Securing Drones, Handsets, and Data at the Edge: Zero Trust for Private 5G Military Networks

How a top-5 U.S. military contractor replaced VPN-dependent security with session-level Zero Trust

Drone

Contents

  • Company: Top 5 U.S. Military Government Contractor (confidential)
  • Industry: Government/Public — Defense
  • HQ: Undisclosed
  • Customers: U.S. military and defense operations
  • Products Used:
    • The NetFoundry Platform

Ready to get started?

Legacy VPNs couldn’t secure real-time drone-to-handset data over a private 5G network without IP conflicts and coarse-grained access.

NetFoundry’s Zero Trust platform embedded directly into handsets, drones, databases, and intermediate firewalls.

Session-level microsegmentation with centralized control, deployed on any device without IP address dependencies.

About the Contractor

This military contractor operates within the 5G.MIL™ ecosystem, a secure, 5G-enabled “network of networks” that integrates military and commercial telecommunications infrastructure. It’s built to support resilient communication across air, land, sea, space, and cyber domains, and to improve interoperability between 5G, NextG, and DoD networks during live operations.

As part of a private 5G deployment, the contractor needed to move highly sensitive reconnaissance data captured by drones to ground troops in real time, across handsets running different operating systems, without the traditional tradeoff between usability and security. That combination of scale, sensitivity, and device diversity made this one of the more demanding Zero Trust use cases NetFoundry has supported to date.

The Challenge: Legacy VPNs couldn’t keep up with real-time battlefield data

The contractor needed to move sensitive mapping and reconnaissance data captured by drones across a private 5G wireless network to a cluster of virtualized databases, then out to ground troops’ mobile handsets, all in real time, and all without creating new security gaps. Their existing architecture wasn’t built for that.

Traditional VPNs didn’t scale

VPNs are cumbersome to deploy and manage at this scale, and they don’t offer the granularity of access control this environment demands. Every additional device or session added more configuration overhead.

Ground troops needed mobile, real-time access

Ground troops needed a secure but flexible way to access and interact with drone data on mobile handsets in the field, without waiting on static network configurations to catch up to where they physically were.

Existing security couldn’t cover the stakes

The consequences of a data breach in this environment aren’t theoretical. Existing security measures weren’t built to give the fine-grained, session-level control that mission-critical, life-and-safety data requires.

The Solution: Zero Trust, embedded at every touchpoint

The contractor deployed NetFoundry’s Zero Trust platform directly onto handsets, drones, databases, and intermediate firewalls, achieving session-level microsegmentation with centralized policy control across the entire private 5G environment.

Identity-first Overlays Removed IP Conflicts

Because NetFoundry’s overlay is identity-based rather than IP-based, it eliminated the RFC 1918 IP space overlap issues that typically complicate multi-device, multi-network military deployments. Devices could be provisioned and reach each other without depending on a shared or conflict-free IP scheme. 

Session-level microsegmentation across every boundary

Only specific, authorized sessions could pass each low-to-high security boundary. Every handset, drone, and database connection was governed by its own least-privilege policy, so a compromised or misconfigured endpoint couldn’t move laterally into a higher-trust zone.

Deploys on the fly, on any device and any OS

Because the platform doesn’t depend on IP addressing to establish trust, it could be deployed on the fly across a mix of device types and operating systems already in the field, without re-architecting the network to accommodate each one.

End-to-end encryption with fine-grained access

Application-layer encryption ensured only authenticated, authorized entities reached the data. Ground troops could access exactly what their role and mission required, and nothing more.

The Results: Mission-critical data, secured from drone to handset

Integrating NetFoundry’s Zero Trust platform gives the contractor secure, real-time communication across the full private 5G environment, from drone capture to ground troop access, without the VPN overhead or IP conflicts that constrained the previous architecture.

Every communication path secured

Zero Trust architecture protects every leg of the journey, from drones to virtualized databases to ground troops’ handsets, with real-time encryption and authentication preventing unauthorized access at each step.

Improved situational awareness in the field

Ground troops can now securely and efficiently retrieve up-to-date mapping and reconnaissance data on their handsets, directly improving situational awareness during operations.

Proven private 5G for battlefield intelligence

The deployment demonstrated that drones and private 5G networks can reliably support secure, real-time battlefield intelligence at the device level, not just at the network perimeter.

Products and Solutions Used 

  • NetFoundry Platform: Identity-first Zero Trust connectivity embedded directly into field devices, drones, and databases, with no open inbound ports required.
  • OpenZiti: The open-source Zero Trust engine underlying the deployment, enabling session-level microsegmentation and mTLS-based authentication across any device or OS.

Mission-critical networks deserve Zero Trust they can depend on.

NetFoundry helps defense and enterprise teams eliminate open attack surfaces, remove VPN complexity, and extend Zero Trust to any device, anywhere, without rebuilding their architecture from scratch.

About Netfoundry

NetFoundry is a leader in Secure Workload Connectivity, founded by the inventors and maintainers of OpenZiti, the world’s most widely used open source Zero Trust platform. NetFoundry enables enterprises to secure and connect AI agents, MCP servers, LLMs, APIs, OT/IoT infrastructure, and traditional enterprise workloads, all with no open inbound ports, no VPNs, and no firewall changes. NetFoundry secures billions of sessions for critical infrastructure on three continents and supports Fortune 10 companies across regulated industries including healthcare, financial services, and energy.

They Made the Switch. Here’s What Happened.