Uptime Comes First. Your Security Should Too.
Production keeps running while your attack surface shrinks.
- One fabric across IT, OT, IoT, and embedded devices
- No maintenance window — deploy without downtime
- No agent on legacy controllers, no inbound ports
- On-premises or fully air-gapped, built for IEC 62443 and NIS2
OT, IoT, and Vendor Access All Depend on Uptime. Security Keeps Threatening It.
Plants, device fleets, and outside vendors all need more connectivity than ever — telemetry flowing out, updates and diagnostics coming back, partners reaching in to service equipment. But the assets are brittle and the networks are flat, and every conventional way to add that access widens the attack surface and risks uptime. Teams won’t deploy security that threatens production.
Unpatchable assets you can’t take offline
- Vulnerabilities stay open for years — patching means downtime or recertification
- Security can’t interfere with real-time control, and no agent belongs on a brittle controller
- The riskiest assets are the ones the team can’t touch
Constrained devices, multiplied across sites
- Devices ship with default credentials and open services — easy targets the moment they’re reachable
- Constrained endpoints can’t host a traditional agent or VPN client
- Cellular, edge, and roaming devices break IP-based access assumptions
Third-party access you can’t fully see
- Access grants far more reach than any single vendor task requires
- Every OEM brings a different access model — inconsistent governance and audit sprawl
- No per-identity record of which vendor touched which machine, and when
One Fabric. Every Asset. Invisible by Default.
NetFoundry is the connectivity and segmentation layer that enforces what your discovery and detection tools find. Outbound-only and identity-first, it puts no agent on legacy assets and opens no inbound ports — one fabric spanning IT, OT, IoT, and embedded devices, deployable on-premises or fully air-gapped, without interfering with operations.
Segment IT from OT — and contain what moves inside
A lightweight tunneler fronts legacy SCADA, PLC, and HMI assets.
- Stop an IT-borne compromise before it reaches the plant floor
- Machine-to-machine conduits enforce least privilege and shrink the blast radius
- Wrap unpatchable legacy assets in a Zero Trust bubble — no agent, no downtime
Reach every device — down to the constrained edge
Front a group of devices with a lightweight tunneler, or embed the NetFoundry SDK to give one constrained device its own cryptographic identity.
- No traditional agent required, even on the most constrained endpoints
- Remote lifecycle management for edge ML — machine vision, predictive maintenance, digital twins
- Works across cellular, edge, air-gapped, and roaming links where IP allowlists break down
Just-in-time access to one machine — not the plant
Each OEM or integrator identity reaches only the equipment it is authorized to service.
- Just-in-time, least-privilege access to a single machine — granted, then revoked
- Full per-identity audit trail of every vendor connection and maintenance session
- Remote diagnostics and maintenance without a truck roll
“VPN and the other security technologies we relied on in the past can no longer cut it in today’s hyperconnected world. NetFoundry’s technology enables us to apply the strictest deny-by-default security principles to every user, device and application in our customers’ networks.”
Steve Wulchin, CEO — Freewave
Secure an OT Asset in Five Steps
Identity-first connectivity deploys on your existing network, with no redesign, no agent on a controller, and no production interruption. Start with a single line or cell.
Every connection starts from zero. NetFoundry establishes an encrypted conduit only after mutual X.509 authentication verifies both identity and policy, and because no access exists by default, Zero Trust holds from the connection layer up.
Want the architecture in depth — tunnelers, SDKs, the control plane, and enforcement? Explore the platform →
Enforces What Your Security Tools Only See
NetFoundry is not another discovery or detection tool — it is the connectivity and segmentation layer beneath them. It takes the assets those tools find and enforces least-privilege, identity-based access to them, while feeding session and policy data back into the tools your SOC already uses.
- Enforces the segmentation that discovery and detection platforms recommend
- Streams visibility and session data to your SIEM or Elastic stack, or via API
- Partners with OEMs and integrators across the industrial ecosystem
Aligned to the Frameworks Your Auditors Require
NetFoundry maps to the frameworks that govern industrial operations, enforcing identity-based, zone-and-conduit segmentation with least-privilege access and immutable audit logs. For the assets you cannot patch or take offline, removing the attacker’s path serves as a recognized IEC 62443 compensating control. The same model produces the evidence auditors expect for NIS2, NERC CIP, and the EU Cyber Resilience Act.
“Our customers don’t even need to open a single inbound firewall port for TZ to remotely manage our software deployed on their networks. This greatly strengthens security for our customers and streamlines their operations. InfoSec reviews which historically can take weeks became single-meeting events.”
John Wilson, CEO — TZ Limited
Open-Source Roots, Enterprise-Grade Delivery
NetFoundry created OpenZiti, the open-source Zero Trust networking project, and builds on it with the managed control plane, FIPS-validated cryptography, and global scale that regulated industrial deployments require. The same fabric that protects a single plant protects thousands.
Shipping inside Siemens SINEC Secure Connect
NetFoundry’s identity-first connectivity is embedded directly in Siemens network devices as Siemens SINEC Secure Connect — bringing outbound-only, Zero Trust connectivity to industrial infrastructure through one of the world’s largest automation OEMs. It is proof that the fabric is built to be embedded and white-labeled by the vendors your plant already trusts.
- Zero Trust connectivity native to Siemens network hardware
- Outbound-only, no inbound ports, no separate agent
- Embeddable and white-labeled through the NetFoundry SDKs
“Traditional network security approaches struggle with the convergence of IT and OT systems. With the SINEC Secure Connect platform, Siemens offers a cybersecurity solution that protects increasingly digitalized production networks while also helping to simplify network management.”Michael Metzler, Vice President, Horizontal Management Cybersecurity, Siemens Digital Industries
OT & IoT Connectivity FAQ
What is NetFoundry OT & IoT connectivity?
