ports?

No. The DHD only connects outbound.

What if a DHD goes missing in shipping?

Its storage is encrypted, and access for that DHD is shut off on my side.

Can we get the logs?

Yes. Ask for the access logs for your engagement.

How do we end access early?

Unplug it. The engagement stops there.

Working through the DHD on your next engagement

Every priced page on this site that's delivered remotely runs through the DHD or your own access, whichever your policy prefers. A scoping call is the place to talk through placement before anything ships.