Comparison: SaaS vs. Traditional Remote Maintenance

SaaS Remote Maintenance vs. Traditional Solutions — Comprehensive TCO and ROI Comparison

Eziwan (SaaS Zero Trust) vs. TeamViewer + IPSec VPN (traditional): Compare the 5-year TCO, MTTR, NIS2 compliance, GDPR compliance, and CMMS integration for your fleet of industrial sites.

Verdict: SaaS wins in terms of TCO, security, MTTR, and NIS2 compliance—traditional solutions are only suitable for occasional use

Comparison Table — 15 Criteria

Eziwan SaaS (Zero Trust) vs. TeamViewer + IPSec VPN (traditional)

CriterionEziwan SaaS (Zero Trust)TeamViewer / IPSec VPN
New Website LaunchAutomatic ZTP < 1 hour2–4 days (network engineer)
Security ArchitectureZero Trust, zero-inbound-portPerimeter VPN (network access)
Granular audit trailLogging by action + who + whenBasic connection logs (IP address + duration)
NIS2 ComplianceNative integration (access, logs, 2FA)Partial with offsets
CAPEX Infrastructure CostsZero (no hub/PKI)High (concentrator, PKI, FW)
5-Year TCO (10 sites)70 000-100 000€95 000-195 000€
Typical MTTR< 30 minutes (immediate access)2–8 hours (travel may be required)
First-call resolution rate65-80%30-50%
Technician MobilityWeb browser or mobile appVPN client + TeamViewer on PC required
OT Controller CompatibilityModbus RTU/TCP, SNMP, RS-485Windows only (TeamViewer)
CMMS/EAM IntegrationNative REST API (SAP PM, Maximo)Does not exist (manual access)
Two-Factor Authentication (2FA)Embedded (TOTP/FIDO2)Optional (manual configuration)
GDPR Compliance LogsEU Hosting, Article 28 of the DPAVaries depending on the configuration
Multi-site scalabilityImmediate (self-service addition)Complex (network configuration by site)
Infrastructure MaintenanceZero (managed cloud, automatic updates)Resource-intensive (servers + certificates + rules)

In-Depth Analysis

8 Dimensions for Comparing SaaS-Based and Traditional Industrial Remote Maintenance

1

Deployment: ZTP vs. Engineering Days

Deploying an Eziwan gateway at a new site takes less than an hour thanks to Zero Touch Provisioning: plug it in, power it on, and insert a SIM card. The gateway contacts the cloud platform, downloads its configuration, establishes the OpenVPN tunnel, and is up and running. A traditional IPSec VPN infrastructure requires: configuring the concentrator at headquarters, setting up firewall rules on both sides, generating PKI certificates for each site, performing round-trip connectivity tests, and creating network documentation. Across 10 sites, the Eziwan advantage translates to 2 to 4 weeks of engineering work saved, or 20,000 to 40,000 euros.

2

Security: Zero Trust vs. VPN Perimeter

The perimeter-based IPSec VPN approach provides broad network access once connected. A technician with VPN access can potentially reach all devices on the OT network, not just those for which they are authorized—this is known as lateral movement, a major attack vector in industrial cybersecurity incidents. Eziwan applies the Zero Trust principle: every access attempt is authenticated, authorized by granular policies (technician X, device Y, from 9 a.m. to 5 p.m. on business days), and logged. This is the difference between “access to the building” and “access to room X between 9 a.m. and 5 p.m. with a time and attendance log.”

3

5-Year TCO: The Complete Comparison

For 10 industrial sites, the TCO over 5 years is drastically different. Traditional IPSec VPN: CAPEX: hub €10,000 to €20,000 + firewalls €10,000 to €20,000 + PKI €5,000 + deployment engineering €30,000 to €50,000 + annual maintenance10,000 to 20,000 euros × 5 = 105,000 to 195,000 euros. Eziwan SaaS: gateway: 1,000 euros × 10 = 10,000 euros + subscription: 100 euros × 10 sites × 60 months = 60,000 euros = total TCO: 70,000 euros. Savings: 35,000 to 125,000 euros over 5 years. The larger the infrastructure, the greater the SaaS advantage.

