Cyber-diversion attacks against industrial control systems try to smuggle unauthorized command packets from a compromised IT network into the OT network that runs physical equipment — pumps, valves, breakers. This simulator renders the boundary between the two networks in 3D and lets you fire malicious command packets at it under two real defensive architectures: a hardware data diode, which is physically incapable of carrying traffic in the sabotage direction, and a software firewall rule, which blocks based on configuration and therefore carries a small but real per-packet leak probability. Live counters track blocked attempts, successful breaches, delivered telemetry and the resulting OT process integrity, and a governing-formula panel explains why the two architectures behave so differently under rising attack intensity.