Eziwan SaaS (Zero Trust) vs. TeamViewer + IPSec VPN (traditional)
| Criterion | Eziwan SaaS (Zero Trust) | TeamViewer / IPSec VPN |
|---|---|---|
| New Website Launch | ✓ Automatic ZTP < 1 hour | ✗ 2–4 days (network engineer) |
| Security Architecture | ✓ Zero Trust, zero-inbound-port | ✗ Perimeter VPN (network access) |
| Granular audit trail | ✓ Logging by action + who + when | ✗ Basic connection logs (IP address + duration) |
| NIS2 Compliance | ✓ Native integration (access, logs, 2FA) | ✗ Partial with offsets |
| CAPEX Infrastructure Costs | ✓ Zero (no hub/PKI) | ✗ High (concentrator, PKI, FW) |
| 5-Year TCO (10 sites) | ✓ 70 000-100 000€ | ✗ 95 000-195 000€ |
| Typical MTTR | ✓ < 30 minutes (immediate access) | ✗ 2–8 hours (travel may be required) |
| First-call resolution rate | ✓ 65-80% | ✗ 30-50% |
| Technician Mobility | ✓ Web browser or mobile app | ✗ VPN client + TeamViewer on PC required |
| OT Controller Compatibility | ✓ Modbus RTU/TCP, SNMP, RS-485 | ✗ Windows only (TeamViewer) |
| CMMS/EAM Integration | ✓ Native REST API (SAP PM, Maximo) | ✗ Does not exist (manual access) |
| Two-Factor Authentication (2FA) | ✓ Embedded (TOTP/FIDO2) | Optional (manual configuration) |
| GDPR Compliance Logs | ✓ EU Hosting, Article 28 of the DPA | Varies depending on the configuration |
| Multi-site scalability | ✓ Immediate (self-service addition) | ✗ Complex (network configuration by site) |
| Infrastructure Maintenance | ✓ Zero (managed cloud, automatic updates) | ✗ Resource-intensive (servers + certificates + rules) |
8 Dimensions for Comparing SaaS-Based and Traditional Industrial Remote Maintenance
Deploying an Eziwan gateway at a new site takes less than an hour thanks to Zero Touch Provisioning: plug it in, power it on, and insert a SIM card. The gateway contacts the cloud platform, downloads its configuration, establishes the OpenVPN tunnel, and is up and running. A traditional IPSec VPN infrastructure requires: configuring the concentrator at headquarters, setting up firewall rules on both sides, generating PKI certificates for each site, performing round-trip connectivity tests, and creating network documentation. Across 10 sites, the Eziwan advantage translates to 2 to 4 weeks of engineering work saved, or 20,000 to 40,000 euros.
The perimeter-based IPSec VPN approach provides broad network access once connected. A technician with VPN access can potentially reach all devices on the OT network, not just those for which they are authorized—this is known as lateral movement, a major attack vector in industrial cybersecurity incidents. Eziwan applies the Zero Trust principle: every access attempt is authenticated, authorized by granular policies (technician X, device Y, from 9 a.m. to 5 p.m. on business days), and logged. This is the difference between “access to the building” and “access to room X between 9 a.m. and 5 p.m. with a time and attendance log.”
For 10 industrial sites, the TCO over 5 years is drastically different. Traditional IPSec VPN: CAPEX: hub €10,000 to €20,000 + firewalls €10,000 to €20,000 + PKI €5,000 + deployment engineering €30,000 to €50,000 + annual maintenance10,000 to 20,000 euros × 5 = 105,000 to 195,000 euros. Eziwan SaaS: gateway: 1,000 euros × 10 = 10,000 euros + subscription: 100 euros × 10 sites × 60 months = 60,000 euros = total TCO: 70,000 euros. Savings: 35,000 to 125,000 euros over 5 years. The larger the infrastructure, the greater the SaaS advantage.
NIS2 (transposed into national law as of October 2024) requires significant and critical entities to implement access management, logging, and incident response capabilities. Eziwan natively provides the necessary audit trail: every connection, every Modbus action, and every download is time-stamped and attributed to a user identified by their device. IEC 62443 (cybersecurity for automation and control systems) recommends segmentation by zones and conduits, which Eziwan implements without modifying the OT infrastructure. An NIS2 audit using an Eziwan solution can be documented in a matter of hours; with a traditional VPN, logs must be manually reconstructed.
