Industrial operations depend on secure remote connectivity for diagnostics, updates, and third-party support. Yet legacy hardware, proprietary protocols, and safety-critical systems make Operational Technology (OT) environments and Industrial Control Systems (ICS) especially vulnerable. Secure Remote Access (SRA) platforms address these risks with policy-enforced, monitored connections that enable resilience, regulatory compliance, and safer collaboration across energy, manufacturing, transportation, and utilities.
Don’t miss the opportunity to join Senior Analyst Warwick Ashford for an informative webinar, where he will present an overview of the KuppingerCole Leadership Compass on Secure Remote Access (SRA) for OT and ICS. Warwick will discuss the market drivers, key findings, and overall results. He will be joined by Bill Moore, Chief Executive Officer & Founder of XONA Systems, who will contribute a practical perspective, highlighting how XONA’s solutions perform in real-world industrial environments to support remote access operations. Together, they will provide a comprehensive and insightful view of this rapidly evolving market—an event not to be missed by professionals seeking to stay informed about the latest developments in OT and ICS security.
Hello and welcome to this webinar on Securing Remote Access in IoT and ICS Beyond VPNs. I'm Warwick Ashford, author of the inaugural KuppingerCole Leadership Compass Report on SRA for OT and ICS environments, and joining me today is Bill Moore, the founder and CEO of XONA Systems, one of the vendors covered in the report. Hello and welcome, Bill.
Hi, thanks Warwick for the invitation and looking forward to talking a little bit later. Well, great to have you here and I'm sure you'll agree with me that this is an important, dynamic and innovative market. Absolutely.
Well, that's great. I mean, we'll have lots to talk about and I look forward to our discussion later so you can sit tight and sit back and have a good listen. But before we go any further, I'd just like to run through some of the housekeeping notes for the agenda for today.
So, as you can see, you are muted centrally, so there is no need to worry about the sound controls. We have a couple of polls for you to participate in, so we'll discuss the results of those later. There will also be a Q&A session, which is your chance to put your questions to me and Bill. We'd like to make this as interactive as possible, so please enter your questions at any time using the question tab in the Livestorm control panel.
And don't worry about taking detailed notes because we are recording the webinar and that recording, as well as the slide will be made available to you for download in a day or two. So now to run through the agenda.
First, I'll give you an overview of the Leadership Compass report. We'll have a look at the key drivers, the key findings of the report and the overall results.
Then, as already mentioned, I'll be joined by Bill Moore from Zona Systems to get his perspective on the market. And finally, we'll have a look at the poll results and run through your questions in the Q&A section of this webinar.
Remember, you don't have to wait till the end. You can enter your questions at any time by going to the question tab in the control panel in the bottom right-hand corner. And just before I begin, I have a question for you. Here is your first poll question. Which factor is your organization most concerned about when enabling remote access to OTICS systems?
One, regulatory compliance. Two, third-party access.
Three, legacy system exposure. And four, operational downtime. You can record your answer by going to the polls tab, also in the bottom right-hand corner of the control panel. And only by participating will you be able to see the results. So you can do that at any time during the webinar. But now let's dive into the first section of this webinar. And the first observation that I'd like to make is that secure remote connectivity isn't a nice-to-have anymore. It's become essential for industrial operations.
As IT and OT systems come together, as regulations tighten, and as the demand for real-time diagnostics and support keeps growing, secure remote access has become increasingly important. Whether it's in energy, manufacturing, transportation, water, or other critical services, these environments depend on it to keep systems available, safe, and running smoothly. Today we're going to explore why SRA is so important in the world of operational technology and industrial control systems.
We'll also look at how vendors are evolving, how some are leading the way with new capabilities, and how others are catching up, as secure access becomes a core requirement for industrial resilience. So whether you are responsible for cybersecurity strategy, compliance, or OT operations, this webinar will help you to understand what's happening in the SRA market and where it's headed next. Let's start with the basics. Secure remote access in industrial environments is all about enabling connectivity without compromising safety or reliability.
In traditional OT systems, networks were often isolated, what we sometimes call air-gapped, but that's changing fast. The convergence of IT and OT systems, the rise of digital transformation, and the need for rapid diagnostics and remote support have made connectivity essential, because remote access supports digital transformation, and it enables things like rapid diagnostics and instant technical support.
However, that same connectivity opens the door to new risks. Many of the systems, like physical processes, like PLCs, RTUs, and SCADA workstations, were never designed to be exposed to external networks. They often lack built-in security controls, such as encryption or authentication, and that's where purpose-built SRA solutions come in. They act as a secure gateway for access to these environments. Instead of letting users connect freely as a VPN might, SRA solutions enforce policies about who can connect, when, and to what, all while recording and monitoring every action.
