TroutTrout
Solutions / OT Network Security

OT Network Security Zero-Trust via Proxies. No agents, no VLAN redesign.

As IT ties into OT, network segmentation and Purdue Zones (the standard way OT networks are layered) are proven best practices, and most environments already use them to some extent. Access Gate builds on these by locking down access, enforcing identity, and logging activity.

OT NETWORK — ZERO-TRUST WITH ACCESS GATELIVEMPLS, APN, TUNNELSINTERNET / WANSITE BFIREWALL / ROUTERphysical wireLANZERO-TRUST OVERLAYVLANTagged & TrunkSECURITYAuth, Encryption, ACLOT SERVICESDNS, NTP, Protocol Gateway,Remote AccessACCESS GATEIT CLIENTIT SERVERZONE A OTZONE B OTDesktopDesktopDesktopDesktopIT SERVICESApps, SIEM, etcHMISensorDesktopPLCHMISensorPLCDesktop
Defense in Depth Limits

The Purdue Reference Model and the OT security problem.

The Purdue Reference Model organises an industrial network into levels. Level 0 is the physical process: the sensors and actuators on the line. Level 1 is basic control, the PLCs and RTUs that drive that process. Level 2 is supervisory control, the SCADA servers and HMIs. Level 3 is site operations, where the historian and MES live. Levels 4 and 5 are the enterprise: ERP, email, and the rest of corporate IT.

The IT/OT boundary is the junction attackers aim for. It is also becoming more brittle with increased digitalization. Remote maintenance and cloud-bound data flows are prime examples of challenges to Purdue and segmentation efforts.

The result is that most sites stay flat or only partly segmented, not because operators do not know the model, but because retrofitting it onto a live network is too disruptive.

IEC alignment

IEC 62443 Zones and Conduits.

In IEC 62443: a zone is a grouping of assets that share the same security requirements and a common Security Level. The standard defines four, from SL1 (protection against casual or coincidental violation) to SL4 (protection against a state-level actor with extended resources). A conduit is the controlled communication path between two zones.

The hard part is implementing conduits on a network that is already running, which traditionally means a VLAN redesign: re-addressing equipment, reconfiguring switches, and taking production down for the cutover. For most operators, that downtime is the blocker that keeps a flat network flat for another year.

How Access Gate deploys

OT Cybersecurity without a network redesign.

PHASE 1

Connect Access Gate to the Network

Access Gate deploys alongside the existing network in an aggregation or lollipop architecture. No VLAN changes. No agents on PLCs or OT endpoints.

PHASE 2

Zero Trust consolidation.

The overlay becomes the new Zero Trust fabric. Migration runs at about 10 systems per hour through the Access Gate proxy, so a 100-system site is done in a single day. IT admins and OT operators manage policy through role-based access in a shared UI.

Deployment

Access Gate adapts to your network

Pick your environment to see where the Access Gate sits, how much Zero-Trust coverage you get, and the migration path, from full coverage to partial coverage.

Access Gate: deploy Zero-TrustSelect an option to highlight its path
See the full deployment guide
The second layer of value

Access Gate secures your assets first, then exposes the simple services your teams and vendors actually want, so they run through the sanctioned path, not around it.

OT runs through you, not around you.

Trusted by industrial and critical infrastructure operators.

Saint-Gervais Domaine Skiable
55

distributed sites protected across harsh operational environments, securing critical infrastructure without agents or downtime.

Read the case study

Trusted by leading companies

Thales
Orange Cyberdefense
Carahsoft
John Cockerill
NeverHack
Kyron
Eden Cluster
Airicom
Skynopy
Frequently asked questions

OT network security, answered.

6

Purdue, IEC 62443 zones, multi-site policy, and the two-phase Access Gate deployment

The Purdue Reference Model (part of ISA-95) is the standard architecture for industrial control systems. It defines six logical levels, from Level 0 (the physical process: sensors and actuators) up through Level 1 (basic control: PLCs and RTUs), Level 2 (supervisory control: SCADA and HMIs), Level 3 (site operations and MES), to Levels 4 and 5 (enterprise IT). In OT security the model matters because it locates the IT/OT boundary at Level 3 and defines which systems should never talk directly to which. That is the basis for segmentation.

IEC 62443 formalises Purdue-style segmentation into two constructs. A zone is a grouping of assets that share the same security requirements and a common Security Level (SL1 to SL4). A conduit is the controlled communication path between zones. It sets and enforces exactly which traffic may cross a zone boundary, and under what conditions. Without conduits, a zone diagram is theoretical: any device can still reach any other.

Access Gate deploys in two phases. In Phase 1 it sits adjacent to the existing network at the Level 3 / DMZ boundary and creates a Zero Trust overlay across the Purdue zones. No VLAN reconfiguration, no agents on PLCs or OT endpoints, no production downtime. Visibility and identity-based access control are immediate. In Phase 2 that overlay becomes the new Zero Trust fabric as systems migrate behind the gate, with no forklift replacement of switches.

Phase 1, the adjacent overlay, is live in hours, not months. Phase 2 migration runs at about 10 systems per hour through the Access Gate proxy, so a 100-system OT environment is done in roughly a single working day. Compare that with the months a traditional VLAN redesign and consolidation project takes, most of which is change-control and validation, not the cutover itself.

NIS2 Article 21 does not name IEC 62443 explicitly, but its technical measures (network segmentation, access control, logging) map directly onto the zone-and-conduit model. National guidance for OT operators, including ANSSI guidance in France, treats IEC 62443 as the recognised technical implementation standard for those obligations, so building to IEC 62443 zones is the practical route to demonstrating Article 21 segmentation.

Access Gate provides central policy management across every site from a single role-based UI. Each site deploys independently in Phase 1, with no cross-site interdependency and no big-bang cutover. From day one of Phase 2, the sites roll up into one unified Zero Trust fabric. IT admins set enterprise-wide policy while OT operators keep site-level control, so a 50-site group runs a consistent IEC 62443 zone posture without sending a network team to every plant.

OT (operational technology) security protects the industrial systems that run physical processes: PLCs, HMIs, SCADA, and the legacy servers behind them. Unlike IT security it cannot rely on endpoint agents or frequent patching, so Access Gate enforces identity, segmentation, and monitoring at the network layer with a Zero-Trust proxy in front of each asset, no agents and no downtime.

IT security defends data and user devices, where agents, patches, and reboots are routine. OT security defends availability and safety on equipment that often cannot be patched, agented, or taken offline. Access Gate adds Zero-Trust access, microsegmentation, and audit at the network layer instead of on the device, so protection does not disrupt production.