4

NIS2 and IEC 62443 Compliance: The SaaS Advantage

NIS2 (transposed into national law as of October 2024) requires significant and critical entities to implement access management, logging, and incident response capabilities. Eziwan natively provides the necessary audit trail: every connection, every Modbus action, and every download is time-stamped and attributed to a user identified by their device. IEC 62443 (cybersecurity for automation and control systems) recommends segmentation by zones and conduits, which Eziwan implements without modifying the OT infrastructure. An NIS2 audit using an Eziwan solution can be documented in a matter of hours; with a traditional VPN, logs must be manually reconstructed.

5

MTTR and First-Call Resolution: Operational KPIs

MTTR (Mean Time to Repair) is the most tangible ROI metric for remote maintenance. With a traditional VPN solution, a technician who cannot connect remotely must travel to the site: 2 to 8 hours of travel time to a remote site + 1 hour of on-site work = an MTTR of 3 to 9 hours. With Eziwan, the connection is established in less than 5 minutes from any browser: MTTR < 30 minutes in 70% of cases. The first-call resolution rate (incidents resolved without on-site visits) increases from 30–50% with a VPN to 65–80% with Eziwan. For a network of 50 sites with 200 incidents per year, the reduction in on-site visits represents annual savings of 50,000 to 100,000 euros.

6

CMMS and EAM Integration: Moving Toward Predictive Maintenance

Eziwan integrates natively with maintenance management systems (CMMS) and asset management systems (EAM) via REST APIs and webhooks. When Eziwan detects an alarm (Modbus threshold exceeded, equipment offline, abnormal current variation), it automatically triggers a webhook that creates a work order in SAP PM, IBM Maximo, Infor EAM, or CARL Source. Historical equipment data (consumption curves, operating hour counters) enriches the CMMS to optimize preventive maintenance intervals. This integration is the first step toward predictive maintenance: Eziwan data feeds anomaly detection algorithms that anticipate failures before they occur.

7

Data, GDPR, and Ownership: The Challenges of the Cloud

SaaS-based remote maintenance raises legitimate questions about data ownership and GDPR compliance. Eziwan hosts data in Europe (EU) under a Data Processing Agreement (DPA) that complies with Article 28 of the GDPR, covering the obligations of the data processor. OT data (Modbus values, alarms, history) remains the property of the operator—Eziwan does not use it for commercial purposes. Access logs are encrypted and accessible only via the authenticated API. In the event of termination, the data can be exported in JSON/CSV format and is deleted within 30 days in accordance with the contractual terms.

8

Mobility and Technical Experience

With a traditional VPN solution, the technician must install a VPN client on their PC (often Windows only), configure personal certificates, connect to the gateway, and then use TeamViewer separately. In the field, using a smartphone or tablet, this is often impossible without additional configuration. Eziwan offers access via a web browser or native iOS/Android mobile app: the technician opens their browser, authenticates using 2FA TOTP (Google Authenticator, Authy), and gains direct access to authorized OT equipment. The reduction in incident resolution time is measurable: an average 40% decrease in MTTR observed among Eziwan customers.

Real-world use cases

4 Real-World Examples of Transformation in Industrial Remote Maintenance

Cas 1

Machine Manufacturer: After-Sales Service Without Borders

Background: A manufacturer of packaging machines with 300 machines installed at customer sites in France, Benelux, and Spain

Solution: Eziwan SaaS for Remote After-Sales Service

Before Eziwan, every service call on a remote machine required a 1- to 3-day trip (travel + hotel + service time). With Eziwan, 75% of service calls are resolved via remote maintenance in less than 2 hours from the engineering office. Average MTTR reduced from 18 hours to 2.5 hours. Annual savings on field service travel: 180,000 euros. Field service technicians access Schneider M340 PLCs via Modbus TCP from their browsers using 2FA authentication.

Cas 2

Water Authority: NIS2 and Successful Audit

Background: An intermunicipal water district classified as a “significant entity” under NIS2, with 55 pumping stations and 3 treatment plants

Solution: Eziwan SaaS + NIS2 Audit Trail

The union underwent an NIS2 audit by ANSSI in 2025. The Eziwan solution made it possible to present, within two hours, all access logs from the past 18 months: who, when, from which device, and which systems were accessed. The old IPSec VPN only retained IP connection logs, which were insufficient for the audit. NIS2 compliance was validated without any additional mitigating measures. The audit report cited Eziwan as a best practice for OT access control.