Traditional remote access models no longer work in OT and ICS environments, because they were designed for connectivity, not control. The key is providing access that is controlled and monitored. Whether it's an engineer updating firmware, a vendor diagnosing an issue, or a contractor providing emergency support, every session is authenticated, time-limited, and tightly restricted. So what's driving this market forward? From my perspective, there are three big forces at play.
First, IT-OT convergence. As organizations connect their operational systems to enterprise IT networks, the attack surface grows. Data sharing between plants and corporate systems helps efficiency, sure, but it also creates new pathways of cyber threats. So SRA is the control mechanism that allows integration without exposing the plant floor to risk. Second is regulatory pressure.
Now, regulatory frameworks are getting tougher across the board. Standards such as IEC 62443, NERC SIP, and NIST 2 now explicitly require secure, auditable remote access with strong authentication, least privilege control, and detailed logging.
Now, traditional VPNs and remote desktop tools simply don't provide the level of control or visibility that regulators expect, and that's pushing organization towards purpose-built SRA platforms, which enable them to move away from static VPN models to dynamic access controls. And the third force is operational continuity and efficiency. The need for real-time troubleshooting, remote diagnostics, and vendor support has never been greater. Field service can be expensive, and it can be slow, especially when plants are in remote locations.
SRA enables experts to connect securely in minutes rather than hours, reducing downtime and keeping critical processes running safely. And beyond these main drivers, we're also seeing strong business cases around cost savings, faster response times, and improved collaboration with partners.
In short, secure remote access isn't just a cybersecurity investment, it's an operational enabler. Next, we look at the key findings of the Leadership Compass Report, but before that, here is your second poll question. What remote access approach is most common in your environment today?
One, VPN or generic remote desktop, two, jump hosts and session gateways, three, a purpose-built SRA platform, and four, hardware-enforced access controls. Please enter your answer as we move on to the key findings of the report, starting with the fact that SRA has evolved from a niche capability into a foundational element of industrial cybersecurity. As I said earlier, it's no longer something that's nice to have for a few maintenance teams.
It's a core requirement across the entire OT landscape, especially in the light of the fact that cyber attackers are now increasingly targeting OT environments directly. Some other findings include the fact that the SRA market is maturing rapidly. Vendors are expanding beyond simple connectivity to deliver full-featured platforms that include things like protocol isolation, behavioral analytics, and compliance-ready monitoring.
Leading vendors are embedding zero-trust principles throughout their solutions to verify identity for every connection and enforce time-bound, auditable, and least-privileged access. This shift from static VPNs to dynamic policy-based access is one of the defining trends of the market, I think. This approach is aimed at strengthening both security and operational continuity. Leading SRA solutions typically integrate with SIEM and SOAR, as well as credential vaults, allowing centralized visibility and response, and that's critical for organizations that want a unified IT-OT security operation.
The focus on legacy system compatibility is also important. Many industrial systems are decades old. Leading SRA platforms, therefore, can securely wrap insecure protocols, creating encrypted tunnels and proxy gateways to protect legacy assets that can't be patched, or not easily anyway. And another important area of focus is high availability and failover, because downtime in OT environments can be incredibly costly. Vendors are prioritizing resilience. High availability designs and session persistence during failover have become key differentiators.
And when it comes to innovation, we are broadly seeing this driven by automation, interoperability, and compliance. We're seeing advanced features like just-in-time access and just-enough access, machine-to-machine and non-human access control, AI-based anomaly detection, context-aware authentication, and automated incident response through SOAR integration. These go beyond compliance. They improve operational visibility and security posture.
And with an eye on the future, some SRA solutions are already introducing quantum-safe cryptography and quantum-resistant tunneling, which is strategically important for the long-term in security. Overall, this market is moving towards comprehensive platforms that blend secure access, monitoring, compliance, and resilience, all tailored to industrial realities.
Now let's look at how vendors scored in the Leadership Compass report based on briefings with each of the vendors and a very comprehensive questionnaire that looked at all the key aspects of SRA solutions, including security, functionality, deployment, interoperability, usability, innovativeness, market position, financial strength, and ecosystem. In the report, there are also spider charts rating each of the vendors on authentication and authorization, end-to-end monitoring, legacy OT support, threat detection and response, high availability and failover, and compliance.
So please have a look at the report to see how they scored. In the overall leadership graph, Palo Alto Networks is closely followed by Cron Technologies, SSH Communications, Security, Fudo Security, Arnis, and of course Zona Systems. These companies lead because they combine strong product features, market presence, and innovation. They deliver mature solutions that balance usability, control, and compliance. Challenges such as while existentia, clarity, and kosher also offer solid functionality but are still building market share or deepening OT-specific capabilities.