NetFoundry is an identity-first connectivity and segmentation platform for operational technology (OT) and IoT environments. It connects plants, devices, and vendors through an outbound-only overlay that opens no inbound ports and puts no agent on legacy controllers. Authorized identities can still reach OT and IoT assets, while those assets stay invisible to the internet. The same fabric spans IT, OT, IoT, and embedded devices and deploys on-premises or fully air-gapped.
Will deploying NetFoundry cause downtime or affect production?
NetFoundry deploys without downtime or a maintenance window. A lightweight tunneler drops in front of an asset, or an SDK embeds in a device, with nothing installed on the controller and no change to VLANs, firewall rules, or the existing network. Because each asset dials out and local enforcement runs on-site, you add connectivity without interrupting real-time control, and plant-to-plant and on-site traffic keeps running even if the WAN or cloud link drops.
How does NetFoundry protect legacy OT assets that can’t be patched?
NetFoundry protects unpatchable OT assets by removing the path an attacker would use to reach them rather than requiring a patch. A lightweight tunneler sits in front of a legacy controller or an HMI running an unsupported operating system. The asset then connects outbound-only, with no inbound ports and no software installed on the device itself. The vulnerability remains present but becomes unreachable to unauthorized identities, which serves as a recognized IEC 62443 compensating control for assets that cannot be patched or taken offline.
Does NetFoundry require opening inbound firewall ports or a VPN into the plant?
NetFoundry requires no inbound firewall ports and no VPN into the plant. Every connection is outbound-only: each asset dials out to the overlay, which leaves no listening port to scan and no VPN endpoint to attack. This eliminates the standing entry points that VPNs and jump servers create, and it lets your team add new connectivity without firewall rule changes, VLAN redesigns, or maintenance windows.
How does NetFoundry help meet IEC 62443 and NIS2 requirements?
NetFoundry maps directly to IEC 62443 and NIS2 by enforcing identity-based, zone-and-conduit segmentation with least-privilege access and immutable audit logs. It supports IEC 62443 requirements for identification and authentication, authorization, boundary protection, and audit, and provides a recognized compensating control for unpatchable assets. Centralized policy and logging produce the evidence auditors expect, and the same model also aligns to NERC CIP and the EU Cyber Resilience Act.
Which security and compliance frameworks does NetFoundry support for OT and IoT environments?
NetFoundry supports the frameworks that govern industrial and critical-infrastructure operations, including IEC 62443, NIS2, NIST 800-171, NERC CIP, the Security of Critical Infrastructure (SOCI) Act, the EU Cyber Resilience Act, DORA, SOC 2 Type II, and FIPS. It maps to them through identity-based, zone-and-conduit segmentation, least-privilege access, and immutable session and policy logs. For assets that cannot be patched or taken offline, removing the network path to the asset serves as a recognized IEC 62443 compensating control.
Can NetFoundry be deployed on-premises or in an air-gapped environment?
NetFoundry runs fully on-premises or in a completely air-gapped environment on commodity hardware you already own. It needs no proprietary appliance and no vendor-hosted cloud, which lets it satisfy OT security reviews that prohibit outside connectivity. Local enforcement continues even if the WAN or cloud link drops, keeping plant-to-plant and on-site connectivity running and protecting production during an outage.
How does NetFoundry stop lateral movement between IT and OT?
NetFoundry stops lateral movement by enforcing default-deny, identity-based segmentation between IT and OT and between individual machines. It grants access by verified identity to a specific service rather than by IP address or network location. A compromise in IT or a single infected device therefore has no authorized path to spread onto the plant floor. Even when an attacker exploits one asset, the blast radius stays contained to that asset, because no lateral path exists to anything else.
Does NetFoundry replace my existing OT security and detection tools?
NetFoundry does not replace your discovery and detection tools; it enforces what they find. Those tools identify the assets and threats on your network, and NetFoundry provides the connectivity and segmentation layer beneath them, granting least-privilege, identity-based access to each asset and streaming session and policy data back to the SIEM or SOC tooling your team already uses. A single enforcement layer then acts on the visibility your existing stack produces.
How does NetFoundry secure remote vendor and OEM access to equipment?
NetFoundry gives each vendor or OEM identity just-in-time, least-privilege access to only the specific equipment it is authorized to service, with no VPN and no open inbound ports. NetFoundry authenticates every session by identity and records it in full for audit, and your team grants or revokes access without firewall or infrastructure changes. This replaces broad VPN tunnels and jump servers with a door to one machine rather than the whole plant, and it enables remote diagnostics without a truck roll.
How does NetFoundry connect constrained IoT devices at fleet scale?
NetFoundry connects IoT fleets by giving each device its own cryptographic identity through an embeddable SDK or a lightweight tunneler, with no traditional agent, no public IP, and no per-device firewall rules. Devices communicate outbound-only, which keeps them invisible to inbound scans, and default isolation prevents any one compromised device from reaching the others. The same identity model works across cellular, edge, air-gapped, and roaming deployments, and NetFoundry’s connectivity ships embedded in Siemens SINEC Secure Connect, proof that it scales inside industrial products.
Still have a question we didn’t cover? Talk to Us
Raise Your Security Without Risking Uptime
See how NetFoundry keeps production running while it contains lateral movement and protects the assets you can’t patch.