Zero Trust OT & IoT Connectivity

Uptime Comes First. Your Security Should Too.

Production keeps running while your attack surface shrinks.

  • One fabric across IT, OT, IoT, and embedded devices
  • No maintenance window — deploy without downtime
  • No agent on legacy controllers, no inbound ports
  • On-premises or fully air-gapped, built for IEC 62443 and NIS2
NetFoundry OT IoT Zero Trust security diagram
0 inbound ports opened on OT or plant networks
0 agents required on legacy SCADA, PLC, or HMI assets
0 maintenance windows or production downtime to deploy
The challenge

OT, IoT, and Vendor Access All Depend on Uptime. Security Keeps Threatening It.

Plants, device fleets, and outside vendors all need more connectivity than ever — telemetry flowing out, updates and diagnostics coming back, partners reaching in to service equipment. But the assets are brittle and the networks are flat, and every conventional way to add that access widens the attack surface and risks uptime. Teams won’t deploy security that threatens production.

OT

Unpatchable assets you can’t take offline

  • Vulnerabilities stay open for years — patching means downtime or recertification
  • Security can’t interfere with real-time control, and no agent belongs on a brittle controller
  • The riskiest assets are the ones the team can’t touch
IoT

Constrained devices, multiplied across sites

  • Devices ship with default credentials and open services — easy targets the moment they’re reachable
  • Constrained endpoints can’t host a traditional agent or VPN client
  • Cellular, edge, and roaming devices break IP-based access assumptions
Vendor & OEM Access

Third-party access you can’t fully see

  • Access grants far more reach than any single vendor task requires
  • Every OEM brings a different access model — inconsistent governance and audit sprawl
  • No per-identity record of which vendor touched which machine, and when
Flat network lateral movementAn attacker compromises the IT network, and a flat, unsegmented network lets that foothold reach OT plant assets, the IoT device fleet, and vendor access sessions.The shared problem: one foothold, a flat network, three ways in!AttackerIT networkcompromisedFlat, converging network — no segmentationPlant floorOT controllers, PLCs, HMIsDevice fleetIoT sensors & gatewaysVendor accessOEM & integrator sessionsThe same flat network that carries production traffic carries the attack.
The NetFoundry solution

One Fabric. Every Asset. Invisible by Default.

NetFoundry is the connectivity and segmentation layer that enforces what your discovery and detection tools find. Outbound-only and identity-first, it puts no agent on legacy assets and opens no inbound ports — one fabric spanning IT, OT, IoT, and embedded devices, deployable on-premises or fully air-gapped, without interfering with operations.

OT

Segment IT from OT — and contain what moves inside

A lightweight tunneler fronts legacy SCADA, PLC, and HMI assets.

  • Stop an IT-borne compromise before it reaches the plant floor
  • Machine-to-machine conduits enforce least privilege and shrink the blast radius
  • Wrap unpatchable legacy assets in a Zero Trust bubble — no agent, no downtime
IoT

Reach every device — down to the constrained edge

Front a group of devices with a lightweight tunneler, or embed the NetFoundry SDK to give one constrained device its own cryptographic identity.

  • No traditional agent required, even on the most constrained endpoints
  • Remote lifecycle management for edge ML — machine vision, predictive maintenance, digital twins
  • Works across cellular, edge, air-gapped, and roaming links where IP allowlists break down
Vendor & OEM Access

Just-in-time access to one machine — not the plant

Each OEM or integrator identity reaches only the equipment it is authorized to service.

  • Just-in-time, least-privilege access to a single machine — granted, then revoked
  • Full per-identity audit trail of every vendor connection and maintenance session
  • Remote diagnostics and maintenance without a truck roll
Common to all three
  • Outbound-only with no inbound ports — nothing to scan, nothing to attack
  • Access by verified identity, not IP address or network location
  • Default-deny isolation gives one compromise nowhere to spread
  • Deploys on-premises or fully air-gapped on commodity hardware you already own
  • One policy model governs every asset, site, and vendor from a single control plane
“VPN and the other security technologies we relied on in the past can no longer cut it in today’s hyperconnected world. NetFoundry’s technology enables us to apply the strictest deny-by-default security principles to every user, device and application in our customers’ networks.”

Steve Wulchin, CEO — Freewave

How it works

Secure an OT Asset in Five Steps

Identity-first connectivity deploys on your existing network, with no redesign, no agent on a controller, and no production interruption. Start with a single line or cell.

Five-step deployment flowA five-step process: deploy a tunneler or SDK, the asset dials out, authenticate by identity, enforce least-privilege conduits, then govern centrally with continued operation if the cloud link drops.Secure an asset in five steps1Deploytunneler or SDK,no network change2Dial outasset connects out,nothing listens3Authenticateverify identitybefore any link4Least privilegeidentity-basedconduits only5Governcentral policy,survives cloud dropNo agent on the controller • no inbound ports • no maintenance window

Every connection starts from zero. NetFoundry establishes an encrypted conduit only after mutual X.509 authentication verifies both identity and policy, and because no access exists by default, Zero Trust holds from the connection layer up.