What this all tells us is that the SRA market for OT and ICS is vibrant, competitive, and rapidly innovating. We're seeing both established cybersecurity vendors and OT native specialists converge toward the same goal, which is delivering secure, compliant, and resilient remote access that works across legacy and modern systems alike. Remember that the vendors that have the highest scores are not necessarily the most appropriate for your use cases, so again please read the report in detail to identify the vendors that offer the products that best meet your needs.
Next we look at the product leadership graph. The tight grouping indicates a close alignment in feature depth, usability, integration breadth, and deployment flexibility for SRA in OT and ICS environments. All these leaders deliver solutions that address the full range of core SRA requirements including granular access control, session monitoring, and secure connectivity for both modern and legacy systems. Next we look at the leaders in the innovation leadership graph. The competition among these vendors is exceptionally tight and there is very little separating their innovation scores.
These leaders distinguish themselves through advancements such as adaptive zero trust architectures for OT, integration of advanced behavioral analytics, AI-driven anomaly detection, and expanded interoperability with legacy and proprietary protocols. And finally we look at the leaders in the market leadership graph. These vendors have achieved strong market positions through a combination of broad customer adoption, large-scale deployments, global reach, and mature partner ecosystems.
Their solutions are capable of meeting the needs of organizations across a wide range of OT and ICS use cases, supporting diverse industrial environments, and enabling secure connections at scale. In summary let's look at a checklist of features that distinguish a mature solution. So first is strong authentication and identity binding which with features such as MFA, pass keys, and device trust. Next is attribute-based and policy-based access controls to support dynamic decision making based on risk, user attributes, time, context, and device attributes.
Just in time and just enough access models which help to shrink exposure windows. Session mediation and protocol isolation. An SRA solution should proxy or mediate individual protocols such as SSH, RDP, OPC, UA, Modbus, and so on to filter, sanitize, and block certain commands preventing misuse or the classic collateral movement. Session monitoring, recording, live shadowing, and anomaly detection. An SRA solution should support alerting and remote session termination.
An SRA solution must also natively understand or be able to encapsulate legacy and propriety protocols without requiring modifications to the target device. It can achieve this through gateways or protocol wrappers that securely tunnel or otherwise insecure traffic ensuring that compatibility and protection across mixed environments. Next is high availability, clustering, failover, and session re-establishment. The architecture needs redundancy, failover, session persistence, or fast re-authentication and separation of planes so management stays alive even under degraded networks.
API integration with identity system vaults and logging infrastructure is another point that's very important because an SRA solution must export logs, alerts, and metrics through things like syslog, cf, rest APIs, or native connectors into seam, saw, and identity governance systems. That ensures that SRA isn't an island but part of a broader security workflow. Scalability to multiple sites with centralized governance. This is important and SRAs should support governance centrally across many plants or sites yet allow local policy customization and autonomous connectivity where needed.
Configuration propagation, site-aware policies, and consistency checks are key. And finally, auditability and compliance support. This includes reporting and evidence trails. A solution missing any one of these is liable to fail in a demanding industrial deployment. Now one of the vendors that appears among the leaders in all the graphs is Zona Systems and we'll be talking to its founder and CEO shortly right after your third and final poll question which is, what capability do you see as the most critical in an SRA solution?
One, granular policy-based access control. Two, session monitoring and recording.
Three, high availability and failover support. And four, integration with identity and security tools. Please record your answer now. In the slide deck I have included some links to the leadership compass and the bias compass on SRA for OT and ICS as well as other related search research so that you can have a look at in your own time. I would also like to flag up Kuping et al's EIC conference in May next year where we and learn about all matters to do with identity and cloud. The agenda for that is coming together quite nicely so I hope to see you there.
And today we're discussing one of Kuping et al's many research topics and I've just mentioned our EIC event in May but we also provide advisory services to support IT professionals in decision-making processes. But now as promised we turn our specialist access security provider Zone Assistance and I'm joined by the founder and CEO Bill Moore. Welcome. Thanks Warwick for the invitation and looking forward to our conversation. Perhaps you could start by telling us a little bit about yourself and the company. Yeah sure. Bill Moore, I'm founder and CEO of Zone Assistance.
We were founded in 2017 really around solving the problem with OT access. So we were born and developed our product and our earliest customers had this challenge around secure remote access to their OT equipment and the existing tools weren't doing it so that's where it all started. So you have customers in around over 40 countries and they're already using your Zona platform. So you mentioned some of the factors already but from your perspective what's driving this global adoption?
Yeah well there's really a universal challenge across ICS systems really in every industry whether it's energy, manufacturing, transportation.
We have customers you know as a fairly small company you know having customers in every geo and really every industrial market segment is really because there is an issue here where there either has not been allowed secure remote access and there's been a drive to allow that or there's been a challenge around having legacy jump servers and VPNs that aren't meeting you know the regulatory pressures and things like that or the security that they need to control those assets.