MTTR (Mean Time to Repair) is the most tangible ROI metric for remote maintenance. With a traditional VPN solution, a technician who cannot connect remotely must travel to the site: 2 to 8 hours of travel time to a remote site + 1 hour of on-site work = an MTTR of 3 to 9 hours. With Eziwan, the connection is established in less than 5 minutes from any browser: MTTR < 30 minutes in 70% of cases. The first-call resolution rate (incidents resolved without on-site visits) increases from 30–50% with a VPN to 65–80% with Eziwan. For a network of 50 sites with 200 incidents per year, the reduction in on-site visits represents annual savings of 50,000 to 100,000 euros.
Eziwan integrates natively with maintenance management systems (CMMS) and asset management systems (EAM) via REST APIs and webhooks. When Eziwan detects an alarm (Modbus threshold exceeded, equipment offline, abnormal current variation), it automatically triggers a webhook that creates a work order in SAP PM, IBM Maximo, Infor EAM, or CARL Source. Historical equipment data (consumption curves, operating hour counters) enriches the CMMS to optimize preventive maintenance intervals. This integration is the first step toward predictive maintenance: Eziwan data feeds anomaly detection algorithms that anticipate failures before they occur.
SaaS-based remote maintenance raises legitimate questions about data ownership and GDPR compliance. Eziwan hosts data in Europe (EU) under a Data Processing Agreement (DPA) that complies with Article 28 of the GDPR, covering the obligations of the data processor. OT data (Modbus values, alarms, history) remains the property of the operator—Eziwan does not use it for commercial purposes. Access logs are encrypted and accessible only via the authenticated API. In the event of termination, the data can be exported in JSON/CSV format and is deleted within 30 days in accordance with the contractual terms.
With a traditional VPN solution, the technician must install a VPN client on their PC (often Windows only), configure personal certificates, connect to the gateway, and then use TeamViewer separately. In the field, using a smartphone or tablet, this is often impossible without additional configuration. Eziwan offers access via a web browser or native iOS/Android mobile app: the technician opens their browser, authenticates using 2FA TOTP (Google Authenticator, Authy), and gains direct access to authorized OT equipment. The reduction in incident resolution time is measurable: an average 40% decrease in MTTR observed among Eziwan customers.
4 Real-World Examples of Transformation in Industrial Remote Maintenance
Background: A manufacturer of packaging machines with 300 machines installed at customer sites in France, Benelux, and Spain
Before Eziwan, every service call on a remote machine required a 1- to 3-day trip (travel + hotel + service time). With Eziwan, 75% of service calls are resolved via remote maintenance in less than 2 hours from the engineering office. Average MTTR reduced from 18 hours to 2.5 hours. Annual savings on field service travel: 180,000 euros. Field service technicians access Schneider M340 PLCs via Modbus TCP from their browsers using 2FA authentication.
Background: An intermunicipal water district classified as a “significant entity” under NIS2, with 55 pumping stations and 3 treatment plants
The union underwent an NIS2 audit by ANSSI in 2025. The Eziwan solution made it possible to present, within two hours, all access logs from the past 18 months: who, when, from which device, and which systems were accessed. The old IPSec VPN only retained IP connection logs, which were insufficient for the audit. NIS2 compliance was validated without any additional mitigating measures. The audit report cited Eziwan as a best practice for OT access control.
Background: An engineering firm that implements automation solutions for 20 industrial clients per year
Before Eziwan, each deployment involved configuring a dedicated VPN for each customer (2 to 3 days of network work). With Eziwan ZTP, deploying the gateway takes 30 minutes on-site. The integrator has reduced its deployment costs by 3,500 euros per project. With 20 projects per year, the savings amount to 70,000 euros. Customers have read-only access to their own Eziwan dashboard for self-monitoring.
Background: Pharmaceutical manufacturing facility compliant with GAMP5 and 21 CFR Part 11 requirements for the traceability of operations
GAMP5 (Good Automated Manufacturing Practice) and 21 CFR Part 11 require that all changes to equipment parameters be tracked with an electronic signature. Eziwan logs every Modbus write with the user ID, a certified NTP timestamp, and the action hash for accountability. Eziwan logs can be exported in CSV format compatible with pharmaceutical audit systems. The GAMP5 validation of the Eziwan solution was completed in 3 weeks, compared to 3 months for the previous VPN.
The 5 Most Costly Mistakes in Implementing Industrial Remote Maintenance
TeamViewer can access Windows workstations, but not PLCs. A Siemens S7 PLC, a Schneider drive, or a Modbus meter does not have a TeamViewer agent. For true OT remote maintenance (reading/writing Modbus registers, modifying PLC parameters), only a network gateway such as Eziwan provides access to the devices via their native protocols.
