TroutTrout

Zero Trust without agents on the asset.

Most OT devices cannot run security agents. Here is how to enforce identity-bound access, segmentation, and audit at the network layer, in front of the asset, so the device never changes.

The short answer

Agentless Zero Trust puts the enforcement point on the network, not on the device. An overlay sits next to your OT network and brokers every session: it checks who the user is, what they are allowed to do, and records it, before traffic ever reaches the PLC, HMI, or SCADA server. The asset installs nothing and never changes. Trout Software's Access Gate works this way.

Monitoring vs enforcement

Detection tells you. Enforcement stops it.

Most agentless OT security is passive: it watches traffic and flags anomalies. That is useful, but on a legacy PLC that cannot run an agent, a passive tool sees a malicious command only after it has been sent. An in-path industrial proxy is different. It terminates the session, checks identity and the specific command against policy, and forwards only what is authorized, so it denies an attack in real time instead of reporting it after the fact. Passive OT monitoring platforms detect and alert; an in-path enforcement point like Trout's Access Gate can also deny the command.

Passive monitoring

Detects anomalies after the fact and cannot block a command mid-session. It adds visibility, not control. On its own it leaves the asset reachable.

In-path industrial proxy

Authenticates the user, authorizes the exact command, records the session, and denies anything outside policy in real time. Protocol-aware for OT (Modbus, DNP3, and more), not a generic reverse proxy.

Built for OT resilience. Industrial processes prioritize uptime, so the proxy runs with failover and a break-glass path: operators always reach the asset in an emergency, and a single fault never stops the process. This is what lets an in-path enforcement point live in a critical environment.

Why agents fail in OT

Why can't OT devices run a security agent?

IT Zero Trust assumes the device can host an agent that checks posture, enforces policy, and reports telemetry. OT cannot make that assumption. So the question is not whether to deploy without agents. It is whether the network-layer enforcement that replaces them is strong enough.

Closed operating systems

Proprietary real-time OSes on PLCs and controllers do not allow third-party software to be installed.

Timing that cannot slip

Deterministic control loops cannot tolerate the jitter an agent introduces. A few milliseconds is a fault.

Warranties that void

OT vendor support and warranties typically void the moment endpoint software touches the device.

Compensating controls

What replaces the agent in agentless OT security?

When the asset cannot host security software, the enforcement point moves to the boundary in front of it. Each capability below is what the agent would have done, delivered at the network layer instead.

Identity-bound access

MFA is enforced at the network boundary against your identity provider. Each session is tied to a named user, not a shared or service credential, and the asset never sees the identity directly.

Per-session authorization

Policy is per asset, per protocol, per session. A user can read a Modbus register on one PLC and be denied write on another, inside the same authenticated session.

Tamper-evident audit

Every session is logged with user, time, asset, protocol, and payload. Records are hash-chained and signed, so they stand up as audit evidence, not just alerts.

Microsegmentation

An overlay enforces per-asset boundaries on top of the existing network, aligned to IEC 62443 zones and conduits. The Layer 2 topology does not change, so safety and control assets can share a VLAN yet stay isolated.

Encryption for legacy protocols

Modbus, DNP3, OPC UA, and EtherNet/IP are wrapped in TLS at the boundary and forwarded natively to the asset. The device does not need to support TLS itself.

Just-in-time vendor access

Vendor and contractor sessions are scoped, time-bound, and revocable, and access closes automatically when the session ends. This is the controlled vendor remote access that NERC CIP-003-9 and NIS2 require, with no standing VPN tunnels or shared credentials.

Deployment

Access Gate adapts to your network

Pick your environment to see where the Access Gate sits, how much Zero-Trust coverage you get, and the migration path, from full coverage to partial coverage.

Access Gate: deploy Zero-TrustSelect an option to highlight its path
See the full deployment guide
Questions

Agentless Zero Trust, answered

You move the enforcement point off the device and onto the network. An industrial proxy sits in the access path in front of the PLC, authenticates the user, authorizes the specific command against policy, and records the session before anything reaches the controller. Unlike passive monitoring, which flags a malicious command only after it has been sent, an in-path proxy denies it in real time. Because OT lives and dies by uptime, the proxy is built for resilience, with failover and a break-glass path so enforcement never costs availability. Trout's Access Gate takes this approach and has been validated by a NATO navy for its most critical workloads.

Agentless Zero Trust enforces identity-based access, segmentation, and audit without installing software on the protected asset. Enforcement happens at a network boundary in front of the asset, not inside it. It is the practical posture for legacy OT, where most devices cannot host an agent.

Three reasons. Proprietary real-time operating systems on PLCs and industrial controllers do not allow third-party software. Deterministic control loops cannot tolerate the timing jitter an agent introduces. And OT vendor warranties typically void if endpoint software is installed.

No. Passive monitoring flags anomalies after the fact, but it does not block a malicious command in an active remote-access session until it has been sent. Agentless Zero Trust pairs visibility with enforcement at the network boundary that can deny a session in real time, not just log it.

A firewall asks whether a port is allowed between two subnets. Agentless Zero Trust asks whether this specific user, in this specific session, may send this specific command to this specific asset, right now. The firewall enforces at Layer 4. Zero Trust enforces at the application layer, with identity binding, session attribution, and full payload logging.

Access Gate is an on-premise appliance or VM that brokers access to OT assets at a network boundary. It runs next to the network, not inline, so production keeps running if it goes down. Every session terminates at the appliance, where authentication, authorization, and recording happen before traffic reaches the asset. The asset installs nothing and never sees the user identity directly.

The second layer of value

Access Gate secures your assets first, then exposes the simple services your teams and vendors actually want, so they run through the sanctioned path, not around it.

OT runs through you, not around you.