Okay so that kind of more or less thankfully aligns with what I was saying at the end and again from your perspective what makes SRA for OT and ICS kind of different to become IT environments? Yeah I think you know if you really look at IT everything's around the CIA triad or confidentiality, integrity, availability.
It's kind of flipped upside down you had that safety at the top for OT and it's really the you know the intermittent nature of how people connect to OT systems and needing controlled access as you mentioned before by attributes like time because you know you want to make sure that who's connecting to those systems are doing so in a controlled manner and so having very strict controls on how people connect to them is really important right. So it's really a tight scoping for monitoring and controlling access to the environments that's different than IT right.
And one of the things that I particularly liked about your platform is that it's agentless and browser-based. How does this simplify secure access for operators and contractors in the field? Yeah so one of the early problems that we recognized was that there seemed to be an access mismatch or access methodology mismatch between third-party vendors, contractors and so forth in the company and how they did. So you have different client-based VPNs or maybe VDI and VPNs and that created a lot of friction.
So what we do having it all web browser-based without agents or clients is we make it much more frictionless and without sacrificing any of the control and in fact we offer more control through this clientless approach in the way that we connect people from the outside to directly to those assets through a controlled manner. Yeah I think that's definitely a strong point for your approach and then as I said that's what I particularly like. And I also mentioned earlier a lot around protocol isolation. I mean this is quite a strong differentiator.
Can you explain how it enhances both security and usability compared with the more traditional approaches? Yeah so we think about when we say protocol isolation basically we're not allowing a direct connection from the user's endpoint directly to that critical asset, that OT asset.
We're essentially becoming a broker in the middle to connect to those and then we render images back to the browser at the remote side so that there's no, we're essentially reducing the attack surface and not in the case of VPNs and tools like that, you're essentially extending that attack surface out to that remote endpoint. So we limit the attack surface and then by converting this into images instead of dragging the protocol like RDP or VNC all the way out to the endpoint, it's actually more efficient.
So we can operate under satellite, lower cellular, lower bandwidth kind of operations because it's really more just we're dealing with the image convert over that remote link as opposed to having the protocol. Many times OT we don't have the high bandwidth operations that you typically do in IT networks. So there's OT industrial control systems everywhere, oil fields and mines, so you need to handle that in a different way.
I was quite surprised when I started researching for this report and how many operational technology systems there are, how many industrial control systems there are out there and until now they've kind of largely been unmanaged, especially not connecting outwards. Deployment speed is also a recurring sort of pain point. How are you able to get most gateways operational? I think your claim is under 30 minutes.
Yeah, so obviously if you have a hundred assets and things that you need to connect to, it might take a little longer than that, but if you want to get up your first few assets, critical assets for your third party OEM to connect to, yeah, I mean it can be done in less than 30 minutes. It's really about making sure that you have the network configured to allow the encryption of web traffic back to the web browser. So 443 out to the remote endpoint and so it's just having that IP address set for the outside connectivity.
We call the untrusted side and then the IP for whatever your critical assets are on. So once you set up that, you just set up a connection and you just assign the user to that connection and you're off and running. So it's a two or three click process for the user. Our whole premise is we want to make this simple for the technician and the user to get access to the asset when they need to.
Yeah, I definitely found that looking across this market that's a trend where some of the vendors like yourselves are trying to make it easy for the people in the field and I think that's a really good approach because it must be really difficult to have to do that and so I think the easier you can make it the better and I think security, if it's easy but secure, that's good. But if it's difficult, people will find go-arounds, right? But many OT systems still use legacy protocols and I kind of mentioned the importance of being able to kind of straddle the legacy and modern systems.
So how does Zone enable secure access without requiring changes to those systems? Because as you said, there's limited bandwidth and a lot of these systems are, as I said, decades old but don't like to be touched. So how do you do that?
Yeah, so within the connection profiles, if they're using sort of the display protocols like RDP, VNC, SSH, WebGL, things like that, so we can set up that connection and hard code those credentials and become sort of the hard multi-factor authentication layer, you know, either within our product natively, we can provide MFA or we can do that in conjunction with your upstream IDP, right, if you have Bing or Microsoft, what have you, and connect to that.
If it's a proprietary protocol that doesn't, it's not a typical display protocol like a Modbus TCP, DMP3, things like that, we have the ability to do what we call XConnect. So we treat it as if it's a connection directly to that but we wrap that in a TLS encrypted tunnel. We can still enforce attribute controls and policies around time and what role they have to be able to use that connection. We can also introduce things like virtual weight lobby because, you know, as I mentioned before, safety is a big, you know, part of this.
You don't want somebody turning something on in the world that should be off and things like that. So you may want to have a human in the loop in the control center to allow that.
