Company
Support
Login
BifrostConnect BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel

    Create a Zero Trust network without VPN Tunneling

    Clientless Serial Tunnel

    Establish a Serial (RS232) connection without borders

    Offline File Transfer

    Transfer files without exposing endpoints to the internet

  • Who We Help
    Case Studies
    Damgaard Automatik Case Study
    SGS Case Study
    Luságua Case Study
    Operational Technology
    Engineering & Commissioning
    Cybersecurity & Compliance
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • OT Cybersecurity
    Best-practice Guide for Secure 3rd party remote access in OT
    NIS2 Remote Access WHITE PAPER
    Blog
Contact Us
BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel
    Clientless Serial Tunnel
    Offline File Transfer
  • Who We Help
    Cybersecurity & Compliance
    Engineering & Commissioning
    Operations
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • Support
  • OT Cybersecurity
    OT Cybersecurity Landscape: Denmark 2027
    NIS2 Remote Access WHITE PAPER
    Blog
Book a Demo
Contact Us

Getting Started

12
  • Admin
    • Set up your organization
    • User roles and permissions
  • Onsite User Guides
    • Onsite Step Guide
    • Connect KVM
    • Connect IP Tunnel
    • Connect Offline File Transfer
    • Connect USB Tunnel
    • Connect Serial Tunnel
    • Connect SSH
    • Connect Serial Terminal (Console Access)
  • Datasheets
    • Technical Specifications
    • Requirements

Technical Support

2
  • Feedback & Feature requests
    • Share your ideas and feedback
  • Report a bug
    • Reporting Bugs 

Release Notes

21
  • 2026
    • Remote Access Interface Release 25 June 2026
    • Direct Tunnel Release 1 June 2026
    • Bifrost Release 13 January 2026
  • 2025
    • Bifrost Release 30 Oktober 2025
    • Bifrost Release 19 August 2025
    • Bifrost Release 30 June 2025
    • Bifrost Release 11 February 2025
  • 2024
    • Bifrost Release 04 December 2024
    • Bifrost Release 16 November 2024
    • Bifrost Release 2 Oktober 2024
    • Bifrost Release 14 August 2024
    • Bifrost Release 7 May 2024
    • BifrostConnect Firmware V4.8.0
  • 2023
    • BifrostConnect Firmware V4.7.0
    • BifrostConnect Firmware V4.6.0
    • BifrostConnect Firmware V4.5.0
    • BifrostConnect Firmware V4.4.0
  • 2022
    • BifrostConnect Firmware V.4.3.2
    • BifrostConnect Firmware V.4.3.1
    • BifrostConnect Firmware V.4.2.0
  • 2021
    • BifrostConnect Firmware V.4.0.0

Best Practice Guide

14
  • About this guide
  • Core Framework
  • Architecture & Principles
  • Threat Context
  • Zero Standing Privilege
  • Four OT Access Patterns
  • Degraded Mode & Legacy Equipment
  • Defence in Depth
  • Compliance & Implementation
  • Residual Risks
  • Definitions
  • References
  • Operational Lifecycle 
  • Procurement Appendix

Implementing the OT Best Practice Framework with BifrostConnect

13
  • Overview and Framework Mapping
  • Threat Model
  • Scenario Implementation – Scenario 1
  • Scenario Implementation – Scenario 2
  • Scenario Implementation – Scenario 3
  • Scenario Implementation – Scenario 4
  • Product Reference
  • Architecture & Differentiation
  • Hardening & Deployment Guidance
  • Security Architecture Reference
  • Legacy OT & Air-Gapped Environments
  • Incident Response & Degraded Mode
  • Sources & References
  • Home
  • Knowledge Center
  • Implementing the OT Best Practice Framework with BifrostConnect
  • Architecture & Differentiation
View Categories

Architecture & Differentiation

ARCHITECTURAL COMPARISON
How does BifrostConnect’s architecture differ from a VPN, a jump host, or a ZTNA broker?

Cross-reference: Part 1, Implementation approaches.

Part 1 notes that a best-practice OT remote access architecture must close the path when no session is active, bind every action to a named individual, and keep the trust boundary out of the enterprise attack surface.

This section shows how BifrostConnect differs architecturally from the three most common alternatives in the context of OT access. The comparison applies to trust boundary placement in OT environments specifically. Modern Zero Trust and SASE architectures address related problems in IT environments through different patterns; the discussion below is deliberately scoped to OT.

