Operational Technology (OT) Product Builder Demo

Operational Technology (OT) Product Builder Demo

Product screenshot of Identities and Watch List. Demo video thumbnail.

In this presentation, Hersh Sangvi from NetFoundry demonstrates how Operational Technology (OT) product builders can embed zero-trust connectivity directly into their devices.

This built-in secure networking bypasses the traditionally slow and complex IT security approvals required by customers, allowing OT vendors to seamlessly and securely access their deployed products remotely. By utilizing automated, “just-in-time” access, companies can quickly troubleshoot hardware, ensure regulatory compliance, and significantly reduce the operational costs associated with on-site visits.

Three Key Takeaways:

  • Overcoming Traditional Connectivity Bottlenecks: Relying on traditional VPNs or navigating a customer’s internal IT and security processes can delay deployments and troubleshooting by weeks or months. By embedding secure connectivity directly into the product, vendors avoid these hurdles and drastically reduce the need for expensive on-site visits (“truck rolls”).
  • Just-in-Time, Least-Privilege Access: The demonstration highlights a highly secure, automated workflow for remote troubleshooting. A support engineer is granted temporary access to specific customer resources only after a support ticket is approved. Once the task is complete and the ticket is closed, access is instantaneously revoked, ensuring strict security boundaries are maintained.
  • Driving Compliance and New Revenue Streams: Operating with secure-by-design connectivity makes it much easier to comply with strict, incoming cybersecurity regulations (such as the CRA). Furthermore, reliable remote access enables OT builders to launch new, revenue-generating services for their customers, such as proactive maintenance and AI-driven analytics.

OT Product Builder – Pain Points Resolved

Lack of visibility
Disconnected OT product builders are blind to how their products are being utilized and can be potentially improved

Sales, deployment, consumption velocity
Enterprise IT/cybersecurity requirements and processes can take weeks/months to enable the connectivity required for connected OT products to be demo’d, deployed and put in operations by the customers.

High OPEX
Legacy connectivity solutions are complex to maintain and require dedicated team of experts to troubleshoot network issues. Lack of reliable connectivity results in more frequent onsite visits to resolve product issues v/s being able to troubleshoot and remediate remotely.

Customer Satisfaction
Network connectivity issues are viewed by customers as product issues and impacts their overall satisfaction with your products and services.

Revenue stagnation
Lack of reliable, consistent and secure connectivity prohibits OT product builders from providing value added products and services to increase their book of business with existing customers.

Regulatory Compliance
Current and upcoming compliance requirements mandate that connect OT products must be ‘secure by design’ and must work securely even if the underlying customer network is not secure (e.g. CRA, NERC-CIP etc)

Contact us today for a live demo!

Frequently Asked Questions

1. What are the main connectivity challenges faced by OT product builders?

OT product builders typically encounter several significant hurdles when relying on traditional network connectivity:

  • Lengthy Deployment Cycles: Relying on a customer’s internal IT and security processes can delay necessary connectivity by weeks or even months.
  • High Operational Costs (OPEX): Legacy VPNs are notoriously difficult to maintain, and the lack of reliable remote access leads to costly on-site visits (truck rolls) to resolve issues.
  • Stifled Innovation: Inadequate connectivity prevents teams from launching new features and advanced AI/ML-driven services.
  • Compliance Risks: New regulations like the Cyber Resilience Act (CRA) enforce strict penalties for OT products that fail to operate securely on untrusted networks.

2. How does NetFoundry secure remote access for OT environments?

NetFoundry utilizes a zero-trust, API-driven platform to ensure fast and secure remote access:

  • Just-in-Time Access: A support engineer requests access via a ticketing system, which is approved by an administrator.
  • Automated Policy Provisioning: Upon ticket approval, an API call instantly pushes specific access policies directly to the engineer’s device.
  • Private DNS Security: The system uses private DNS, allowing engineers to connect to resources using literal names without ever exposing the underlying IP addresses or domain names.
  • Instant Revocation: As soon as the task (such as updating a PLC) is complete and the ticket is closed, an API call instantly revokes access, rendering the user blind to the network resources once again.

3. How does traditional connectivity compare to NetFoundry’s zero-trust approach?

Embedding NetFoundry’s zero-trust capabilities directly transforms how you manage your OT products:

FeatureTraditional ConnectivityNetFoundry Zero-Trust
Deployment TimeDelayed by weeks/months waiting for IT/security approvals.Instant, API-driven policy provisioning.
Maintenance & SupportRequires expensive on-site “truck rolls” to troubleshoot issues.Enables efficient, instantaneous remote access for troubleshooting.
Network VisibilityExposes actual IP addresses and domain names.Private DNS ensures exact network details are never exposed to the end user.
Compliance & GrowthLacks the security needed for CRA compliance and hinders new service launches.Secure-by-design, meeting compliance standards and enabling new AI/ML revenue streams.

Full Transcript

Hello everyone, it’s my name is Harsh Sanghvi, and I lead the Sales Engineering and Customer Success teams at NetFoundry. Today I’m going to do a quick demo on how an OT product builder can bake in zero trust connectivity from NetFoundry into their products and really simplify how their connected products can connect back to their data centers or your engineers be able to get into the products and do the troubleshooting remotely.