Again, that's a different differentiator in IT that nobody thinks about because, you know, there's not people's lives at stake, you know, when you're dealing with connecting to systems and IT, right? So OT just is just a different way of, you know, yeah, you just have to treat OT differently.
Yeah, and one of the things that I highlighted earlier was the, you know, need to kind of record all the sessions and to kind of log everything because it's really important to have that audit trail and know, you know, who's doing what. So in your solution, session recording and logging our native features, how do customers use these for compliance and incident response?
Yeah, so, yeah, so the session recording, you know, as you mentioned before, I think, you know, it's part and parcel to regulations now with NIS2 and NIST and NERC SIP and all the different regulations around that. What we see is kind of not only from the cybersecurity perspective of having a forensic analysis, so we, you know, we pride ourselves on not only providing our core capabilities in this identity-based control, but we also can integrate with other solutions, you know, SIMs and so forth.
So you can take the forensic knowledge about behavior analysis from having a user access recording of every mouseover and every keystroke that's done on that system and replay that if you need to, if there's an incident that happens, you can kind of go and find the exact time, the exact session, and exactly what the user touched. So you can determine if there's, you know, if there was malicious behavior there. So that's a big part. But the other part that sometimes doesn't get talked about as much is the ability to do things like training.
So there's just a paucity of, you know, qualified senior technical personnel that can do the work in these systems, and the age of the average SCADA supervisor, SCADA control systems engineer is not getting younger. So, you know, getting junior techs up to speed faster is great by having the ability to have them view recordings from senior tech and so forth of what they did on the systems and label those. And so you can go back and use those for training purposes.
So, yeah, that sounds really good. And adaptive context of where access is becoming critical, because it's really, you can't have step-up access all the time. You've got to have sort of something that's usable, right, since the age-old balance between usability and security. But how do you plan to address the current lack of risk-adaptive controls in the solution?
Yeah, so again, you know, we have an open API. We connect to various tools. So on the identity side, you know, a lot of those types of context-aware tools that are, we have a SAML connector for, as I mentioned before, Okta and Microsoft Entrez ID and things like that. And so that's sort of more on the IT side.
So we can, whether it's a third party or an employee, they can have mechanisms to watch them kind of come through and apply, you know, the context on that side, on the IT, even before they come over to the OT. We also integrate with OT asset visibility tools like Dragos and Forescout and Nozomi and so forth. So we can get visibility into those assets. And we're going to be building more and more upon, you know, being able to make, you know, decisions and what we call active defense based on that, so. That sounds good.
Threat detection in your system currently relies on sort of third-party integrations, and I think you've mentioned some of those already. Do you see Zona developing more native detection and automated response in the future, or are you still planning to continue this reliance on third-party integrations?
Well, it's a little bit of both, right? I think we'll continue relying on the third-party integrations to provide us, you know, the visibility and provide us, you know, vulnerabilities that they're seeing.
You know, centrally to what we do is really, you know, we're an identity-based security, you know, governance and control platform to these critical assets. So we're going to be putting in what we call an active defense engine into our product. And so that will look more at sort of being able to look at anomalies and understand how users are interacting with these critical assets. So we understand, you know, if there is a risk, we can score that risk either natively or in conjunction with some of these visibility tools.
You know, we can do automated session termination, for instance, and so forth. So that active defense engine, you know, is kind of in development now.
I mean, we have sort of phase one completed. We're going to be adding an insights product next year that will provide more of kind of the overall ability to compliance reporting and sort of visibility into the overall picture of what's happening in terms of the user interactions with critical systems.
Yeah, I think, as I said earlier, I think that's one of the things that I really like about this market is that, you know, most of the big players or most of the good players are continually innovating, continually extending, and there seems to be just kind of a lot of activity in this area. That's why I listed just those key things for people to look out for when considering these systems, but to look at each of the individual vendors to see what they're doing and how they are innovating. I'm just having a look at the questions tab.
I'm not seeing many questions yet, so please, guys, don't forget that you can at any time enter your questions in the question tab. We'll be getting to those shortly, but this is a great opportunity for you to ask Bill about systems or about the industry in general, if there are any particular issues that you are facing that you think that you'd like to get some input on. This is the kind of thing to try and get the most out of this webinar time is to kind of get your interactive responses and so on to kind of see what you can find out and learn.
For Bill, I'd like to say, you know, with enterprises shifting to OWLF and OIDC, how is Zona preparing to support these identity standards more directly? Yeah, I think, you know, our philosophy really, as I mentioned before, is we want to be, you know, the identity security company for OT, right, and controlled access to OT.
So, we've already done work outside of our sort of our native authentication that we have our own, you know, this could be in a lot of cases. So, we have OT only customers, you know, that don't really touch IT. You can think of them as completely air gap.