Three questions that expose the difference (in OT context):

  • Where is the trust boundary? In a VPN it is the network edge; in ZTNA it is a cloud broker; in a jump host it is a reachable server; in BifrostConnect it is a physical hardware device the operator never logs into. In OT, a trust boundary that requires inbound connectivity is a trust boundary that can be probed, scanned, or exploited from the vendor or internet side.
  • What is the attack surface when no session is active? A VPN concentrator on the OT boundary is always on. A jump host in the DMZ is always listening. BifrostConnect’s Bifrost Unit maintains only an outbound connection and listens on no inbound port. This is the OT Island principle in practice: OT calls out, OT never receives.
  • What is the failure mode if the broker is compromised? A compromised VPN concentrator exposes the OT network. A compromised jump host gives an attacker a dwell position inside L3. A compromised Bifrost Unit cannot be reached inbound, cannot be logged into locally, and cannot boot alternative firmware. The Service-side trust boundary is a separate hardening surface (see Architectural transparency below).

Architecturally, BifrostConnect implements the OT Island Principle. OT initiates outbound, OT never accepts inbound. The Bifrost Unit is the enforcement point of that principle at the OT boundary. The consequence is that the OT environment remains an island: reachable only through explicitly activated, time-limited, identity-bound sessions brokered by the Bifrost Unit’s outbound connection.

COMPLEMENTARY LAYERS
Which security tools should I keep alongside BifrostConnect, and where does BifrostConnect fit?

BifrostConnect occupies the access-and-governance layer. Defence in depth keeps each layer with its specialist. The following pairings produce a stronger architecture than any single product attempting to cover the full stack:

  • Endpoint Detection and Response on engineering stations: keep your EDR vendor for malware detection on the station. AccessGuard governs who connects and what they do; EDR observes what runs once they are in. The two are complementary recording layers.
  • Network intrusion detection on the OT network: keep an OT-IDS for protocol-level DPI. Co-deploy alongside BifrostConnect, with both feeding the SIEM. Correlation produces the joint forensic view that neither product alone can.
  • Credential vaulting at enterprise scale: keep your PAM platform for credential rotation and vaulting. BifrostConnect sits upstream as the access-and-audit layer. Mapping ownership cleanly avoids overlap and keeps the credential audit trail in PAM.
  • Industrial telemetry backbone: BifrostConnect is the governance-and-access layer for human sessions; keep your industrial telemetry transport (OPC UA aggregator, MQTT broker, historian) for continuous machine-to-machine data flow.
  • IT remote access: for enterprise IT with standard endpoints and SaaS applications, ZTNA platforms cover the IT use case. BifrostConnect is the OT-specific complement – keep both, scoped to their respective domains.
CO-DEPLOYMENT CATEGORIES
What products can be co-deployed with BifrostConnect, and how do they integrate?

Cross-reference: Part 1, Implementation approaches.

BifrostConnect is the governance and access layer. Defence in depth requires monitoring, inspection and isolation layers. The relationships below are co-deployments: BifrostConnect and the co-deployed products operate independently on the same network, correlated at the SIEM layer. Unless stated otherwise, there is no API-level integration with shared data model or certified integration tests.

Matrix – suggested optional co-implementations:

Product categoryRoleCo-deployment pattern
OT-IDS platformsDeep packet inspection on Modbus TCP, OPC UA, S7comm, IEC-104 and equivalent.Deploy OT-IDS on L1/L2 traffic after Bifrost Unit decryption. Forward alerts to customer SIEM alongside Bifrost Manager events.
SIEM platforms (Splunk, Sentinel, IBM QRadar)Centralised correlation of access and OT telemetry.Bifrost Manager native SIEM export (Dedicated Cloud / on-premises). Correlation of BifrostConnect events with OT-IDS alerts at the SIEM.
Identity providers (enterprise IdP / on-prem directory)Enterprise identity federation.SAML 2.0, OAuth 2.0, AD, LDAP via Auth0. SSO available on Dedicated Cloud / on-premises.
Certified data diodeUnidirectional log export, file security gateway (malware scanning, 30 AV engines, content disarm/reconstruction), one-way database replication.Place diode between OT logging infrastructure and enterprise SIEM destination. Inline file security gateway with Direct Tunnel Access for vendor file uploads.
PAM platformsEnterprise privileged credential vaulting.BifrostConnect sits upstream of the credential layer. Co-deployment: Manager handles access authentication, PAM handles credential rotation and vaulting.
Updated on July 24, 2026
Product ReferenceHardening & Deployment Guidance
Essentials Logo
Islands Brygge 55
2300 Copenhagen S, Denmark
+45 70 60 20 56
[email protected]
About Us
Release Notes
Privacy Policy
Terms & Conditions
FAQ
Book a Demo
Book a Demo

Subscribe to Our Newsletter

Copyright BifrostConnect ApS. 2026
All Rights Reserved