Zero Trust · OpenVPN · IEC 62443 · 2FA

Secure OT Remote Access —Zero Trust, zero exposed ports

Give your technicians and service providers access to your OT networks without exposing any incoming ports. Zero Trust model with mandatory 2FA authentication, comprehensive audit logs, and network segmentation by device. Architecture recommended by ANSSI, IEC 62443-compliant.

0
Exposed Incoming Port
AES-256
OpenVPN Encryption
2FA
Authentication Required
100%
Accesses logged in the audit log
14-Day Free TrialRequest a demo
Zero Trust Architecture

Six layers of security for your OT networks

Every remote access session is monitored, encrypted, tracked, and restricted to the strictly authorized scope. There is no trade-off between security and ease of use.

Zero Trust Model

No network access without prior strong authentication. Each technician has access only to the equipment for which they have explicit authorization. OT/IT network segmentation prevents lateral movement in the event of a compromise.

OpenVPN/IPSec VPN with AES-256

End-to-end encrypted tunnel using OpenVPN (AES-256-GCM), a proven and extensively audited protocol that traverses firewalls via TCP port 443. Mutual authentication using X.509 certificates. No open incoming ports.

TOTP 2FA Authentication

A TOTP code is required for every technician's access to VPN tunnels. Compatible with Google Authenticator, Microsoft Authenticator, and Authy. Automatic lockout after N failed attempts. Secure reset by an administrator only.

Complete audit trail

Each session is logged: user ID, date/time, source IP address, devices accessed, duration, and volume. The logs are tamper-proof, exportable to CSV, and retained for at least 12 months. Meets the traceability requirements of NIS2 and IEC 62443.

Fine-grained network segmentation

Define separate network zones (PLCs, SCADA servers, sensors, cameras) and grant each technician access only to their own zone. The gateway enforces firewall rules and prevents unauthorized traffic between zones.

IEC 62443 Compliance

Architecture compliant with security levels SL1 through SL3 of the IEC 62443 standard. ANSSI recommendations for OT networks are followed. Architecture documentation is available for your RSSI audits and industry-specific certifications.

Secure Deployment

Deploy Zero Trust OT in 4 Steps

A robust architecture that can be implemented without a large-scale IT project and without modifying your existing infrastructure.

01

Deploy the gateway (zero inbound)

Install the Eziwan gateway in the electrical cabinet at your OT site. It establishes an outbound connection to the Eziwan cloud—no inbound ports are open on your network. Your OT network remains invisible from the Internet.

02

Create 2FA accounts for technicians

Create an account in the portal for each technician or service provider. Assign access rights on a per-device basis. The user sets up their TOTP 2FA. Instant deactivation of an account in the event of departure or an incident.

03

Set Permissions by Device

Fine-tune who can access what: PLC A for technician X, the SCADA server for contractor Y, and the cameras for operator Z. Each scope is isolated—a compromised account grants access only to its authorized scope.

04

Enable the audit log

The audit log is enabled by default and records all sessions. Configure automatic alerts (logins outside scheduled hours, unknown IP addresses, login attempts on unauthorized devices). Export the logs to your SIEM.

OT Security Use Cases

Who needs Zero Trust for their OT access?

🏭

Industrial under NIS2

Your industry (energy, water, food, transportation) has been subject to NIS2 requirements since October 2024. The directive requires full traceability of third-party access to your OT systems. Eziwan provides the regulatory audit logs, strong 2FA authentication, and network segmentation necessary for your NIS2 compliance.

NIS2 compliance with full traceability of third-party access
🔧

Maintenance Provider

Your industrial clients are asking you to prove that your remote access is properly managed and that every access event is logged. With Eziwan, you can provide an exportable audit report for each client showing who accessed what, when, and from which IP address—without revealing other clients’ access history.

Exportable audit report by client for each period
💻

CIO OT / CISO

You have identified aging IPSec VPNs, untraceable TeamViewer access, and shared vendor accounts as major risks on your OT network. Eziwan replaces these solutions with a modern Zero Trust architecture, featuring access inventory, instant account revocation, and SIEM integration via syslog.

Replacing Legacy VPNs and TeamViewer with Zero Trust
OT Cybersecurity FAQ

Frequently Asked Questions About OT Access Security

Questions asked by CISOs, CIOs, and industrial security managers.

Secure Your OT Access with Zero Trust Today

Replace your legacy VPNs and untraceable access methods with an enterprise-grade Zero Trust architecture. Deployable in less than a day, without any changes to your existing network.

See also: Industrial Remote Access · Industrial VPN · Industrial 4G Router