Cas 3

Automation Integrator: Accelerated Deployment

Background: An engineering firm that implements automation solutions for 20 industrial clients per year

Solution: Eziwan SaaS (ZTP for every new customer)

Before Eziwan, each deployment involved configuring a dedicated VPN for each customer (2 to 3 days of network work). With Eziwan ZTP, deploying the gateway takes 30 minutes on-site. The integrator has reduced its deployment costs by 3,500 euros per project. With 20 projects per year, the savings amount to 70,000 euros. Customers have read-only access to their own Eziwan dashboard for self-monitoring.

Cas 4

Pharmaceutical Industry: GAMP5 and Traceability

Background: Pharmaceutical manufacturing facility compliant with GAMP5 and 21 CFR Part 11 requirements for the traceability of operations

Solution: Eziwan SaaS with a signed audit trail

GAMP5 (Good Automated Manufacturing Practice) and 21 CFR Part 11 require that all changes to equipment parameters be tracked with an electronic signature. Eziwan logs every Modbus write with the user ID, a certified NTP timestamp, and the action hash for accountability. Eziwan logs can be exported in CSV format compatible with pharmaceutical audit systems. The GAMP5 validation of the Eziwan solution was completed in 3 weeks, compared to 3 months for the previous VPN.

When should you choose what?

TeamViewer/IPSec VPN if…
  • One-time, non-recurring access
  • VPN infrastructure that has already been amortized
  • Only Windows workstations to maintain
  • No NIS2 compliance required
  • Experienced VPN IT team available
  • Single site with no multiple operators
Eziwan SaaS, if…
  • Frequent remote access (regular remote maintenance)
  • OT / Modbus Equipment to Be Maintained
  • NIS2 / IEC 62443 compliance required
  • Multi-site deployments that can be rolled out quickly
  • Audit trail and logging required
  • Team without VPN/network expertise
  • CMMS/EAM integration desired

Common Mistakes

The 5 Most Costly Mistakes in Implementing Industrial Remote Maintenance

1
Believing that TeamViewer is sufficient for OT remote maintenance

TeamViewer can access Windows workstations, but not PLCs. A Siemens S7 PLC, a Schneider drive, or a Modbus meter does not have a TeamViewer agent. For true OT remote maintenance (reading/writing Modbus registers, modifying PLC parameters), only a network gateway such as Eziwan provides access to the devices via their native protocols.

2
Open a direct NAT port to a PLC for remote access

Configuring a NAT rule on the router to access a PLC directly from the Internet exposes the PLC to all automated scanners. Thousands of industrial PLCs are publicly accessible on ports such as 502 (Modbus) or 102 (Siemens S7). Remote access must always go through an outbound VPN tunnel (OpenVPN Eziwan) without opening any inbound ports.

3
Neglecting Remote Maintenance Performance KPIs

Without measuring MTTR, first-call resolution rate, and the number of site visits avoided, it is impossible to demonstrate the ROI of a remote maintenance solution to management. Define KPIs before deployment, track them for 3 months, and then present the cost-benefit analysis. Eziwan exports these metrics via its analytics API.

4
Do not include remote maintenance in the CMMS

A SaaS-based remote maintenance solution that does not integrate with the CMMS results in duplicate data entry: the technician accesses the equipment via Eziwan and then must manually create the work order in the CMMS. The Eziwan → CMMS Webhook integration automates this process and populates the equipment record with real-time service logs.

5
Sharing User Accounts Among Technicians

A VPN account shared among three technicians makes NIS2 traceability impossible: who did what, and when? NIS2 requires individual access assignments. Each technician must have their own Eziwan account with personalized permissions, their own 2FA, and access limited to the sites and equipment under their responsibility.

Results by Industry Sector

Which remote maintenance model is best for your industry?

Secteur
Water Supply and Sanitation
Recommendation: Eziwan SaaS

NIS2 requirements for operators of essential services (OES) mandate a comprehensive audit trail and granular access control. Eziwan natively meets these requirements. Without Eziwan, remote maintenance of the 40 to 200 scattered pumping stations would require dozens of on-site visits each week.