Configuring a NAT rule on the router to access a PLC directly from the Internet exposes the PLC to all automated scanners. Thousands of industrial PLCs are publicly accessible on ports such as 502 (Modbus) or 102 (Siemens S7). Remote access must always go through an outbound VPN tunnel (OpenVPN Eziwan) without opening any inbound ports.
Without measuring MTTR, first-call resolution rate, and the number of site visits avoided, it is impossible to demonstrate the ROI of a remote maintenance solution to management. Define KPIs before deployment, track them for 3 months, and then present the cost-benefit analysis. Eziwan exports these metrics via its analytics API.
A SaaS-based remote maintenance solution that does not integrate with the CMMS results in duplicate data entry: the technician accesses the equipment via Eziwan and then must manually create the work order in the CMMS. The Eziwan → CMMS Webhook integration automates this process and populates the equipment record with real-time service logs.
A VPN account shared among three technicians makes NIS2 traceability impossible: who did what, and when? NIS2 requires individual access assignments. Each technician must have their own Eziwan account with personalized permissions, their own 2FA, and access limited to the sites and equipment under their responsibility.
Which remote maintenance model is best for your industry?
NIS2 requirements for operators of essential services (OES) mandate a comprehensive audit trail and granular access control. Eziwan natively meets these requirements. Without Eziwan, remote maintenance of the 40 to 200 scattered pumping stations would require dozens of on-site visits each week.
Machine manufacturers maintain hundreds of machines at their end customers' sites around the world. Eziwan enables remote maintenance from the engineering department without the need for on-site visits, reducing MTTR from 4 hours to 30 minutes. The ROI is immediate for after-sales service teams.
At SEVESO-classified sites or those subject to ATEX requirements, compliance with IEC 62443 mandates high levels of security. Eziwan Zero Trust is suitable for most access scenarios. For safety-related equipment (SIS), an additional layer of validation may be required depending on the operator’s internal procedures.
Managing a portfolio of 50 to 500 buildings with a small maintenance staff is the ideal scenario for Eziwan. Centralized monitoring, automatic alerts, and remote maintenance via smartphone reduce operating costs by 25 to 40 percent compared to traditional on-site inspections.
O&M (Operations & Maintenance) teams at wind farms and solar power plants monitor hundreds of pieces of equipment across dozens of sites. Eziwan reduces corrective maintenance by improving the early detection rate of anomalies and enabling remote configuration without the need for on-site visits.
Traditional remote maintenance (modem, self-hosted VPN server, direct access) works but becomes unmanageable and risky when scaled to a fleet. The SaaS model centralizes provisioning, security, and auditing. Here are the regulatory and operational criteria to help you make a decision.
Requires access management, traceability, and incident response. A SaaS portal provides centralized auditing—which is difficult to maintain for scattered VPN access points.
Requirements for service providers and systems: named accounts, least privilege, logging—all built into a remote maintenance platform.
Information Security Management: A certified SaaS provider delivers a level of security that is rarely achievable through self-hosting by small and medium-sized businesses.
Data Location and Protection: Verify the SaaS provider’s hosting (EU/France) and use of third-party service providers.
Encrypted data transmission and mutual authentication via certificates: the common building block, but orchestrated and automatically renewed in a SaaS environment.
Mass deployment without a technician: The gateway downloads its configuration and tunnel settings on first startup—something that's impossible with a manually configured VPN server.
In SaaS, provisioning, updates, access revocation, and auditing are all managed through a single portal. The traditional model requires you to maintain your own VPN server, PKI, backups, and 24/7 availability.
| Criterion | SaaS | Traditionnel |
|---|---|---|
| Deployment | ZTP (minutes) | Manual configuration by site |
| Updates | Centralized OTAs | Service by Equipment Type |
| Cost Model | Predictable operating expenses | Capex + Hidden Maintenance Costs |
| High Availability | Provided by the publisher (SLA) | To be paid by the operator |
| Audit / Compliance | Centralized, NIS2-native | Manual reconstruction |
| Scaling | Linear (1 to 1,000) | Increasing Complexity |
The true cost of the “traditional” approach is hidden: operational time, PKI, backups, on-call duty, and security liabilities—which are rarely quantified up front.
Migration from an overloaded internal VPN server to a multi-tenant SaaS platform: ZTP provisioning, role-based access for technicians, NIS2 audit.
Additional Resources on Industrial Remote Maintenance
Deploy in less than an hour. Access your controllers from your browser. Log every action. Compliant with NIS2 and IEC 62443. Native CMMS integration.