Independently validated. Overlay security for brownfield OT.
Irish Manufacturing Research validated Access Gate in an industrial OT testbed: identity-based access, segmentation, and auditor-readable evidence, with no agents and no re-IPing.
Last updated:
“A network overlay can enforce stronger security while preserving the behaviour of industrial communications: without agents on legacy devices, without re-IPing production assets, and without redesigning the underlay network.”
Core finding, IMR / Trout feasibility study. Independent feasibility study conducted by the IMR Lab under Enterprise Ireland Innovation Partnership IP20252213Y.
Stronger control, without disrupting production.
Industrial traffic kept working.
Modbus reads, OPC-UA sessions and subscriptions, MQTT topic governance, browser-based HMI sessions, and scoped remote-desktop access all functioned correctly through the overlay. Tested at the workflow level, not just by port reachability.
Proven by denial.
Governed sessions are brokered through the overlay, where policy is enforced at the protocol level. Unauthorised Modbus writes, control-topic publishes, and lateral pivots were denied and logged, while the underlying process kept running. Broad implicit trust was replaced with narrow, identity-bound, auditable paths scoped to a single service and asset.
Auditors can read it.
Access logs, policy exports, and rollback records were structured to map to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness, so a cyber lead, an OT engineer, and an auditor can each interpret the same evidence base.
Adjacent overlay. Governed sessions brokered.
Access Gate runs next to the network, not in the middle of it. Only the routable north-south sessions it governs, remote access, engineering, vendor, and supervisory traffic, are brokered through the overlay, where policy is enforced at the protocol level. A write can be denied because that session rides the overlay, not because a box sits inline on the control loop.
Enforcement is at the function-code level, read from the protocol on the wire: a governed Modbus TCP session (port 502) can allow FC03 holding-register reads while denying FC06 and FC16 writes to control registers, with each denial logged. Cyclic controller-to-I/O traffic stays on the underlay and is never in the enforcement path, so if Access Gate is unavailable the running process keeps going. Fail-open versus fail-closed is a per-asset, logged decision, and the overlay runs as a high-availability pair.
Industrial OT testbed, representative brownfield plant network. Tested at the workflow level.
One evidence base, four frameworks.
NIS2 and its technical baselines expect risk management, access control, segmentation, and audit evidence at the OT layer, which is exactly where those obligations are hardest to satisfy. The study structured Access Gate's access logs, policy exports, and rollback records so the same evidence maps to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness.
That matters for industrial operators in scope of NIS2: a cyber lead, an OT engineer, and an auditor can each read the same records against the framework they answer to. See NIS2 compliance for industrial operators and the NIS2 compliance solution. For the underlying architecture, see what an industrial proxy is, PLC security, and IEC 62443 zones and conduits for OT.
“Working with Trout, we validated Access Gate as a reference implementation of overlay security for brownfield OT. It added identity-based access, segmentation, and audit evidence to a representative plant network without touching the underlay, and produced evidence strong enough for a cyber lead, an OT engineer, and an auditor to interpret.”
Dermot Murphy
IIoT Technologist, Irish Manufacturing Research (Principal Investigator)
Validated in a testbed. Ready for production.
The same overlay approach IMR validated brings identity-based access, segmentation, and NIS2-ready audit evidence to your OT network, without agents, re-IPing, or underlay changes.
The technology validated
Access Gate is Trout's agent-free zero-trust overlay for OT and IT. It adds identity-based access, segmentation, and audit evidence to existing plant networks without inline appliances, agents, or re-IPing.
Enterprise Ireland Innovation Partnership
Conducted by Irish Manufacturing Research (IMR) in its IMR Lab under Enterprise Ireland Innovation Partnership IP20252213Y. Access Gate was assessed as the reference implementation of a vendor-neutral network-overlay security model.
IMR Validation FAQ
OT protocols validated through the overlay
Irish Manufacturing Research (IMR), an independent research and technology organisation, ran the feasibility study in its IMR Lab under an Enterprise Ireland Innovation Partnership (Project IP20252213Y). Access Gate was assessed as the reference implementation of a vendor-neutral network-overlay security model.
A representative brownfield plant network in an industrial OT testbed. The team validated five protocols (Modbus TCP, OPC-UA, MQTT, web, RDP), six use-case families from remote access to containment, and mapped the resulting evidence to six CyFun functions from Govern through Recover. Tests were run at the workflow level rather than by port reachability alone.
NIS2 and its technical baselines expect risk management, access control, segmentation, and audit evidence at the OT layer, which is exactly where they are hardest to satisfy. The study structured Access Gate's logs, policy exports, and rollback records to map directly to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness, so the same evidence base supports an audit under multiple frameworks.
No. The core finding is that a network overlay can enforce stronger security while preserving the behaviour of industrial communications: without agents on legacy devices, without re-IPing production assets, and without redesigning the underlay network. Access Gate added identity-based access, segmentation, and audit evidence to the plant network without touching the underlay.
Five: Modbus TCP (port 502), OPC-UA, MQTT, browser-based HMI over the web, and scoped RDP remote-desktop access. Reads, sessions, subscriptions, and topic governance continued to function correctly through the overlay while unauthorised actions were denied.
It means the study did not only confirm that authorised traffic worked; it confirmed that unauthorised actions were actively denied and logged. In a protocol-aware overlay this works at the function-code level: a governed Modbus session can allow FC03 register reads while denying FC06 and FC16 writes to control registers. Denial, not just permitted reachability, is what demonstrates least privilege.
By default it runs as an adjacent overlay, next to the network rather than in the middle of it. Only the governed north-south sessions it brokers (remote access, engineering, vendor, and supervisory traffic) pass through enforcement. Cyclic controller-to-I/O traffic stays on the underlay and is never in the enforcement path. Inline placement is available per site where stronger, unbypassable enforcement is required.
New governed access sessions stop, while the running process keeps going: local controllers and HMIs are unaffected because the control loop never traversed enforcement. Fail-open versus fail-closed is a per-asset, logged decision, and the overlay runs as a high-availability pair so a single fault is not a single point of failure.
The study structured Access Gate's access logs, policy exports, and rollback records so one evidence base maps to CyFun, NIS2, IEC 62443, and ISO/IEC 27001 readiness. A cyber lead, an OT engineer, and an auditor can each read the same records against the framework they answer to.
A firewall trusts the port; Access Gate parses the protocol and can tell a read from a write at the function-code level. A VPN extends the whole network to a person; Access Gate extends one authorised action to one asset and nothing else. In Zero Trust terms it is the policy enforcement point for OT.