So, we have customers that use us for, you know, that identity and we take that, you know, obviously, we do a very secure way and use, you know, FIPS validated protocols and things like that for the way that we are, you know, encryption for the way we do that. We have the ability to connect today with SAML, as I mentioned before, to upstream identity providers.
We also, for our DoD customers, have implemented certificate-based authentication, such as CACDIV, which is fairly new. And, you know, we see that as obviously important in public sector.
Yeah, so OAuth and OIDC, we're watching that very closely, you know, and we're thinking it probably more in terms of the upstream providers, but we will also be able to recognize as those, you know, mature and move forward, we'll certainly be integrating those standards into our product. Yep, for sure.
So, from my perspective, anyway, you know, the organizations that do have a spread across IT and OT, it would make sense to have them kind of in a unified platform so that they, you know, because my impression is that in many organizations, they have OT over here and IT over there and, you know, the one side is not terribly aware of what the other side is doing and that there's kind of not a good level of cross-pollination between the two. So, you know, do you agree that this kind of unified approach is probably the better way to go?
Yeah, I mean, you know, so we've been doing this pretty early in the game, right, since 2017, 2018, and again, we built the platform initially for the problem set in OT only, right, because there was an OT-specific problem set. But as we've seen the evolution in many industries of IoT, IIoT, and these types of devices and the digital transformations that are really going on, really in every industry, there's this need now as, you know, for instance, in manufacturing, you would have sort of hard-coded PLCs, now you have little computers running soft PLCs, PLC software, things like that.
And it's, you know, so these assets now need to be protected because, you know, historically, they never had IP addresses, but now they do, right? So, they can, in IP, if they want to, if they can connect to the greater world and the internet, they will, right?
So, you know, we really think hard about how we address that problem set and connecting to those, you know, as the maturity of OT moves sort of into sort of this blur, I guess, if you will, between IT and OT, you know, we want to make sure that we're sitting there as the safeguard between and access between how people are connecting, you know, in their IT network to OT. And we continue to iterate with our customers.
And, you know, we're, you know, I say, you know, from we built the product with our customers, and now we're, we're scaling with a lot of our customers, you know, to address more complex problems and integrations. So, yeah, I think that's a great approach when vendors can develop products in collaboration with their customers, because I think we've often seen in the past, where, you know, vendors can present, not particularly in this market, but in other markets presented solutions to problems that people didn't have.
Yeah, it's like, it's like, well, we can do all this stuff. We don't need you to do that. But we need you to do X, Y, and Z. I think I'm going to take a short break now to have a look at the poll questions. And we can we can have a discussion around those. So the first question I asked was, what capability do you see as the most critical in an SRA solution? And the biggest vote was for policy-based access control. Does that kind of align with what you're seeing out there in the real world?
Yeah, I think there, you know, the industry has matured. And when I say the industry, I'm saying, you know, multiple industries here, manufacturing, energy, oil and gas, I think there's a growing recognition very rapidly now that that VPNs and broad network authentication type access is not going to cut it, right, that there needs to be. And this has happened on the IT side of the world, you know, with microsegmentation and things like that. And I think there's also a movement to understand that, you know, really, if we can segment by identity, you know, that's even better, right?
That's kind of like, you know, firewall 4.0, right? So, you know, we want to be right there and sort of being able to, you know, broker the access and do it in a controlled manner without exposing the network and without, you know, increasing the attack surface.
In fact, you know, reducing the attack surface, right, through granular controls. Yeah, I mean, you mentioned that earlier, and I think there's this whole approach of reducing the attack surface is a great approach. And some of the kind of hardware-based solutions in the space are also going along that, you know, let's just make the attack surface really, really small.
So, in response to that question, there was kind of 25-25 split on high availability and integration. Interestingly, there was zero percentage voted for session recording and monitoring, which is quite interesting, because I would have thought that some organizations would really want that, and we've already discussed that.
So, yeah, that was quite interesting. Well, you know, what's interesting about that is a lot of times when we show that, folks didn't even realize it was possible, right?
Oh, wow, you can do a complete, I mean, people think about session logging and things like that, but I think particularly in the OT space, you know, there's, you know, we're really moving, kind of leaping here in some ways, IT, because there's things that you can do in OT that are challenging. Like, in terms of session recording, I always say, you know, who's going to watch an eight-hour, you know, video of somebody in an Excel spreadsheet?
You know, that's the IT world. In OT, you know, maybe not eight hours a day, it may be eight minutes a month, you know, and so you can collect all these recordings in an effective and efficient way in OT, so, yeah.
Okay, and then the next poll question was, what remote access approach is most common in your environment today? We had an equal split between VPN and purpose-built SRA solutions, so I quite like that, that there is kind of, it seems to be a movement towards purpose- one.
