TroutTrout
Zero Trust for on-premise and industrial

Zscaler competitors and alternatives for OT networks

Trout Access Gate is an on-premise appliance to secure OT access without the cloud: it protects PLCs and HMIs that never run an agent, with enforcement staying in-path on your own network.

Last updated:

The real question

A question of category fit, not a scoreboard

Zscaler is genuinely good at what it was built for: connecting a distributed workforce to cloud applications. Its model assumes an agent on the endpoint and a network path out to a cloud point of presence. For a fleet of laptops reaching SaaS, that is the right design, and nothing here argues otherwise.

A water treatment plant or a machine shop breaks both assumptions. The endpoint is a PLC or an HMI that will never run an agent, and it often sits on a segment with no route to the internet. Cloud-delivered Zero Trust has nothing to install on the device and nowhere to send the traffic. That is a category mismatch, not a product flaw.

So the useful comparison is not who is better. It is which model fits a plant floor. The table below is built from each vendor's own public documentation, and where a capability is not documented it says so rather than guessing.

The shortlist

5 Zscaler competitors and alternatives, ranked for OT

Ranked for one job: securing on-premise IT and OT assets. A different ranking would be right for a laptop fleet reaching SaaS, and the first entry says so.

  1. 1. Trout Access Gate

    An on-premise appliance that enforces Zero Trust in-path, with no agent on the device and no cloud control plane to reach.

    Best for
    Plants with legacy PLCs, HMIs and SCADA, isolated or air-gapped segments, and data-sovereignty mandates that keep every packet on site.
    Where it stops
    It is not a SASE. If your problem is a distributed workforce reaching cloud applications, this is the wrong shape and a cloud ZTNA is the better call.
  2. 2. Palo Alto Prisma Access

    Cloud-delivered SASE with a documented OT and ICS remote-access story, and OT protocol parsing that lives in the next-generation firewall rather than in the access broker.

    Best for
    Organisations already standardised on Palo Alto that want one vendor across the IT edge and the OT remote-access path.
    Where it stops
    Cloud-delivered, so it does not function on a segment with no route out. Deployment timelines are not publicly documented.
  3. 3. Zscaler Privileged Remote Access

    The benchmark for cloud-first Zero Trust, with a privileged remote access product that brokers clientless sessions to OT systems.

    Best for
    Large distributed workforces reaching SaaS, plus supervised vendor access to OT systems that do have a path to the cloud.
    Where it stops
    Needs the cloud control plane, so it stops at the air gap. No OT protocol parsing is documented in the broker itself.
  4. 4. Netskope

    Cloud Zero Trust on the NewEdge network, marketed for access to SCADA, PLCs and HMIs, with OT capability weighted toward discovery rather than enforcement.

    Best for
    Teams that want visibility across cloud, web and private applications and treat OT access as one more private application.
    Where it stops
    Session recording and playback are not publicly documented, and enforcement depends on reaching NewEdge.
  5. 5. Cloudflare Zero Trust

    The fastest cloud Zero Trust to stand up, with a generous entry tier and no OT-specific positioning.

    Best for
    Lean teams securing web applications, SSH and RDP for people, where cost and time to first policy matter most.
    Where it stops
    No documented support for OT devices, command logging without replay, and it depends entirely on Cloudflare's network.
Side by side

How the Zero Trust options compare for industrial environments

Competitor cells are drawn from each vendor's public documentation, linked below. Where a capability is not publicly documented, the cell says so rather than assuming.

