Every remote access session is monitored, encrypted, tracked, and restricted to the strictly authorized scope. There is no trade-off between security and ease of use.
No network access without prior strong authentication. Each technician has access only to the equipment for which they have explicit authorization. OT/IT network segmentation prevents lateral movement in the event of a compromise.
End-to-end encrypted tunnel using OpenVPN (AES-256-GCM), a proven and extensively audited protocol that traverses firewalls via TCP port 443. Mutual authentication using X.509 certificates. No open incoming ports.
A TOTP code is required for every technician's access to VPN tunnels. Compatible with Google Authenticator, Microsoft Authenticator, and Authy. Automatic lockout after N failed attempts. Secure reset by an administrator only.
Each session is logged: user ID, date/time, source IP address, devices accessed, duration, and volume. The logs are tamper-proof, exportable to CSV, and retained for at least 12 months. Meets the traceability requirements of NIS2 and IEC 62443.
Define separate network zones (PLCs, SCADA servers, sensors, cameras) and grant each technician access only to their own zone. The gateway enforces firewall rules and prevents unauthorized traffic between zones.
Architecture compliant with security levels SL1 through SL3 of the IEC 62443 standard. ANSSI recommendations for OT networks are followed. Architecture documentation is available for your RSSI audits and industry-specific certifications.
Your industry (energy, water, food, transportation) has been subject to NIS2 requirements since October 2024. The directive requires full traceability of third-party access to your OT systems. Eziwan provides the regulatory audit logs, strong 2FA authentication, and network segmentation necessary for your NIS2 compliance.
Your industrial clients are asking you to prove that your remote access is properly managed and that every access event is logged. With Eziwan, you can provide an exportable audit report for each client showing who accessed what, when, and from which IP address—without revealing other clients’ access history.
You have identified aging IPSec VPNs, untraceable TeamViewer access, and shared vendor accounts as major risks on your OT network. Eziwan replaces these solutions with a modern Zero Trust architecture, featuring access inventory, instant account revocation, and SIEM integration via syslog.
Questions asked by CISOs, CIOs, and industrial security managers.