TroutTrout

Secure utility OT without downtime or rewiring.

A Zero Trust reference architecture for utilities that build new plants and harden running ones. It adds authentication, access control, proxying and audit to SCADA, RTUs and PLCs. There is no IP renumbering and no firewall rewrite, and the plant stays online.

Last updated:

Direct answer

Every utility plant has two security-critical moments: greenfield commissioning (a new plant being built) and brownfield operations (a plant already running, often for decades). The same Zero Trust architecture applies to both. Access Gate is an on-premise security broker. It connects beside the site core, brokers identity-bound sessions across IT, OT and IoT machines, and keeps a tamper-evident audit trail. The architecture diagram is below.

Commissioning and operations

New and running plants use the same architecture.

Every utility plant goes through two security-critical moments. The same Zero Trust architecture closes both.

Greenfield

Commissioning a new plant.

Access Gate is installed during the integration window. Asset discovery, IdP integration, enclave policy, and audit are configured before handover. The plant goes live with identity-bound access and audit on day one.

Brownfield

Hardening a running plant.

Access Gate sits adjacent to the site core, observes traffic, and overlays identity-bound policy on top of the existing topology. No firewall ruleset change, no IP renumbering, no SCADA restart.

Reference architecture

Access Gate connects beside the site core.

The architecture is the same whether the plant is being commissioned or already running. Access Gate connects beside the site core switch. It observes traffic, brokers identity-bound sessions and keeps a tamper-evident audit trail. It needs no change to the MPLS or VLAN topology and no IP renumbering. Nothing is installed on field machines.

OT NETWORK · ZERO-TRUST WITH ACCESS GATELIVEMPLS, APN, TUNNELSINTERNET / WANSITE BFIREWALL / ROUTERphysical wireLANZERO-TRUST OVERLAYVLANTagged & TrunkSECURITYAuth, Encryption, ACLOT SERVICESDNS, NTP, Protocol Gateway,Remote AccessACCESS GATEIT CLIENTIT SERVERZONE A OTZONE B OTDesktopDesktopDesktopDesktopIT SERVICESApps, SIEM, etcHMISensorDesktopPLCHMISensorPLCDesktop
Access Gate sits adjacent. The firewall, MPLS, and VLAN topology stay as they are. The orange overlay is the identity-bound policy and audit plane added by Access Gate.
Where it fits

Water, electric and gas utilities share one pattern.

Water and electric utilities run the same underlying pattern: SCADA, RTU, PLCs, geographically dispersed sites, vendor remote access, audit pressure. The reference architecture applies identically. The regulatory hook and the assessment workflow differ by vertical.

For US electric utilities specifically, the NERC CIP compliance landing covers CIP-003-9 vendor remote access and CIP-015 INSM in depth. For New York water utilities, the NY EFC SECURE grant page maps Access Gate to the 12-step DEC/DOH compliance checklist. For the wider picture, see the Zero Trust for OT hub.

Get the whitepaper

Download the architecture for new and running plants.

The PDF includes the full architecture diagram, the four-pillar coverage map, three operational scenarios, and the NERC CIP + CCCS matrix.

Done

No maintenance window needed.

Access Gate connects beside the site core. No firewall ruleset change, no IP renumbering, no SCADA restart. This holds for a new plant and for a running one.

Evidence stays audit-ready.

Tamper-evident, identity-bound session logs forwarded to your SIEM. Evidence packs map directly to NERC CIP-005/010 and the CCCS baseline.

Questions

Questions utility security teams ask.

The architecture is the same; the operational context differs. Greenfield commissioning means the plant is being built, so the security work fits inside the project calendar before handover. Brownfield means the plant is already running. The appliance connects beside the live network and adds identity-bound policy on top. There is no IP renumbering, no firewall change and no maintenance window.

No. The firewall and MPLS keep doing what they do: north-south policy at the site edge, VLAN segmentation and encrypted transport between sites. Access Gate fills the gap they were never designed to cover. It adds identity per session, an audit trail of who touched which PLC or RTU, and visibility into vendor remote support sessions.

Access Gate operates as the Intermediate System required by NERC CIP-005-7 for Interactive Remote Access. It brokers identity-bound sessions, can disable an active vendor session (R2.4/R2.5) and keeps tamper-evident audit logs. Everything runs on premise, with no cloud dependency. CIP-010 change-window grants produce evidence packs ready for assessment. The same four pillars cover access control, vendor access, and incident handling. The compliance matrix on this page shows the row-by-row mapping.