NetFoundry, the leader in embedded zero trust networking, has introduced an upgraded OT security platform designed to secure critical infrastructure, including on-premises and air-gapped environments like substations.

The launch at Distributech 2025 addresses three key customer needs:

  • Software-only, interoperable, vendor-neutral OT microsegmentation
  • Secure connectivity to IT and OEMs without exposing the OT network or risking data exfiltration
  • Lower costs associated with firewalls, SIEM, SOAR, analytics, data lakes, and storage

Galeal Zino, CEO of NetFoundry, stated: “NetFoundry secures critical infrastructure across three continents, and our customers’ top priority is simple security with reduced cost and complexity for multi-vendor OT environments.”

He added, “Solutions that rely solely on firewalls or vendor-specific technologies introduce unnecessary complexity and fail to meet evolving OT cybersecurity and microsegmentation demands. Our deny-all-inbound data approach ensures IT and OT make all firewalls and servers unreachable from underlay networks. This enhances security, eliminates complex access-control management, and significantly reduces costs associated with security and storage resources by cutting down unnecessary data logs from port scanning and unauthenticated events.”

NetFoundry partner FreeWave Technologies recently integrated NetFoundry’s zero trust technology alongside Keyfactor for Industrial Internet of Things (IIoT) and wireless connectivity solutions to secure remote and embedded industrial edge operations.

Steve Wulchin, CEO of FreeWave, commented: “Traditional security measures like VPNs are no longer sufficient in today’s hyperconnected world. NetFoundry’s technology allows us to enforce strict deny-by-default security principles across all users, devices, and applications. The on-prem option is a game-changer for customers who need to function independently from external connectivity while maintaining secure access to external edges and clouds when needed. This partnership helps us align with emerging secure-by-design regulations like the EU Cyber Resilience Act (CRA).”

Rik Turner, Senior Principal Analyst at Omdia, added: “While zero trust has gained traction for secure remote access in IT, it is even more critical for OT environments, where security must be enforced for both remote and on-premises access. NetFoundry’s introduction of an on-prem option aligns with the needs of critical infrastructure operators who cannot rely on cloud-based security solutions.”

The NetFoundry OT security platform allows OT firewalls to operate with a single inbound rule—deny-all inbound traffic, with no exceptions, even when communicating with IT or OEM systems. The software-only microsegmentation solution seamlessly integrates with existing routers, firewalls, edge compute devices, and programmable logic controllers (PLCs). Additionally, security operations teams gain access to telemetry and analytics for threat response and regulatory compliance tracking, while IT benefits from lower operational costs.

Both OT and IT teams can deploy NetFoundry’s software on any server, including existing firewalls, edge devices, and PLCs. OEMs can also integrate NetFoundry’s software directly into industrial control systems, manufacturing machines, modems, routers, firewalls, edge cells, and reverse proxies. Organizations leveraging NetFoundry’s technology include Microsoft, Arrow, Capgemini, FreeWave, EdgeX Foundry, and Supermicro.