Why Digital Transformation Left OT’s Traditional “Broken” Networking in the Dust
NetFoundry CEO Galeal Zino was recently interviewed by Larry O’Brien, VP of Research at ARC Advisory Group, where they discussed the realities of OT’s “broken” networking paradigm.
The old strategy for Operational Technology (OT) security was simple: build a fortress. You air-gapped the systems, set up a flat network, and focused on keeping everyone out. But in the era of Industry 5.0, that model is officially broken.
Watch the complete interview here:
With the rise of predictive maintenance, digital twins, and edge-to-cloud connectivity, today’s OT networks are inherently porous. Traditional networking models (relying on IP addresses, VLANs, and firewalls) were not built for the modern era of digital transformation, AI, and Industry 5.0. Bolting security solutions onto these outdated networks stifles business agility, decreases velocity, and creates complexity—which ultimately leads to insecurity.
Galeal summed up this reality perfectly:
“When we look at digital transformation, Industry 4.0, Industry 5.0, AI… they’re all great. However, in many ways what they left behind in the dust was the cyber security model, and the networking model. Our mission at NetFoundry is essentially to catch up and rebuild the secure networking model to fit this kind of digital transformation age.”
The Complexity Trap
Attempting to force legacy networking to support modern digital transformation creates friction that kills business velocity. Even worse, it creates vulnerabilities. As Galeal noted, “Actually, the complexity itself becomes insecurity. Nothing that’s complex is ever very secure.”
The Shift to Identity-First Security
Instead of relying on network perimeters, NetFoundry advocates for true Zero Trust based on cryptographically verifiable identities. This “assume breach” mentality allows organizations to solve three massive challenges without risking uptime or human safety:
- Secure Inbound Access: Safely authenticating vendors and remote employees.
- Secure Outbound Data: Routing crucial OT data to the cloud (like AWS) for analytics without opening dangerous inbound firewall ports.
- Internal Segmentation: Isolating threats before they can spread and cause millions in unplanned downtime.
The transition doesn’t require a “big bang” overhaul. By leveraging an open-source ecosystem (e.g., NetFoundry’s OpenZiti) and pre-installed integrations with major vendors like Siemens, organizations can start with a single, high-value use case—and finally leave traditional networking in the dust.
Frequently Asked Questions
1. Why is traditional networking failing Operational Technology (OT) environments? Traditional networking relies heavily on IP addresses, VLANs, and firewalls, which were not built for the highly connected nature of Industry 4.0. To secure modern operations, organizations are forced to “bolt on” complex security layers, which can reduce business agility and introduce new vulnerabilities that threaten uptime and reliability.
2. How does a zero-trust network overlay improve industrial cyber security? Instead of relying on network perimeters and IP addresses, a zero-trust overlay uses strong, cryptographically verifiable identities and continuous authentication. This ensures that every connection is authorized based on specific policies, allowing organizations to securely manage data flows and remote access without exposing inbound firewall ports.
3. What are the primary cyber security use cases for OT environments? There are three main use cases for modern OT networking: securely enabling remote access for vendors and employees, safely extracting outbound data to IT systems or the cloud, and implementing internal network segmentation to isolate potential breaches and maintain visibility.
4. How does NetFoundry integrate with existing industrial network hardware? NetFoundry is designed to work seamlessly within existing OT environments, including legacy Layer 2 networks. It can be deployed via software or utilized through native integrations with major vendors, such as being pre-installed on Siemens SCALANCE network components and SINEC Secure Connect platforms.
5. What is OpenZiti and how does it relate to secure networking? OpenZiti is an open-source zero-trust networking platform created and maintained by NetFoundry. Often described as the “Linux of secure networking,” it allows developers and organizations to embed secure, identity-based networking directly into their applications and infrastructure at their own pace.
