TroutTrout
All Case Studies
ManufacturingNIS2 / IEC 62443OT testbed overlay

Irish Manufacturing Research

Access Gate validated as a reference implementation of overlay security for brownfield OT

SectorIndustrial research and technology organisationLocationIrelandCompany SizeResearch & technology organisation
5Protocols validatedModbus TCP, OPC-UA, MQTT, web, and RDP, tested at the workflow level
6CyFun functions mappedEvidence structured across Govern through Recover
4Frameworks coveredOne evidence base for CyFun, NIS2, IEC 62443, and ISO/IEC 27001
0Underlay changesNo agents on legacy devices, no re-IPing of production assets

The challenge

Brownfield OT networks are hard to secure without breaking them. Legacy PLCs and HMIs cannot run agents. Production assets cannot be re-IPed on a whim. And the underlay network, grown over years, cannot be redesigned during a change freeze. Yet regulators expect segmentation, identity-based access, and audit evidence at exactly this layer, where it is hardest to deliver.

Irish Manufacturing Research (IMR), an independent research and technology organisation, set out to test a question that matters to every industrial operator now in scope of NIS2: can a network overlay add real security to a representative plant network without disrupting the industrial communications that keep it running?

The study

Under an Enterprise Ireland Innovation Partnership (Project IP20252213Y), IMR's AM Lab ran an independent feasibility study in an industrial OT testbed, assessing Access Gate as the reference implementation of a vendor-neutral network-overlay security model.

The team validated five protocols (Modbus TCP, OPC-UA, MQTT, web, and RDP) across six use-case families, from remote access through to containment. Crucially, they tested at the workflow level rather than by port reachability alone: Modbus reads, OPC-UA sessions and subscriptions, MQTT topic governance, browser-based HMI sessions, and scoped remote-desktop access all had to function correctly through the overlay.

They then probed the other direction. Unauthorised Modbus writes, control-topic publishes, and lateral pivots were attempted, and each was blocked and logged. Broad implicit trust was replaced with narrow, identity-bound, auditable access paths scoped to a single service and asset.

Results

The core finding: a network overlay can enforce stronger security while preserving the behaviour of industrial communications, without agents on legacy devices, without re-IPing production assets, and without redesigning the underlay network.

Least privilege was proven by denial, not just asserted. And the evidence was built to be read: access logs, policy exports, and rollback records were structured to map to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness, so a cyber lead, an OT engineer, and an auditor can each interpret the same records against the framework they answer to.

For the full scope, protocols, and framework mapping, see the IMR validation report.

Working with Trout, we validated Access Gate as a reference implementation of overlay security for brownfield OT. It added identity-based access, segmentation and audit evidence to a representative plant network without touching the underlay, and produced evidence strong enough for a cyber lead, an OT engineer and an auditor to interpret.
Dermot Murphy · IIoT Technologist (Principal Investigator), Irish Manufacturing Research