Secure Remote Access
for Critical Infrastructure
As cyber threats targeting industrial control systems (ICS/OT) grow in frequency and sophistication, traditional VPN and IT-centric tools fall short of OT's unique demands. Protect your OT networks with solutions built on Zero Trust architecture and IEC 62443 standards.
Critical Risks in OT Security
Traditional IT solutions cannot address the unique requirements of OT/ICS environments.
Expanding Attack Surface
As industrial systems become more connected, cyberattacks on OT infrastructure grow more frequent and sophisticated.
Inadequacy of IT-Centric Tools
VPNs, VDIs, jump servers, and PAM solutions were designed for IT — they don't support OT-specific protocols or security requirements.
Rising Compliance Demands
NIS2, IEC 62443, and the Cyber Resilience Act (CRA) mandate rigorous security controls for critical operations and infrastructure.
High MTTR Costs
Unplanned downtime and slow mean-time-to-repair (MTTR) translate directly into production losses and customer dissatisfaction.
Pillars of Our Cybersecurity Strategy
Zero Trust Model
Every connection is identity-verified before access is granted. Robust focus on authentication and access control minimizes the risk of unauthorized entry.
Defense in Depth
Overlapping layers of protection — from MFA and data encryption to network segmentation and audit logging — secure your assets at every level.
Purdue Model (PERA)
Seamlessly integrates into your existing OT infrastructure. Define access boundaries and restrict communication down to each device's IP and port.
How It Works
A three-component architecture spanning the field, the cloud, and the remote engineer's device.
Edge Gateway
Installed on-site. Direct connection to PLC, HMI, SCADA, RTU. All traffic is outbound-only — no open inbound ports.
Access Management Server
Cloud or on-prem. Centralized identity management, audit logs, session recordings, and SSO integration.
Remote Access Portal
Browser-based or lightweight client. Supports RDP, VNC, SSH, Modbus, Profinet, Ethernet/IP, and more.
Outbound-Only Traffic
The gateway initiates all connections from inside the OT network outward. No inbound ports required — fully compatible with corporate firewall policies.
TLS 1.2 + AES-256 Encryption
x.509 certificate-based authentication guarantees data confidentiality, integrity, and authenticity across every session.
Trust-on-First-Use (ToFU)
The gateway locks to the server's certificate on first connection. Subsequent connections are verified against it, preventing MitM and redirect attacks.
Direct & Clientless Access
Native OT protocol support (Modbus, Profinet, EtherCAT, Ethernet/IP) alongside browser-based RDP, VNC, SSH, and Telnet.
Granular Access Control
Restrict connections to specific device IP addresses and ports. Hierarchy-based roles enforce the least privilege principle at every level.
MFA + SSO (Azure AD / Okta)
SMS-based multi-factor authentication and Single Sign-On integration with enterprise identity providers.
Real-Time Monitoring & Audit Logs
View active sessions live, log every user action automatically, and retain session recordings for compliance and incident response.
Vulnerability Hub
Proactively identify gateways running outdated firmware or approaching end-of-life before they become a security liability.
International Certifications
Security compliance verified through independent third-party audits — not self-assessed.
Secure Product Development Lifecycle
Certified for secure-by-design methodology, secure implementation, patch management, and end-of-life processes throughout the full product lifecycle.
System Security Requirements
Compliant with all seven foundational requirements: IAC, UC, SI, DC, RDF, TRE, and RA — at both component and system level.
Organisational Security Controls
Controls assessed and documented in an independent third-party ISAE 3402 report. Consistent, repeatable, and fully auditable security practices.
Regulatory Compliance Ready
Built-in features supporting the EU NIS2 Directive, Cyber Resilience Act (CRA), and NIST 2.0 — with exportable audit logs ready for inspection.
CVE Numbering Authority
Officially recognised by CISA as a CVE Numbering Authority (CNA) — one of the few organisations globally authorised to identify and name cybersecurity vulnerabilities.
Information Security Management
Features and audit infrastructure designed to support customers' own ISO 27001 compliance programmes and information security management systems.
Why IT Teams Trust This Solution
Built for OT. Approved by IT. Secure, auditable, and fully integrable with your existing IT infrastructure.
❌ Traditional Approach
✓ Secure OT Remote Access
Central Control
Manage all remote access operations across all sites and vendors from a single pane of glass.
Security by Design
Zero Trust architecture, outbound-only traffic, MFA, and no open inbound ports — secure from day one.
Audit Ready
Full session tracking, role-based permissions, and exportable audit logs for regulatory compliance.
IT Integration
Native integration with Entra ID, Okta, Splunk, Syslog, ticketing systems, and more via API.
Legacy OT Support
Natively supports PLC, HMI, SCADA, DCS, and RTU equipment — regardless of age or brand.
Fast Deployment
No changes to existing infrastructure required. Up and running immediately after installation.
Secure Your OT Network
Talk to a CZ Mobility expert about secure remote access for your industrial facilities.
Speak to an Expert All Solutions