Full Transcript
Larry: Hi everybody, I’m Larry O’Brien, Vice President of Research for ARC Advisory Group, and we’re here in another edition of our Digital Transformation podcast. Today’s podcast is more OT and industrial cyber security focused. I have with me here today Galeal Zino, the Founder and CEO of NetFoundry. Good afternoon, Galeal, how are you doing today?
Galeal: Larry, how are you?
Larry: I’m really good. Thanks for joining us. So as you know here at ARC, we track everything related to industrial cyber security. NetFoundry is a company that recently was at our ARC forum or ARC Industry Forum in Orlando and sponsored the forum, so we thank you for that Galeal. But today we’re here to talk a little bit more about what NetFoundry’s doing. And I’d like to start off with my first question, and that’s just sort of a general overview. Maybe you could tell us a little bit about who NetFoundry is and what it is you guys are doing and how you view industrial cyber security.
Galeal: Yeah, always happy to talk about NetFoundry, one of my favorite topics. But even before that, Larry, pleasure meeting you and your team and your community in Orlando I guess a few short weeks ago. Time goes by fast.
Larry: It goes by fast, it goes by fast.
Galeal: Yeah, but great event. So thank you for that, and it’s great to meet you guys. So NetFoundry, this might sound a little bit grandiose, but but I started the company to solve or to help solve what we saw as two of the most important problems in the business world, cyber security and networking. It turns out they go hand in hand, Larry. And we can kind of unpack that, but, you know, when we look at digital transformation, Industry 4.0, Industry 5.0, AI, you know, when we look at all these things, they’re all great. However, in many ways what they left behind in the dust was the cyber security model, was the networking model. And our mission at NetFoundry is essentially to catch up and, and, and rebuild the secure networking model to fit this kind of digital transformation age.
Larry: Yep, and I agree with you. You know, even at the forum you could see that. Lots of people talking about digital transformation and the application of industrial AI. I think people get so enamored with these new technologies and implementing them that cyber security can a lot of times be an afterthought, you know? It, you know, it’s not as attractive, I guess, as, you know, talking about these sweeping topics like digital transformation and so forth, but it is a very necessary part of all these elements. And let’s talk about your philosophy, you know, at NetFoundry. And I think the phrase that you used, you know, when we were talking earlier is that the network is broken. Can you elaborate a little bit on that and you know, how you how you view that, in context of industry?
Galeal: Yeah, absolutely. So actually it starts where you left off a bit there Larry, in terms of, you know, cyber security quote unquote not being attractive or networking quote unquote not being attractive. I think what has changed is that in, in today’s world, post-digital transformation or, you know, Industry 5.0, etc., whatever terms you want to use, in today’s world, it’s not really about security or networking. It’s about reliability. It’s about uptime. It’s about business continuity. In other words, networking and cyber security today as we speak are more important in those contexts than they ever have been before. And I think Larry, the, the reason this ties together is because networking is so broken, as the term I used before. What it means is we have to bolt on a lot of stuff on top of networking. We have to kind of take something that inherently not built for today’s world and certainly not built for a world like OT that needs like you know, the levels of, of uptime and reliability and predictability and security that it does. And so we bolt on all this other stuff. And then you bolt on all that other stuff and that breaks business velocity and that breaks agility. And actually the complexity itself becomes insecurity. Nothing that’s complex is, is, is ever very secure. At starting at a high level, what I, what I mean by that if I unpack that a little bit, the way we are doing networking today is using things like IP addresses and VLANs and network routing protocols and firewalls and firewall ACLs. We’re using those things as substitutes or proxies for actual identity, authentication, authorization, policy, continuous authentication, authorization, right. These things are core to security anywhere, right. But especially on the network, and because, again, with networking we’re not doing those things, we ended up, at NetFoundry and, and, and many others are as well saying, okay, let’s go from a world of IP addresses. Let’s replace that with identities, like cryptographically verifiable identities, strong identities, and authentication, authorization. Let’s go from a world of networking, DNS, NAT, CGNAT, IP addresses, VLANs, firewalls, firewall ACLs, to a world of policies. Does this identity, under these conditions have the right to connect to this identity, under its posture? And if so, how do you connect them in a very simple, reliable manner? That’s where we’ve taken networking and, and hence cyber security.