CapabilityZscalerPalo Alto Prisma AccessNetskopeCloudflare Zero TrustTrout Access Gate
Cloud dependencyCloud service; on-prem data-plane optionCloud-delivered SASECloud (NewEdge)Cloud only (global network)None; on-premise and in-path
Agent requiredClient Connector; clientless browser via PRAGlobalProtect; clientless browser via PRANetskope client; clientless browserWARP client; some clientless accessNone; agent-free
Works with legacy PLC / HMIBrokers clientless access to OT systemsBrokers OT and ICS remote accessMarkets access to SCADA, PLCs, HMIsNot documented for OT devicesYes; the device is never touched
Functions air-gappedNo; needs the cloud control planeNo; cloud-deliveredNo; needs the NewEdge cloudNo; needs Cloudflare's networkYes; no cloud dependency
Typical deployment timeNot documentedNot documentedNot documentedNot documentedHours; no rewiring, no downtime
Session recording and playbackYes; PRA session recordingYes; Browser PRA recordingNot documented; monitoring onlyCommand logging only; no replayYes; recorded and replayable
OT protocol awarenessRDP, SSH, VNC; no OT parsing documentedRDP, SSH, VNC; OT parsing lives in the NGFW, not the brokerRDP, SSH; OT discovery, not enforcementTCP, HTTP, SSH; no OT parsingProtocol-aware enforcement, including Modbus
Compliance mapping (CMMC L2 / NIS2 / NERC CIP)NIS2 published; CMMC and NERC not documentedNIS2 and NERC referenced; CMMC not documentedNIS2 published; CMMC and NERC not documentedNIS2 and FedRAMP; CMMC and NERC not documentedCMMC L2, NIS2, and NERC CIP

Sources: Zscaler · Palo Alto · Netskope · Cloudflare

What to look for

The questions that decide it on a plant floor

Does enforcement stay on site?

Cloud-delivered Zero Trust routes the access decision through a vendor point of presence. In-path, on-premise enforcement keeps every decision and every packet inside the fence, which is what an isolated OT segment and a data-sovereignty mandate require.

Can it protect a device that will never run an agent?

A modern proxy terminates the session, authenticates the person, applies policy, records what happened, and forwards a clean request. The PLC or HMI never knows anything changed, and it never needs software installed on it.

Is the audit trail ready for an assessor?

Tamper-evident logs of who connected, to which device, and what they did are what a CMMC, NIS2, or NERC CIP assessor asks for. Generated at the enforcement point, not reconstructed after the fact.

In production

This runs where agents cannot

Trout Access Gate secures defense manufacturers, research institutions, and critical-infrastructure operators: environments built on legacy PLCs, SCADA, and equipment that cannot take an agent. Among them are Thales, Millbrook Machine, Elna Magnetics, Irish Manufacturing Research, HUN-REN SZTAKI, and STBMA.

See customer stories

Questions about Zscaler competitors and alternatives

Access Gate is an agent-free, on-premise Zero Trust appliance for IT and OT, built for the assets a cloud ZTNA cannot reach.

Not for what Zscaler does best. If your job is connecting a remote workforce to SaaS, Zscaler is a strong fit and Access Gate is not trying to be. Access Gate is for the other half of the problem: securing on-premise IT and OT assets, including PLCs and HMIs that cannot run an agent and often have no path to the cloud. Many sites run both.

Yes. Enforcement happens in-path on the network, not on the endpoint. A modern proxy terminates the session, authenticates identity, applies enclave policy, and records the session, then forwards a clean request to the device. A twenty-year-old PLC gets the same Zero Trust treatment as a modern workstation, with nothing installed on it.

Yes. Access Gate runs fully on-premise as a virtual machine on a host that owns the network path. There is no cloud control plane and no cloud point of presence to reach, so it keeps working on an isolated or air-gapped segment. Cloud-delivered Zero Trust services depend on reaching their provider's network.

It maps to the access-control, system-and-communications-protection, and audit families those frameworks assess: identity-bound access, segmentation, network-layer MFA, and tamper-evident logs generated at the enforcement point. Treat it as one documented control in a broader program, not a compliance box on its own.

Access Gate enforces policy over the protocols on the wire, not just the ports. For a protocol like Modbus that has no native authentication, a protocol-aware proxy can bind access to identity, restrict which function codes and registers a source may use, and record every transaction, without touching the controller.

Start from your endpoints. If they are laptops reaching SaaS, a cloud ZTNA such as Zscaler, Prisma Access, Netskope, or Cloudflare fits. If they are PLCs, HMIs, RTU, or air-gapped servers, an in-path on-premise appliance such as Access Gate fits, because it needs no agent and no cloud. The table above shows where each one lands.

See whether Access Gate fits your plant

Thirty minutes with an engineer is usually enough to tell whether an in-path, agent-free approach fits your network, or whether a cloud ZTNA is the better call. We will tell you honestly either way.