Yeah, well, I mean, it's, I think the good news is it's moving in that direction, right? Yeah.
Obviously, we want to see it move faster, you know, selfishly, but yeah, I think that recognition is happening. I mean, we, there's another piece of this, too, so we've had customers that, you know, they've allowed their third party, their OEMs, and given them VPN clients, and it's gotten out of control, and so they have these sort of, you know, VPNs from dozens of different OEMs connecting into their organization, and it's, you know, they've, now they have to say, oh, how do we get this under, how do we, we've literally expanded the attack surface in a very meaningful way, negatively, right?
So, how do we get that reduced, and so, you know, and it's also who owns the risk, you know, they own the assets, even though maybe the OEM built everything on the manufacturing floor, in terms of the control systems, you know, they built it for somebody that owns those assets, and they have to also own the risk now, and so there's a maturity level there that I think we're seeing moving in that direction that, hey, we have to get control over this, and those OEMs have to come through us, you know, and we have to implement, you know, granular controls and protocol isolation, things like that, to control that access.
So, again, interesting, I see there was no one voted for hardware-enforced access control, but, you know, having spoken to some of the vendors who didn't take part in this particular report, because they felt that they were overwhelmed by the software approach, you know, it kind of makes, it makes sense, though, you know, if, and it kind of plays a bit to your approach, is, you know, if these things are not actually, can't actually go in and out of the environment, if it's been hardware-enforced, then, you know, you're reducing the attack surface to almost nothing, you know, so I just, I'm surprised that there is, there was not more attraction there, but, yeah, anyway, and so the last question was, which factor is your organization most concerned about when enabling remote access, and the biggest vote there was obviously third-party vendor access, which makes sense, and then there was a kind of an even split between regulatory compliance and operational downtime, and, but, again, zero for legacy system exposure.
Do you find that surprising or interesting?
Yeah, well, I think the third-party access, which is the highest one there, kind of, those kind of go together, you know, because what we see is generally the third-party access uses their own tools, and so I think there may be a question of, we know that there may be legacy system exposure, because the third party, we don't have visibility or control or, you know, user access, definitely don't have user access recordings on what their third parties are doing, so I think that's almost the legacy system exposure is kind of a subset or part and parcel to third-party access, at least in what we've seen, so maybe people were sort of looking at from the big picture standpoint instead of the, yeah.
Yeah, okay, well, we can go across to our questions. We have a couple of questions there. First one is, other than Palo Alto, do you see other ZT&A players seeking to move across from selling into enterprise IT to also target the OT world for SRA purposes? What are the barriers they face to get into this market?
Okay, well, I don't know, from my perspective, I think just all the big players like Palo Alto, if they have any interest in security, will be going down, and will be going down this route. I mean, you know, the crowd strikes in the world and like that.
I mean, what's your view, Bill? Yeah, it's interesting.
I mean, there's certainly the big firewall vendors like Palo and Fortinet, you know, they talk about SRA. I mean, you have Palo, you know, does, you know, that kind of control in the cloud, Prisma and so forth, so yeah, I mean, I think the challenge for, you know, for the sort of the legacy firewall vendors is that they generally have infrastructure that they want to deploy and, and there's the concern too, where they maybe sell a lot of VPNs and, you know, they may have to cannibalize some of that business to provide this sort of access into OT.
I think they're, you know, the larger market for them still is IT and, but yeah, I do see them starting to come into this market, you know, more, but it's always going to be a little bit of a challenge for them, just from the infrastructure, they, you know, dragging along infrastructure with them. I think that one of the barriers would also be market perception, because, you know, and not sort of having, and not being known, because also doing this report, I almost found like it's almost the OT world is almost like a separate club, you know.
So, you know, despite the fact that there is growing OT-IT convergence, there just seems to be a lot more, you know, there still seems to be a lot of us and them type approach, you know, and so I think that's changing, it has to change because of all the drivers that we've both been mentioning, and so, you know, the market perception is probably a thing, but I think that's going to change. Yeah, I mean, you know, in terms of, you know, we say our ICP or our customer profile is, you know, we started really solving the OT problem, right?
So, we focused in on that, and then as the problem sort of became more integrated with IT, you know, we do talk with IT and OT now, when we are talking with our prospects and customers, because, you know, and it really varies from customer to customer, you know, and does OT and IT get along? How are they working together?
It's been kind of a mixed bag, but I think it's moving to, hey, IT's recognizing that there's a specific problem in OT that needs to be addressed differently, which is great, and OT's recognition that, hey, we have to get, we have to make sure that IT has some visibility in what's going on and connecting to these critical systems. So, I think it's, you know, I think the innovation is driving IT and OT to work more collaboratively, which is good.
Yeah, I think it's good, and it's interesting, and so, yeah, watch this space. We have another question, and I think this is probably for you, Bill, is how do you ensure security and usability for contractors and third parties who need temporary access?