Secteur
Manufacturing Industry (Machinery Manufacturers)
Recommendation: Eziwan SaaS

Machine manufacturers maintain hundreds of machines at their end customers' sites around the world. Eziwan enables remote maintenance from the engineering department without the need for on-site visits, reducing MTTR from 4 hours to 30 minutes. The ROI is immediate for after-sales service teams.

Secteur
Oil & Gas / Oil Fields
Recommendation: Eziwan Hybrid + VPN for Critical Sites

At SEVESO-classified sites or those subject to ATEX requirements, compliance with IEC 62443 mandates high levels of security. Eziwan Zero Trust is suitable for most access scenarios. For safety-related equipment (SIS), an additional layer of validation may be required depending on the operator’s internal procedures.

Secteur
Smart Buildings / Property Managers
Recommendation: Eziwan SaaS

Managing a portfolio of 50 to 500 buildings with a small maintenance staff is the ideal scenario for Eziwan. Centralized monitoring, automatic alerts, and remote maintenance via smartphone reduce operating costs by 25 to 40 percent compared to traditional on-site inspections.

Secteur
Renewable Energy (O&M)
Recommendation: Eziwan SaaS

O&M (Operations & Maintenance) teams at wind farms and solar power plants monitor hundreds of pieces of equipment across dozens of sites. Eziwan reduces corrective maintenance by improving the early detection rate of anomalies and enabling remote configuration without the need for on-site visits.

Expert Analysis

SaaS-Based Remote Maintenance or an Internal VPN Server: Balancing Security, Cost, and Operations

Traditional remote maintenance (modem, self-hosted VPN server, direct access) works but becomes unmanageable and risky when scaled to a fleet. The SaaS model centralizes provisioning, security, and auditing. Here are the regulatory and operational criteria to help you make a decision.

Applicable Standards & References

NIS2 Directive (EU 2022/2555)

Requires access management, traceability, and incident response. A SaaS portal provides centralized auditing—which is difficult to maintain for scattered VPN access points.

IEC 62443-2-4 / 3-3

Requirements for service providers and systems: named accounts, least privilege, logging—all built into a remote maintenance platform.

ISO/IEC 27001

Information Security Management: A certified SaaS provider delivers a level of security that is rarely achievable through self-hosting by small and medium-sized businesses.

GDPR (EU 2016/679)

Data Location and Protection: Verify the SaaS provider’s hosting (EU/France) and use of third-party service providers.

TLS 1.3 + mTLS / OpenVPN

Encrypted data transmission and mutual authentication via certificates: the common building block, but orchestrated and automatically renewed in a SaaS environment.

Zero-Touch Provisioning

Mass deployment without a technician: The gateway downloads its configuration and tunnel settings on first startup—something that's impossible with a manually configured VPN server.

Recommended Architecture

Gateway Site
outbound tunnel
SaaS Platform
multi-tenant · ZTP
Access + MFA
registered accounts
OTA Update
signed firmware
Central Audit
journal + SLA

In SaaS, provisioning, updates, access revocation, and auditing are all managed through a single portal. The traditional model requires you to maintain your own VPN server, PKI, backups, and 24/7 availability.

Key Technical Parameters

CriterionSaaSTraditionnel
DeploymentZTP (minutes)Manual configuration by site
UpdatesCentralized OTAsService by Equipment Type
Cost ModelPredictable operating expensesCapex + Hidden Maintenance Costs
High AvailabilityProvided by the publisher (SLA)To be paid by the operator
Audit / ComplianceCentralized, NIS2-nativeManual reconstruction
ScalingLinear (1 to 1,000)Increasing Complexity

The true cost of the “traditional” approach is hidden: operational time, PKI, backups, on-call duty, and security liabilities—which are rarely quantified up front.

Field Data & Metrics

Machine manufacturer — equipment installed at 200 customer sites

Migration from an overloaded internal VPN server to a multi-tenant SaaS platform: ZTP provisioning, role-based access for technicians, NIS2 audit.

200
customer sites managed through a single portal
15 min
Commissioning of a new machine (ZTP)
OTA
Scheduled fleet firmware updates
100 %
Traceable and revocable access rights assigned to specific users
FAQ

Frequently Asked Questions

Switch to Zero Trust SaaS Remote Maintenance with Eziwan

Deploy in less than an hour. Access your controllers from your browser. Log every action. Compliant with NIS2 and IEC 62443. Native CMMS integration.