Want the architecture in depth — tunnelers, SDKs, the control plane, and enforcement? Explore the platform →

Beyond discovery

Enforces What Your Security Tools Only See

NetFoundry is not another discovery or detection tool — it is the connectivity and segmentation layer beneath them. It takes the assets those tools find and enforces least-privilege, identity-based access to them, while feeding session and policy data back into the tools your SOC already uses.

  • Enforces the segmentation that discovery and detection platforms recommend
  • Streams visibility and session data to your SIEM or Elastic stack, or via API
  • Partners with OEMs and integrators across the industrial ecosystem
Enforcement layer stack diagramA layered diagram: discovery and detection tools sit on top, NetFoundry is the connectivity and enforcement layer in the middle, and OT, IoT, and IT assets sit at the bottom. Session and policy data streams from the NetFoundry layer to a SIEM.The enforcement layer beneath your detection stackDiscovery & detectionAsset visibility • SOC toolingNetFoundryconnectivity & least-privilege enforcementidentity-based conduits • outbound-onlyOT • IoT • IT assetsplants, devices, workloads, embeddedSIEM /Elastic / APIEnforces what your tools find; streams session & policy evidence back to the SOC.
Standards and compliance

Aligned to the Frameworks Your Auditors Require

NetFoundry maps to the frameworks that govern industrial operations, enforcing identity-based, zone-and-conduit segmentation with least-privilege access and immutable audit logs. For the assets you cannot patch or take offline, removing the attacker’s path serves as a recognized IEC 62443 compensating control. The same model produces the evidence auditors expect for NIS2, NERC CIP, and the EU Cyber Resilience Act.

NetFoundry controls mapped to compliance frameworksFive NetFoundry controls on the left — zone and conduit segmentation, least-privilege access, outbound-only connectivity, immutable logs, and end-to-end encryption with customer-held keys — each map by a connecting line to the frameworks they satisfy on the right: IEC 62443; NIS2 and NIST 800-171; SOCI and NERC CIP; the EU Cyber Resilience Act with DORA and SOC 2; and FIPS with data privacy.One control model, mapped to the standards you report againstWHAT NETFOUNDRY ENFORCESWHAT THE FRAMEWORKS REQUIREIdentity-based zone & conduit segmentationzones and conduitsIEC 62443zone/conduit model & compensating controlLeast-privilege, default-deny accessidentity, not IPNIS2 · NIST 800-171access control & risk managementOutbound-only, nothing left listeningno reachable attack surfaceSOCI · NERC CIPcritical-infrastructure protectionImmutable session & policy logsrecorded by identityEU CRA · DORA · SOC 2audit evidence & reportingEnd-to-end encryption, data securityYou hold your encryption keysFIPS · data privacyvalidated cryptography & data sovereigntyNetFoundry produces the segmentation, least-privilege access, encryption, and immutable evidence these frameworks require.
“Our customers don’t even need to open a single inbound firewall port for TZ to remotely manage our software deployed on their networks. This greatly strengthens security for our customers and streamlines their operations. InfoSec reviews which historically can take weeks became single-meeting events.”

John Wilson, CEO — TZ Limited

From the creators of OpenZiti

Open-Source Roots, Enterprise-Grade Delivery

NetFoundry created OpenZiti, the open-source Zero Trust networking project, and builds on it with the managed control plane, FIPS-validated cryptography, and global scale that regulated industrial deployments require. The same fabric that protects a single plant protects thousands.

3,000companies use NetFoundry
2 of 5largest US companies connect with NetFoundry
8 of 10largest US banks connect with NetFoundry
1B+sessions per month across global infrastructure
Embedded with Siemens

Shipping inside Siemens SINEC Secure Connect

NetFoundry’s identity-first connectivity is embedded directly in Siemens network devices as Siemens SINEC Secure Connect — bringing outbound-only, Zero Trust connectivity to industrial infrastructure through one of the world’s largest automation OEMs. It is proof that the fabric is built to be embedded and white-labeled by the vendors your plant already trusts.

  • Zero Trust connectivity native to Siemens network hardware
  • Outbound-only, no inbound ports, no separate agent
  • Embeddable and white-labeled through the NetFoundry SDKs
“Traditional network security approaches struggle with the convergence of IT and OT systems. With the SINEC Secure Connect platform, Siemens offers a cybersecurity solution that protects increasingly digitalized production networks while also helping to simplify network management.”Michael Metzler, Vice President, Horizontal Management Cybersecurity, Siemens Digital Industries
Questions & answers

OT & IoT Connectivity FAQ

What is NetFoundry OT & IoT connectivity?

NetFoundry is an identity-first connectivity and segmentation platform for operational technology (OT) and IoT environments. It connects plants, devices, and vendors through an outbound-only overlay that opens no inbound ports and puts no agent on legacy controllers. Authorized identities can still reach OT and IoT assets, while those assets stay invisible to the internet. The same fabric spans IT, OT, IoT, and embedded devices and deploys on-premises or fully air-gapped.