Larry: Yeah, and it sounds kind of like taking the zero-trust you know concept another step forward too, I think. So it sounds like this network overlay creates kind of a fortress of sorts, I guess you could say. I mean, you know, one thing I’ve noticed when we talked about it at the forum is that industrial organizations are no longer the kind of fortresses that they tried to build in the past, right? I mean, I think in the past, the focus was on keeping everybody out. But that’s not really possible today, right? As as you mentioned when we spoke before. I mean, and I mentioned this at the forum too, organizations have become kind of porous. You know, we have all these kind of transient inbound and outbound connections, you know, and digital transformation has just compounded the issue, right, where we have so many people that need so much access to so much data, you know, throughout the enterprise, and this number’s only increasing. Any, any thoughts on that?
Galeal: Yeah, I think porous is exactly the right word. When we talked before about how digital transformation has kind of left the old secure networking model in the dust. If you look at that for OT specifically, it used to be viable and realistic to essentially keep everybody out, have a flat network, put up a big barrier between that and the rest of the world. And with some clever engineering and some hardware and some proper processes, you know, you, you, you could do that. In today’s world with predictive maintenance, with digital twins, with big data, with AI, with inferencing, with the connectivity between OT and IT, the connectivity between OT and edge, the connectivity between OT and the cloud and vendors, yeah, porous is, is the word. And so, you also mentioned zero trust. I think the key part of that, and this is a loaded term, right, like we have a love-hate relationship with zero trust like everyone else, but, but the key part of that is, assume breach, right? Assume that you’re porous. Assume that things are not necessarily going to be a sunny day every single day, and build accordingly. And just clicking one step deeper, I think in OT land what that means is if, if your top goals are uptime, reliability, human safety, business continuity, like those things haven’t changed, and they can’t change, and they won’t change. So it’s almost like how do you reinvent the secure networking to match the new reality, to match digital transformation, Industry 4.0, Industry 5.0, while still, you know, if anything improving those things. And that’s, that’s what we’re here to do and that’s what we’ve been doing.
Larry: Yeah, and I think these old approaches really do represent you know, a threat to uptime, as you said. We find here at ARC that the users are finding more and more that cyber security-related incidents are now a major source of unplanned downtime. You know, whereas in the past it used to be things like operator error or, or, you know, things like that, equipment error, what have you, but, but now, you know, unplanned downtime, which we estimate costs industry worldwide about, you know, easily over a trillion dollars a year, so users should definitely be thinking about cyber security in the context of, you know, uptime and unplanned downtime. Can, can you tell us a little bit about how your solution is used specifically in OT environments? Maybe some use cases for example?
