TroutTrout
Back to Blog
OT SecurityRemote AccessComparisonSegmentation

Siemens SINEMA and Scalance: What Sits Between Remote Access and Segmentation

Trout Team4 min read

The short version

Siemens gets the architecture right and charges you in hardware. SINEMA Remote Connect is a server you run yourself, so there is no vendor cloud in the access path and no third-party rendezvous to document under NIS2. On the question that trips up Talk2M and IXON Cloud, Siemens is already on the correct side.

Segmentation is the separate purchase. To divide the plant you deploy Scalance firewalls at the boundaries you want enforced, which means hardware per boundary, configuration per boundary, and in most retrofits, cabling. The architecture is sound. The bill and the change window scale with how many zones you actually want.

Where Siemens is strong

Self-hosted by default. SINEMA RC runs on your infrastructure. When procurement asks who operates the path into your plant, the answer is you. That removes an entire category of supply-chain paperwork, and it is the reason Siemens and Secomea both survive conversations that cloud-brokered gateways do not.

Integrated with the automation stack. If the plant is already Siemens end to end, the remote-access product speaks the same language as the PLCs, the engineering tooling and the support contract. That coherence is worth real money and should not be dismissed.

Scalance is a proper firewall. This is not a criticism of the hardware. It does what industrial firewalls do, and it does it from a vendor that understands industrial environments.

Where the cost actually lands

The gap is not capability, it is the unit of deployment.

Zone-based segmentation with firewalls means one device per boundary. Ten zones is ten devices to buy, rack, cable, configure and keep patched. In a greenfield build that is a line item. In a running plant it is a project: you are inserting hardware into paths that currently carry production traffic, which means planning, a change window, and a rollback story for each one.

That is the reason so many IEC 62443 zone-and-conduit designs exist as a document rather than as a configuration. The design is agreed, the hardware is quoted, and the retrofit never finds a window.

The same arithmetic applies to the remote-access side. A gateway per machine plus a firewall per boundary is an estate: a site with fifteen machines and six zones is twenty-one devices, each with a firmware version, a certificate and a configuration that drifts from its neighbours. The operational cost is not the purchase, it is that no single place answers who can reach what.

The overlay alternative

The other way to enforce a boundary is to stop treating it as a physical location. An overlay puts each asset in an enclave defined in software, with the enforcement point in the path but the topology untouched. Assets keep their IP address, gateway and VLAN. There is no per-boundary hardware, because the boundary is policy rather than a box, and adding a zone is a configuration change rather than a purchase order.

Practically, that collapses the two purchases into one appliance: the remote-access broker and the segmentation enforcement point are the same device, so the technician's session and the enclave policy are decided in the same place and logged in the same record.

The comparison in one table

SINEMA RC + ScalanceTrout Access Gate
Broker locationYour serverYour appliance
Vendor cloud in pathNoNo
Segmentation methodFirewall per boundaryOverlay enclaves in software
Cost of an extra zoneAnother applianceA policy change
Re-cabling to segmentUsually, in a retrofitNone
Asset inventoryNot part of the productAutomatic discovery
Detection and alertingNot part of the remote-access productSnort rules, curated alert library, SIEM forwarding

Deploy both, not one instead of the other

Keep SINEMA RC. It is self-hosted, it is integrated with the automation stack, and on the sovereignty question it is already on the right side. Nothing here argues for removing it.

The risk is remote access without a control point behind it. A gateway per machine gives you doors into the plant, and unless something governs what passes through them at protocol level, your only enforcement is whatever Scalance boundaries you have managed to fund and install.

The solid architecture is both. Keep SINEMA RC for connectivity, put Access Gate behind it for the enforcement and visibility layer, and you get the IEC 62443 zone model as software policy rather than as a hardware bill that never finds its retrofit window.

Related reading