The challenge
Brownfield OT networks are hard to secure without breaking them. Legacy PLCs and HMIs cannot run agents. Production assets cannot be re-IPed on a whim. And the underlay network, grown over years, cannot be redesigned during a change freeze. Yet regulators expect segmentation, identity-based access, and audit evidence at exactly this layer, where it is hardest to deliver.
Irish Manufacturing Research (IMR), an independent research and technology organisation, set out to test a question that matters to every industrial operator now in scope of NIS2: can a network overlay add real security to a representative plant network without disrupting the industrial communications that keep it running?
The study
Under an Enterprise Ireland Innovation Partnership (Project IP20252213Y), IMR's AM Lab ran an independent feasibility study in an industrial OT testbed, assessing Access Gate as the reference implementation of a vendor-neutral network-overlay security model.
The team validated five protocols (Modbus TCP, OPC-UA, MQTT, web, and RDP) across six use-case families, from remote access through to containment. Crucially, they tested at the workflow level rather than by port reachability alone: Modbus reads, OPC-UA sessions and subscriptions, MQTT topic governance, browser-based HMI sessions, and scoped remote-desktop access all had to function correctly through the overlay.
They then probed the other direction. Unauthorised Modbus writes, control-topic publishes, and lateral pivots were attempted, and each was blocked and logged. Broad implicit trust was replaced with narrow, identity-bound, auditable access paths scoped to a single service and asset.
Results
The core finding: a network overlay can enforce stronger security while preserving the behaviour of industrial communications, without agents on legacy devices, without re-IPing production assets, and without redesigning the underlay network.
Least privilege was proven by denial, not just asserted. And the evidence was built to be read: access logs, policy exports, and rollback records were structured to map to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness, so a cyber lead, an OT engineer, and an auditor can each interpret the same records against the framework they answer to.
For the full scope, protocols, and framework mapping, see the IMR validation report.