Galeal: Sure, yeah. We’ll talk about three use cases to start. Depending on the organization, but let’s just take, you know, most of our customers look like a, maybe they have 20, 30, 40 sites globally, you know, fairly large. And therefore all the things that you said are really important to them. Uptime and reliability and human safety and, and of course business continuity and, and security. The three things that our customers are trying to solve, one is, how do I, you know, as you said, essentially let the outside world in? So secure remote access, remote access in general. That can be secure remote access for vendors. That can be secure remote access for employees, contractors, machines, AIs, there’s a lot there. But let’s put that as kind of one general use case. The other second use case is more like data outbound from OT. So how do I let that data get to IT, get to the edge, get to the vendors, get to the cloud, in a very secure manner that’s again, not going to compromise uptime and, and reliability, and is going to have the right performance, you know, jitter, latency, packet loss, etc. And then three is segmentation within the OT environment. So I mentioned earlier, you always want to assume the worst, right? You want to assume you’re already breached. You want to assume that there’s already some, some problems in your network. Well, segmentation becomes really important in those contexts, from perspectives like visibility, right? Even seeing the issue. Segmentation is very helpful. Obviously, if you do have the issue, kind of quarantining it or sandboxing it or isolating it. And ultimately on the remediation side, if you have properly segmented, sandboxed, isolated, the remediation step also not only becomes simpler and faster, but less of a threat to uptime, reliability, etc., because you’re essentially taking action on, on a segment. So, we’ve helped our customers in all three. Our platform and our software is, is fairly unique in that you can deploy it however you wish. So you could deploy it, let’s say, fully on-prem. You could also deploy it in hybrid and cloud scenarios. So one in terms of how you deploy it. Two, it’s built to give you the identities and the policies that I described earlier for all of those use cases. It’s, it’s a horizontal, just call it a platform. But you do not need to do all three use cases at once. It is built specifically to enable you, for example, to start in any of those three use cases, or even subsets of those three use cases. Let me talk about some examples later perhaps. Three, it’s built for OT. So you know, as a quick example, there’s a lot of Layer 2 in OT. It’s not just Layer 3. There’s a lot of devices in OT that you’re just not going to touch. You’re not… maybe in 5, 10, 15, 20 years. Maybe. But for all intents and purposes, you’re not going to touch them anytime soon. And you have different zones, and you have the Purdue model, and you have the firewall to that. There’s some very specific constraints in, in OT and some very specific functionality, like I’m using Layer 2 as an example, and on-prem as an example, that has enabled us to solve all three of those use cases for our customers.
Larry: Yeah, we have lots of assets at Layer 2 in the OT world. That’s for sure. I’m sure, you know, probably more than at Level 3. So it does need to be able to to address that OT specific, you know, Layer 2. And I’m also glad to hear you use the word a platform, right? Because we’ve seen the same thing like you said before about adding on and adding on. I think that’s been kind of a, you know, previous philosophy among end users is you bolt on security. But what we’re finding is the users can’t deal with that anymore, right? They don’t have the resources and the expertise to handle all these different bolt-ons and different tools. You know, they’re looking for something that’s more of a platformized approach, you know, that they can centrally manage and, you know, takes them less time and money and effort, to do that, and we definitely see that as a major trend. Can you provide any specific customer examples of, you know, who’s using this and and, you know, how it’s used specifically in practice in OT?
Galeal: Yeah, let’s, we’ll do a few. One very recent, it was a great one. It’s a a large factory in Germany. They historically rightfully so had, had kind of denied every vendor proposition let’s say to enable them to send data out of OT towards IT, ultimately to the cloud. Ultimately to… actually in this case it was AWS S3, but you know it could have been anywhere. For very good reason, they were not going to open inbound firewall ports. They had to make sure that they essentially had a, just call it a virtual data diode type approach. They had to make sure they had segmentation and visibility. Kill switch, like all these things had to be built in. And so in the meantime, Larry, what they were doing because it was important to get the data up to S3 for the data analytics and data warehousing and, and everything else, some of it is like kind of SIEM, SOAR type data, was, was sneakernet. Right? They, they, they were taking drives out of the factory, and plugging them in somewhere else, where they could securely upload the data to, again in this case S3. And of course it’s not what they wanted to do. But they had no other choice. The other choices were worse. The other choices were complexity and risk and risk to, to uptime and reliability and the things we talked about earlier. And so what they did with us is, they started just by solving that use case. So yeah I mentioned earlier like, great, we’re a platform and you can use this for multiple use cases, fantastic. But you can also start with even one use case. Even a use case as specific and discrete as that use case without touching your firewalls, without touching your network, without installing software. And so that’s exactly what they did. And sure, you know, they have plans for, to solve other problems, and now that the platform’s in place, as they solve all those other problems they can do it without more vendor sprawl. They have centralized identity, centralized telemetry, centralized policy. Like all these good things. But for now Larry, they’re just thrilled that they no longer have sneakernet to AWS S3.
