Independently validated. Overlay security for brownfield OT.
Irish Manufacturing Research validated Access Gate in an industrial OT testbed: identity-based access, segmentation, and auditor-readable evidence, with no agents and no re-IPing.
“A network overlay can enforce stronger security while preserving the behaviour of industrial communications: without agents on legacy devices, without re-IPing production assets, and without redesigning the underlay network.”
Core finding, IMR / Trout feasibility study. Independent feasibility study conducted by IMR AM Lab under Enterprise Ireland Innovation Partnership IP20252213Y.
Stronger control, without disrupting production.
Industrial traffic kept working.
Modbus reads, OPC-UA sessions and subscriptions, MQTT topic governance, browser-based HMI sessions, and scoped remote-desktop access all functioned correctly through the overlay. Tested at the workflow level, not just by port reachability.
Proven by denial.
Unauthorised Modbus writes, control-topic publishes, and lateral pivots were blocked and logged. Broad implicit trust was replaced with narrow, identity-bound, auditable access paths scoped to a single service and asset.
Auditors can read it.
Access logs, policy exports, and rollback records were structured to map to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness, so a cyber lead, an OT engineer, and an auditor can each interpret the same evidence base.
Industrial OT testbed, representative brownfield plant network. Tested at the workflow level.
One evidence base, four frameworks.
NIS2 and its technical baselines expect risk management, access control, segmentation, and audit evidence at the OT layer, which is exactly where those obligations are hardest to satisfy. The study structured Access Gate's access logs, policy exports, and rollback records so the same evidence maps to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness.
That matters for industrial operators in scope of NIS2: a cyber lead, an OT engineer, and an auditor can each read the same records against the framework they answer to. See NIS2 compliance for industrial operators and the NIS2 compliance solution.
“Working with Trout, we validated Access Gate as a reference implementation of overlay security for brownfield OT. It added identity-based access, segmentation, and audit evidence to a representative plant network without touching the underlay, and produced evidence strong enough for a cyber lead, an OT engineer, and an auditor to interpret.”
Dermot Murphy
IIoT Technologist, Irish Manufacturing Research (Principal Investigator)
Validated in a testbed. Ready for production.
The same overlay approach IMR validated brings identity-based access, segmentation, and NIS2-ready audit evidence to your OT network, without agents, re-IPing, or underlay changes.
The technology validated
Access Gate is Trout's agent-free zero-trust overlay for OT and IT. It adds identity-based access, segmentation, and audit evidence to existing plant networks without inline appliances, agents, or re-IPing.
Enterprise Ireland Innovation Partnership
Conducted by Irish Manufacturing Research (IMR) AM Lab under Enterprise Ireland Innovation Partnership IP20252213Y. Access Gate was assessed as the reference implementation of a vendor-neutral network-overlay security model.
IMR Validation FAQ
OT protocols validated through the overlay
Irish Manufacturing Research (IMR), an independent research and technology organisation, ran the feasibility study in its AM Lab under an Enterprise Ireland Innovation Partnership (Project IP20252213Y). Access Gate was assessed as the reference implementation of a vendor-neutral network-overlay security model.
A representative brownfield plant network in an industrial OT testbed. The team validated five protocols (Modbus TCP, OPC-UA, MQTT, web, RDP), six use-case families from remote access to containment, and mapped the resulting evidence to six CyFun functions from Govern through Recover. Tests were run at the workflow level rather than by port reachability alone.
NIS2 and its technical baselines expect risk management, access control, segmentation, and audit evidence at the OT layer, which is exactly where they are hardest to satisfy. The study structured Access Gate's logs, policy exports, and rollback records to map directly to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness, so the same evidence base supports an audit under multiple frameworks.
No. The core finding is that a network overlay can enforce stronger security while preserving the behaviour of industrial communications: without agents on legacy devices, without re-IPing production assets, and without redesigning the underlay network. Access Gate added identity-based access, segmentation, and audit evidence to the plant network without touching the underlay.