Yeah, well, I think you alluded to, you know, just having just-in-time access. So, you know, the way that we think about that is, you know, we have the ability to do, you know, single sign-on.
They can use their own IDP if they have it, you know, but it's, from our perspective, you know, they come in through an authentication mechanism, whether we're providing native MFA or through the other side, and then we set up connection profiles, and, you know, we're a least-privileged model, right, and we're built on zero-trust principles, so when they connect, unless they have access to that particular asset, they can't see anything. They're zero, right, and they can't move laterally. There's nothing they can do.
So, if they're given access to an asset, they can access that asset, and we can monitor that, we can record that, you know, you have complete session and login and recording of that. So, I mean, that's the way that, you know, we look at handling that. We have customers that, you know, will have them come through, you know, their own IDP. Some have third parties use their own IDP.
Some of them say, I want all third-party OEMs to be natively authenticated through Zona, right, so, and that's just to keep it out, keep those third parties out of their active directory and keep a much better control, and so they can get third-party connection reports and logging and recordings and all of that without having to worry about, you know, disabling access in their active directory, so. Yep, sounds good. We've got another question here, which I think is also for you. How does Zona's licensing model help customers manage costs and scale deployments across different environments?
So, I guess this is asking if you've got, yeah, I don't know whether this is just OT and IT or whether this is across different sectors, but yeah, what would you say is the answer there?
Yeah, I mean, so we're a subscription-based model, you know, and we do volume discounting if you have lots of sites and, you know, we work with our customers, you know, we have our platform today consists of a central manager that would be deployed, you know, in the cloud or in your OT or IT network, and then our gateways, which are, you know, I mean, it could be in the cloud as well, but typically we see them deployed in the OT network, you know, they kind of, they work in conjunction with one another, and so, you know, we have a, you know, subscription model for that, whether it's one site, 10 sites, 100 sites, and things like that, so we work with the customers to, you know, figure out what works best for them and how they want to roll out.
Yeah, we'll be coming quite rapidly up to the top of the hour, so I don't know whether we're going to have much time for anything else, but just see, okay, seeing we don't seem to have any questions, and we've only got a few minutes in hand, any final parting thoughts from you, Bill, is there anything you'd like to kind of just wrap up this session, because thanks very much for your input and discussion, and how would you wrap it up?
Yeah, well, thanks, Warwick, I mean, first of all, I'd like to say that, you know, really appreciate Coop and Nicole for putting together this leadership compass report, you know, on OT SRA, I mean, you're a leader in sort of the analyst market and going out and doing that, so I just want to give you all a plug for that, but yeah, I'm just, it's been very exciting watching this industry grow, I mean, I don't think SRA for OT, you go back five years, even was not a thing, right, that you would be doing an analysis on like this, that would be so universally adopted across every industry, and this kind of recognition that a platform is needed, you know, that takes care of, as you mentioned before, you know, attribute-based access, policy controls, you know, recording, session recording, protocol isolation, all of these things are really important when we talk about OT, because it's, you know, ransomware is, you know, not going away, in fact, you know, you look at the, just, you know, bring up Jaguar, Land Rover, your side of the world, but that was hopefully a wake-up call in a big way for a lot of folks in the industries, you know, you can't, you know, there's massive loss if you don't get it right, right, so, to brand as well as, you know, money, right, in the production lines going down, so.
And as you've also said a couple of times, I mean, in OT, it's kind of, can be life-threatening, whereas, you know, so with the other attacks we've seen, it's kind of just, it's hit the bottom line, but at least nobody's died that I'm aware of, so.
Yeah, I mean, you know, we're dealing with, yeah, I mean, you think about some of our customers, whether it's a mine or chemical plant or things like that, I mean, you know, it's not just the employee safety, but it's, you know, also general public safety, right, and things that can go bad very quickly if, you know, the bad guys get in, right, so, or, you know, if there's been a mistake, being able to go back and look at a recording and see what happened, right, and be able to, you know, get to a diagnosis and a remedy quicker, right, so it's all about time, right? Yeah, yeah.
Particularly in OT when, say, when there's a big problem that could affect the safety of the people around the plant or people around the plant, right? Absolutely, as you say, time to resolution, time to wrap up. Thanks so much for your input, thanks for your kind comments, thanks so much for taking part and contributing to the discussion today.
The key takeaway from message for me is that SRA isn't just about connecting people to systems, it's about connecting safely, smartly, and sustainably in an increasingly connected industrial world, so thanks for joining us and participating in the webinar. I encourage you all to read the full leadership compass on our website for detailed vendor analysis and guidance on selecting the right SRA solution for your environment. So from Bill and me, until next time, goodbye. Great.
See All Locations
See All Locations