Larry: Yeah, I can’t imagine how time consuming that must be. Removing drives and transporting them and everything. I, and that’s a good place to start, and, and we tell people that too, you know. This doesn’t have to, when you do these types of things, it doesn’t have to be a big bang kind of implementation. You know, start with a high value use case. And I think that, that use case makes a lot of sense. And that’s another thing we tell users, is look at the, you know, look at the business impact of what you’re doing. You know, pick something that’s going to have the biggest impact, you know, probably with the least amount of work, you know, to start off with, and then work your way out from there. One other thing I wanted to ask you, what sounds really interesting to me, I’ve heard that you’re pre-installed on some major vendor networking gear. You know, one of those examples is Siemens. Can you tell us a little bit more about that?
Galeal: Yeah. Well, we started by saying like, you know, we have some pretty grandiose or mission driven company. We’re trying to solve networking, we’re trying to solve networking security, we’re trying to do it for OT with, with, you know, reliability and uptime and human safety. To do that, we are very much a partner first company. We believe this is a multilayered, this is an ecosystem approach. And we want to partner with the best. And so, you know, Cisco is an investor in NetFoundry. We have public relationships with, you know, very large US MilGov type firms who bring competencies to the table. The Siemens relationship, was announced relatively recently. They have fantastic technology, in their SCALANCE product lines, their firewalls, their what’s called SINEC Secure Connect. And what they did is, is they just built us into those solutions to make it much easier for the end customers to be able to well, solve the three use cases that we talked about earlier. So, you know, for example the Siemens SCALANCE lines and, and other Siemens products, these range from, you know, edge compute at the top of cells that now have zero trust capabilities, so it enables you to do kind of segmentation between cells, enables you to do outbound out from the cells, without opening firewall ports, without any risk of inbound, all to a private Siemens overlay network. It allows you to do the secure remote access with SINEC Secure Connect. So Siemens has if, if folks haven’t used it, SINEC Secure Connect is an incredibly robust platform, and now with a little bit of NetFoundry in it, it makes it that much easier to use, secure, and powerful.
Larry: That’s very interesting. Thanks for explaining that a little bit more. Well this has all been really great. I, you know, for those that are interested in finding out more information, where, where can they go?
Galeal: netfoundry.io is the best place. From there, you’ll find a a wealth of information and and different paths. I will mention that, well, like, like Siemens, like Cisco, we believe in open source. We do believe that we need a, a Linux of secure networking, let’s call it to, to keep it simple, Larry. So we’ve also open sourced kind of like our underlying software, OpenZiti. So…
Larry: Yeah, I was going to ask you about that too actually, yeah.
Galeal: Yeah, that’s a, that’s like the second path. Like so you can go to netfoundry.io if you’re the type who, you know, you kind of want to get your hands on it, you want to see what, you know, sure, you, you understand what we say is written on the tin, but you want to find out for yourself, you want to do it at your own pace, etc. You can go to openziti.io. You can go to the GitHub, etc. Just to be clear, like, we didn’t, we didn’t open source it and then ignore it. Like quite the opposite. We wanted it to be the Linux of secure networking. It’s on that trajectory. We maintain it. We continually invest in it. So it’s a, it’s a thriving community of folks who are using the capabilities like in, in new innovative ways every day, like that we hadn’t even, you know, imagined. So yeah, you have the OpenZiti route, you have the NetFoundry route, and then either of those will bring you to plenty of other pathways.
Larry: Great. Those yeah, those are great resources and, I, I really respect your support of open source. That that all sounds really cool stuff. So we urge our end user customers to check out NetFoundry and OpenZiti, and, this again, this is Larry O’Brien, Vice President of Research at ARC Advisory Group, and we’ve had with us today on our Digital Transformation podcast Galeal Zino, the Founder and CEO of NetFoundry. Galeal, thanks very much for joining us today.
Galeal: Larry, my pleasure. Thank you.
Larry: Yeah, hopefully we can have you back on in the future. Look forward to it.
Galeal: Absolutely. Looking forward to it. Appreciate it, Larry.