So first off, let’s start with the pain points. We have several OT product builders who are using NetFoundry secure connectivity today, and essentially what they tell us is before NetFoundry, there was a significant impact to how quickly their sales were able to demo their connected products or their deployment team were able to deploy or the customer was able to consume. It all boiled down to the internal IT or security processes, which would sometimes take months and weeks to get the connectivity required by your products. That almost always results in high operational costs of managing the connectivity. Typically, a lot of our customers come to us having previously used VPN-based connectivities and really struggling to keep them up. At the end of the day, it has an impact on customer satisfaction because the customer looks at the connectivity issues as the issues with your products or services. At the same time, it typically results in a lot more truck rolls, sending somebody onsite to solve issues that could easily be resolved remotely.

Last but not the least, a couple more points or pain points that our customers share with us is because the lack of connectivity could result in them not being able to launch new features, new services that would rely on being able to connect, either pulling data out of their products deployed in the customer’s environment or being able to remotely access those devices to be able to support them. As well as compliance is coming down fast, for example, CRA, there are penalty-based requirements which mandate that your OT products must be secure and operate securely even if the underlying network from the customer is not inherently secure. And lack of visibility due to lack of connectivity really makes it impossible to be compliant with that.

So here is my demo environment where I have a typical OT network and with an IoT gateway on a separate network and MQTT broker and on a completely separate network, some SCADA system as well as OpenPLC. When I say different networks, they could be either co-located in an air-gap fashion in the OT domain, or it could be in the customer’s IT domain, or it could be offered by you as a service completely run off of your cloud or your on-prem data centers.

The scenario that I’m going to talk through is me as a client, as a customer support engineer working for the OT product builder, requesting access to some data, to some OT resources and being able to get it securely in a moments of time without having to go through the hassle of working through the customer’s IT departments. So first off, the NetFoundry platform, once you kind of log in, integrate with your SSO system, and your OT engineer has received a ticket or your support engineer has received a ticket from the customer and determined that he or she needs access. So your administrators would have an access like this where they can manage your entire business either on a single network or have multiple networks in a single pane of glass, but overall everything boils down to a NetFoundry network to strong identities.

On my computer, I am using a MacBook and I have this NetFoundry software deployed as a support engineer, and then essentially once I open the ticket, the ticket is approved by my manager, and as soon as the ticket is approved, an API call gets made to the NetFoundry platform which grants me access to this particular customer’s environment. And as soon as the access is granted, within a few seconds, I’m going to get those policies pushed down onto my NetFoundry software here. By default, I get access to nothing, so even if there is many, many different resources across many, many different customers, by default because of the least privilege access, I have access to nothing. And now when the policy was added, I got access to some resources only for that particular customer. And I can get to only these resources and nothing else.

Another thing is I can use these literal names because there is private DNS built-in, so I never need to know what is the actual IP address, what is the actual domain name of the device in the customer’s environment. So this is a nice another layer of security that kind of comes in-built with the platform. So now that I have access, I can go in, log into the resources that I need to, and really be able to look at the data that I need to, and once I see the data, be able to troubleshoot that, okay, there is a problem statement, I’m kind of seeing the resources for which the ticket was opened, and I can see that, alright, some data I’m seeing it and I notice that some search where I need to go and power cycle and maybe update a PLC.

So I’m going to go to a second app, and really this is a use case of sending some command and control, so I’m kind of logging into my other app, I say that, okay, I need to update this PLC, I turn it off, as soon as I turn it off, obviously the live data is going to be stopped being reported by that particular PLC, I’m done updating it, making the changes, I go ahead and restart that PLC, and as soon as I restart, obviously the data is going to start showing up live again.

I’m done with my work, I go ahead and close the ticket, as soon as I close the ticket, another API call gets made, which revokes my access, so just in time I got the access and as soon as I was done, the access was revoked. And once the access is revoked, network is going to do the opposite thing, it’s going to revoke my access and again I become blind to those resources. So even if I know where those resources are, those resources are not going to work for me anymore because I no longer have access from the NetFoundry network.

The same thing can be done if I did not have this particular piece of software installed on my computer, then the same resources could have been opened up for me in a temporary basis using a clientless approach which we call a NetFoundry Front Door, but more about that later.

So overall in this demo, I was able to kind of show you that you are no longer inhibited by the connectivity. You have full control once you embed NetFoundry into your connected OT products, you have full control without having to deal with the complex, lengthy processes with the customer IT team, the customer’s network team, or the security team to get the access that you need in order to provide the services that you are providing to your customers. At the end of the day, it has a direct impact on your top line by being able to sell more and being able to get your customers to actually consume what you’re selling them, reduce your OPEX, you don’t have to do as many truck rolls, you’ll be able to support your products remotely very efficiently, and with less number of people obviously because you don’t have to hire experts to troubleshoot and maintain those VPN connections.

Again, I talked about compliance, the incoming compliances like CRA, so you’ll be not only compliant with them today, but going into the future. At the same time, having secure-by-design products would enable you to kind of add new revenue sources like proactive maintenance, AI/ML driven types of functionality to your existing customers and grow your book of business. So that’s all I wanted to share today, thank you for your time, and see you on the next one.