Secure utility OT without downtime or rewiring.
A Zero Trust reference architecture for utilities that build new plants and harden running ones. It adds authentication, access control, proxying and audit to SCADA, RTUs and PLCs. There is no IP renumbering and no firewall rewrite, and the plant stays online.
Last updated:
Every utility plant has two security-critical moments: greenfield commissioning (a new plant being built) and brownfield operations (a plant already running, often for decades). The same Zero Trust architecture applies to both. Access Gate is an on-premise security broker. It connects beside the site core, brokers identity-bound sessions across IT, OT and IoT machines, and keeps a tamper-evident audit trail. The architecture diagram is below.
New and running plants use the same architecture.
Every utility plant goes through two security-critical moments. The same Zero Trust architecture closes both.
Commissioning a new plant.
Access Gate is installed during the integration window. Asset discovery, IdP integration, enclave policy, and audit are configured before handover. The plant goes live with identity-bound access and audit on day one.
Hardening a running plant.
Access Gate sits adjacent to the site core, observes traffic, and overlays identity-bound policy on top of the existing topology. No firewall ruleset change, no IP renumbering, no SCADA restart.
Access Gate connects beside the site core.
The architecture is the same whether the plant is being commissioned or already running. Access Gate connects beside the site core switch. It observes traffic, brokers identity-bound sessions and keeps a tamper-evident audit trail. It needs no change to the MPLS or VLAN topology and no IP renumbering. Nothing is installed on field machines.
Water, electric and gas utilities share one pattern.
Water and electric utilities run the same underlying pattern: SCADA, RTU, PLCs, geographically dispersed sites, vendor remote access, audit pressure. The reference architecture applies identically. The regulatory hook and the assessment workflow differ by vertical.
Water and wastewater utilities
Context. Treatment plants, pump stations, distribution networks. SCADA systems, RTU, legacy serial-to-IP converters across geographically dispersed sites.
Regulatory. EPA America's Water Infrastructure Act, NY EFC SECURE 12-step checklist, post-Volt Typhoon CISA guidance.
Outcome. Pass the cybersecurity assessment your funder requires. Demonstrate identity-bound access to treatment SCADA without taking the plant offline.
Explore verticalElectric utilities and power generation
Context. Substations, generation assets, transmission and distribution control rooms. SCADA, RTU, IEDs, protective relays connected by MPLS.
Regulatory. NERC CIP-005, CIP-007, CIP-010, CIP-015 INSM (US). CCCS baseline (Canada).
Outcome. Cover the East-West traffic that CIP-015 made mandatory. Avoid the $1M/day per-violation NERC fine exposure. Evidence pack ready for the next assessment.
Explore verticalFor US electric utilities specifically, the NERC CIP compliance landing covers CIP-003-9 vendor remote access and CIP-015 INSM in depth. For New York water utilities, the NY EFC SECURE grant page maps Access Gate to the 12-step DEC/DOH compliance checklist. For the wider picture, see the Zero Trust for OT hub.
Download the architecture for new and running plants.
The PDF includes the full architecture diagram, the four-pillar coverage map, three operational scenarios, and the NERC CIP + CCCS matrix.
No maintenance window needed.
Access Gate connects beside the site core. No firewall ruleset change, no IP renumbering, no SCADA restart. This holds for a new plant and for a running one.
Evidence stays audit-ready.
Tamper-evident, identity-bound session logs forwarded to your SIEM. Evidence packs map directly to NERC CIP-005/010 and the CCCS baseline.
Questions utility security teams ask.
The architecture is the same; the operational context differs. Greenfield commissioning means the plant is being built, so the security work fits inside the project calendar before handover. Brownfield means the plant is already running. The appliance connects beside the live network and adds identity-bound policy on top. There is no IP renumbering, no firewall change and no maintenance window.
No. The firewall and MPLS keep doing what they do: north-south policy at the site edge, VLAN segmentation and encrypted transport between sites. Access Gate fills the gap they were never designed to cover. It adds identity per session, an audit trail of who touched which PLC or RTU, and visibility into vendor remote support sessions.
Access Gate operates as the Intermediate System required by NERC CIP-005-7 for Interactive Remote Access. It brokers identity-bound sessions, can disable an active vendor session (R2.4/R2.5) and keeps tamper-evident audit logs. Everything runs on premise, with no cloud dependency. CIP-010 change-window grants produce evidence packs ready for assessment. The same four pillars cover access control, vendor access, and incident handling. The compliance matrix on this page shows the row-by-row mapping.