Will deploying NetFoundry cause downtime or affect production?

NetFoundry deploys without downtime or a maintenance window. A lightweight tunneler drops in front of an asset, or an SDK embeds in a device, with nothing installed on the controller and no change to VLANs, firewall rules, or the existing network. Because each asset dials out and local enforcement runs on-site, you add connectivity without interrupting real-time control, and plant-to-plant and on-site traffic keeps running even if the WAN or cloud link drops.

How does NetFoundry protect legacy OT assets that can’t be patched?

NetFoundry protects unpatchable OT assets by removing the path an attacker would use to reach them rather than requiring a patch. A lightweight tunneler sits in front of a legacy controller or an HMI running an unsupported operating system. The asset then connects outbound-only, with no inbound ports and no software installed on the device itself. The vulnerability remains present but becomes unreachable to unauthorized identities, which serves as a recognized IEC 62443 compensating control for assets that cannot be patched or taken offline.

Does NetFoundry require opening inbound firewall ports or a VPN into the plant?

NetFoundry requires no inbound firewall ports and no VPN into the plant. Every connection is outbound-only: each asset dials out to the overlay, which leaves no listening port to scan and no VPN endpoint to attack. This eliminates the standing entry points that VPNs and jump servers create, and it lets your team add new connectivity without firewall rule changes, VLAN redesigns, or maintenance windows.

How does NetFoundry help meet IEC 62443 and NIS2 requirements?

NetFoundry maps directly to IEC 62443 and NIS2 by enforcing identity-based, zone-and-conduit segmentation with least-privilege access and immutable audit logs. It supports IEC 62443 requirements for identification and authentication, authorization, boundary protection, and audit, and provides a recognized compensating control for unpatchable assets. Centralized policy and logging produce the evidence auditors expect, and the same model also aligns to NERC CIP and the EU Cyber Resilience Act.

Which security and compliance frameworks does NetFoundry support for OT and IoT environments?

NetFoundry supports the frameworks that govern industrial and critical-infrastructure operations, including IEC 62443, NIS2, NIST 800-171, NERC CIP, the Security of Critical Infrastructure (SOCI) Act, the EU Cyber Resilience Act, DORA, SOC 2 Type II, and FIPS. It maps to them through identity-based, zone-and-conduit segmentation, least-privilege access, and immutable session and policy logs. For assets that cannot be patched or taken offline, removing the network path to the asset serves as a recognized IEC 62443 compensating control.

Can NetFoundry be deployed on-premises or in an air-gapped environment?

NetFoundry runs fully on-premises or in a completely air-gapped environment on commodity hardware you already own. It needs no proprietary appliance and no vendor-hosted cloud, which lets it satisfy OT security reviews that prohibit outside connectivity. Local enforcement continues even if the WAN or cloud link drops, keeping plant-to-plant and on-site connectivity running and protecting production during an outage.

How does NetFoundry stop lateral movement between IT and OT?

NetFoundry stops lateral movement by enforcing default-deny, identity-based segmentation between IT and OT and between individual machines. It grants access by verified identity to a specific service rather than by IP address or network location. A compromise in IT or a single infected device therefore has no authorized path to spread onto the plant floor. Even when an attacker exploits one asset, the blast radius stays contained to that asset, because no lateral path exists to anything else.

Does NetFoundry replace my existing OT security and detection tools?

NetFoundry does not replace your discovery and detection tools; it enforces what they find. Those tools identify the assets and threats on your network, and NetFoundry provides the connectivity and segmentation layer beneath them, granting least-privilege, identity-based access to each asset and streaming session and policy data back to the SIEM or SOC tooling your team already uses. A single enforcement layer then acts on the visibility your existing stack produces.

How does NetFoundry secure remote vendor and OEM access to equipment?

NetFoundry gives each vendor or OEM identity just-in-time, least-privilege access to only the specific equipment it is authorized to service, with no VPN and no open inbound ports. NetFoundry authenticates every session by identity and records it in full for audit, and your team grants or revokes access without firewall or infrastructure changes. This replaces broad VPN tunnels and jump servers with a door to one machine rather than the whole plant, and it enables remote diagnostics without a truck roll.

How does NetFoundry connect constrained IoT devices at fleet scale?

NetFoundry connects IoT fleets by giving each device its own cryptographic identity through an embeddable SDK or a lightweight tunneler, with no traditional agent, no public IP, and no per-device firewall rules. Devices communicate outbound-only, which keeps them invisible to inbound scans, and default isolation prevents any one compromised device from reaching the others. The same identity model works across cellular, edge, air-gapped, and roaming deployments, and NetFoundry’s connectivity ships embedded in Siemens SINEC Secure Connect, proof that it scales inside industrial products.

Still have a question we didn’t cover? Talk to Us

Get started

Raise Your Security Without Risking Uptime

See how NetFoundry keeps production running while it contains lateral movement and protects the assets you can’t patch.