← Gallery

Improved remote access

Improved remote access: a vendor with an MFA token goes through a TLS-encrypted VPN gateway (Firewall A), a hardened jump host with approval workflow and session recording, and an allowlist-only Firewall B to one authorized HMI, with other OT assets unreachable and a traffic policy table (RDP or HTTPS allowed from the jump host, all else denied).

More in Vendor & Remote Access