From one station to the whole organisation: USB security at scale

The question that comes up after the demo is always the same: how does this fit into what we already have?
usb scan station inside a data center

A USB scanning station that works on a single desk is useful. A USB scanning programme that works across thirty sites, a thousand users, and an existing security stack is the actual problem to solve. This article walks through how the link22 USB Scan Solution scales from the first unit to a deployment that covers a whole organisation, and what that integration looks like in practice.

The two-component architecture

Every deployment has two parts.

The scan station is the unit the user interacts with. Two USB ports, a touch screen, and a hardened operating system. This is where files are received and where the final clean transfer happens.

The link22 Data Guard is the server-side component. It runs the antivirus engines, performs the Content Disarm and Reconstruction work, and writes the audit log. In smaller deployments it can be packaged with the station itself. In larger deployments it runs centrally, with multiple stations feeding into it.

This separation matters for scaling. A single station can serve a department. A central Data Guard with multiple stations can serve a campus or a region. The scanning logic, the policies, and the logging stay consistent regardless of how many endpoints you deploy.

Why commercial off-the-shelf hardware

The hardware is intentionally standard. link22 uses commercial off-the-shelf (COTS) components rather than custom silicon. There are three reasons for that.

Performance and price scale better with the broader hardware market than with bespoke designs. Antivirus engines and CDR pipelines benefit from general-purpose compute, not specialised chips. A COTS path means you get faster scans this year and next year, without waiting for a vendor refresh.

Supply chain resilience is easier with components that exist outside a single vendor’s catalogue. If a part needs to be replaced, it can be replaced.

And finally, COTS means the security work happens in the software stack, where it can be reviewed, hardened, and audited. The trust boundary is in the operating system and the application logic, not in opaque hardware.

Three deployment patterns

Most organisations land in one of three patterns.

Standalone. A single station serves a single physical location. The Data Guard runs locally. Antivirus updates come in via internet, local network, or signed offline bundles, depending on the environment. This is the right model for small sites, single labs, or pilot deployments.

Multi-site, centralised admin. Multiple stations across different locations report to a central administrative interface. Policies, allowed file types, and update schedules are managed once and pushed everywhere. Logs aggregate to one place. This is how a typical mid-size to large organisation runs the solution: each office, lab, or operational site gets a station, and the security team manages all of them centrally.

Air-gapped operational environment. Stations operate in a network segment that has no inbound or outbound internet connection. Updates are delivered through signed offline media on a defined schedule. This is the model for critical infrastructure operators, defence-adjacent environments, and regulated industries where the network boundary is non-negotiable.

The same product supports all three patterns. The choice is a deployment decision, not a procurement decision.

How it complements existing security infrastructure

A USB scan station is not a replacement for the rest of your stack. It is a checkpoint at a specific point in the data flow, the one place where physical media meets your environment. It pairs with everything else you already run.

Endpoint protection still inspects what happens on workstations. Network segmentation still controls what traffic moves between zones. SIEM systems still aggregate events. The scan station adds one more event stream and one more enforcement point: removable media coming in.

For organisations running cross-domain solutions or data diodes between security zones, the USB Scan Solution closes a gap that those tools were not designed for. A diode controls the one-way movement of files between connected networks. A scan station controls the controlled movement of files from outside the perimeter onto removable media that gets used inside. The two are complementary, not overlapping.

What centralised administration covers

The admin interface is the part of the deployment that scales. From one screen, a security team can:

  • See every station’s status, last scan, and update state
  • Push policy changes (file types allowed, engines used, transfer limits)
  • Review aggregated logs across the entire fleet
  • Schedule offline update distribution for air-gapped sites
  • Export audit data for compliance reporting

The interface is built for operators who manage security tools, not for end users. End users see the touch screen on the station. The complexity stays where the complexity belongs.

Starting small and scaling deliberately

Most deployments do not start with thirty stations. They start with one, in a pilot site or a high-risk location, and grow from there.

This is by design. The product is the same at any scale, so a pilot deployment is not a throwaway. The unit deployed in week one is the same unit that gets folded into central administration in month six. The configuration carries over. The logs carry over. The investment compounds rather than restarting.

Whether you need a single checkpoint or a fleet, the architecture is the same. The scaling is a matter of how many stations you deploy and how you choose to administer them, not a matter of which version of the product you buy.

Learn more about the link22 USB Scan Solution at link22.eu/product/usb-scan-solution/.

Marcus Ekbäck - Business Area Manager CDS

Contact us!​

Sign up for our newsletter!​