How identity-first, agentless connectivity is replacing VPNs and jump boxes across manufacturing, energy, and critical infrastructure
Operational technology (OT) environments were built for safety and uptime, not for internet-style connectivity. Yet today’s plants, refineries, utilities, and production lines depend on remote engineers, third-party vendors, and IT/OT convergence to stay competitive. The result is a widening gap: legacy tools like VPNs and jump servers were never designed for the segmentation, protocol diversity, and zero-downtime requirements of ICS and SCADA systems.
Cyolo closes that gap with a secure connectivity platform purpose-built for OT, ICS, and cyber-physical systems (CPS). Rather than connecting users to a network, Cyolo connects verified identities directly to specific applications and assets — without agents, without network redesign, and without ever routing plant data through the vendor’s cloud.
Why It Matters
| 100 Sites
Sites rolled out in 65 days by a global manufacturer |
4.73
Companies impacted on average per compromised vendor (2022) |
80%+
Of breaches tied to weak or reused passwords |
1. Architecture: Cloud-Routed, Never Cloud-Hosted
Cyolo’s core architectural principle is decentralization. Instead of terminating connections in a vendor-operated cloud, Cyolo keeps all data, secrets, and encryption keys inside the customer’s trusted boundary — the platform is cloud-ROUTED, not cloud-HOSTED.
- Cyolo Edge / Gateway — a lightweight broker that routes traffic using Server Name Indication (SNI) headers. It never decrypts traffic and can be deployed on-premises, in a private cloud, or at the network edge.
- Identity & Access Controller (IDAC) — the “brain” of the platform. Deployed as a lightweight Docker container inside the customer’s environment, the IDAC acts as a reverse proxy, terminates TLS 1.3 connections, enforces access policy, and brokers native protocols (RDP, SSH, VNC, HTTP(S), TIA Portal, FactoryTalk, Studio 5000, and more).
- Outbound-only connections — every IDAC establishes an outbound-only TLS connection to the nearest Edge, so no inbound firewall ports need to be opened into the OT network.
- Works with air-gapped and non-routable networks — Cyolo supports overlapping IP ranges, non-routable networks, and fully air-gapped sites, with a footprint small enough to run on NUC devices or as containers on existing switches, routers, and firewalls.
The diagram below illustrates the end-to-end flow: a remote user or vendor authenticates through an identity provider, is routed (never decrypted) by the Edge, and is granted least-privilege, protocol-aware access to a specific OT asset through the IDAC — all while credentials, session data, and keys remain inside the customer’s own boundary.
Figure 1: Cyolo reference architecture for OT/ICS secure remote access

2. Core Capabilities & Features
- Agentless, browser-based access — vendors and third parties connect instantly from a browser or native client (RDP, SSH, etc.) with no software to install — removing a major source of vendor friction and shadow-IT workarounds.
- Identity-based access, not network access — policies are enforced per user, per application — never per subnet — which enables true least-privilege access even on flat OT networks.
- Legacy and EoL/EoS system support — Cyolo retrofits modern authentication (SSO, MFA) onto legacy Windows/Linux hosts and aging PLCs/HMIs that were never built to support SAML or OIDC.
- Granular, contextual policy engine — access rules can incorporate time of day, geo-location, device posture, and role, and can require supervisor approval before a session starts.
- Just-in-Time (JIT) and supervised access — time-boxed privileged access and live approval workflows reduce standing privilege on critical systems.
- Session recording & full audit trail — video/audio session recording, detailed logs, and (in newer releases) AI-assisted analysis flag risky in-session behaviour before it becomes an incident.
- Real-time session control — administrators can restrict copy-paste and file transfer, and terminate suspicious sessions instantly, mid-connection.
- Multi-tenant, decentralized management — organizations can choose centralized management or site-based local control, supporting everything from single plants to 100+ global sites.
- Broad ecosystem integration — works with any identity provider (IdP), SIEM, SOAR, and ITSM platform already in place.
3. Credential Vaulting
Shared, static, and manually rotated OT passwords remain one of the largest attack surfaces in industrial environments. Cyolo’s built-in credentials vault addresses this directly:
- Privileged credentials are stored and encrypted inside a centralized vault within the customer’s own environment — never exposed to the vendor.
- Passwords are injected directly into the session at the point of connection, so end users never see or type the underlying credential.
- Automatic credential rotation reduces the value of any single stolen or leaked password.
- Vaulting extends MFA and single sign-on (SSO) to systems that were never designed to support modern authentication, enabling password less access in as few as two clicks.
4. Authentication & MFA
Cyolo layers identity verification in front of every connection rather than relying on network location as a proxy for trust:
- Native integration with any enterprise IdP (SAML, OIDC) or use of Cyolo’s built-in local IdP where no IdP exists.
- Multi-factor authentication (MFA) enforced even for legacy and custom applications that cannot natively support it.
- Adaptive, risk- and context-based authentication that factors in device posture, location, and behavior.
- Single sign-on (SSO) across web, RDP, SSH, and industrial engineering tools for a consistent, low-friction login experience.
- Self-service capabilities — registration, password renewal, and lifecycle management — reduce IT overhead without weakening controls.
5. Key Use Cases
| Third-Party & Vendor Access
Give OEMs, integrators, and support engineers scoped, monitored access to only the assets they need — no VPN client, no flat-network exposure, full session recording. |
Remote Privileged Operations
Enable internal engineers to securely operate PLCs, HMIs, and SCADA systems from anywhere, with JIT access and supervisor approval for high-risk actions. |
| IT/OT Convergence & Alignment
Bring modern identity and access management to OT without re-architecting the control network or introducing new attack surface. |
Air-Gapped & Isolated Sites
Deploy fully on-premises with no internet dependency, preserving the air gap while still enabling controlled remote support. |
| Mergers & Acquisitions
Rapidly and securely merge or segregate access between two organizations’ industrial environments without renegotiating the network. |
Regulatory Compliance
Support audit and reporting requirements under ISA/IEC 62443, NIST 800-82, ISO 27001, and similar frameworks with built-in recording, logging, and access governance. |
6. Why Cyolo Stands Out
- True zero trust, not marketing zero trust — many “zero trust” SRA tools still decrypt and route customer traffic through vendor cloud infrastructure. Cyolo’s Edge component never decrypts traffic, and all secrets remain on-premises.
- No rip-and-replace — Cyolo layers onto existing OT infrastructure without requiring network redesign, new firewall rules, or change-management-heavy rollouts.
- Built for OT’s realities — non-routable networks, overlapping IP ranges, legacy protocols, and zero tolerance for downtime are first-class design constraints, not afterthoughts.
The Takeaway
As IT/OT convergence accelerates and remote and third-party access becomes the norm rather than the exception, industrial organizations need a way to say yes to connectivity without saying yes to risk. By combining zero-trust network access, identity provisioning, and privileged access management in a single, on-premises-first platform, Cyolo gives OT and security teams the control, visibility, and auditability that legacy VPNs and jump boxes were never built to provide without compromising the uptime and safety that industrial operations depend on.
