Company
Support
Login
BifrostConnect BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel

    Create a Zero Trust network without VPN Tunneling

    Clientless Serial Tunnel

    Establish a Serial (RS232) connection without borders

    Offline File Transfer

    Transfer files without exposing endpoints to the internet

  • Who We Help
    Case Studies
    Damgaard Automatik Case Study
    SGS Case Study
    Luságua Case Study
    Operational Technology
    Engineering & Commissioning
    Cybersecurity & Compliance
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • OT Cybersecurity
    Best-practice Guide for Secure 3rd party remote access in OT
    NIS2 Remote Access WHITE PAPER
    Blog
Contact Us
BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel
    Clientless Serial Tunnel
    Offline File Transfer
  • Who We Help
    Cybersecurity & Compliance
    Engineering & Commissioning
    Operations
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • Support
  • OT Cybersecurity
    OT Cybersecurity Landscape: Denmark 2027
    NIS2 Remote Access WHITE PAPER
    Blog
Book a Demo
Contact Us

Getting Started

12
  • Admin
    • Set up your organization
    • User roles and permissions
  • Onsite User Guides
    • Onsite Step Guide
    • Connect KVM
    • Connect IP Tunnel
    • Connect Offline File Transfer
    • Connect USB Tunnel
    • Connect Serial Tunnel
    • Connect SSH
    • Connect Serial Terminal (Console Access)
  • Datasheets
    • Technical Specifications
    • Requirements

Technical Support

2
  • Feedback & Feature requests
    • Share your ideas and feedback
  • Report a bug
    • Reporting Bugs 

Release Notes

21
  • 2026
    • Remote Access Interface Release 25 June 2026
    • Direct Tunnel Release 1 June 2026
    • Bifrost Release 13 January 2026
  • 2025
    • Bifrost Release 30 Oktober 2025
    • Bifrost Release 19 August 2025
    • Bifrost Release 30 June 2025
    • Bifrost Release 11 February 2025
  • 2024
    • Bifrost Release 04 December 2024
    • Bifrost Release 16 November 2024
    • Bifrost Release 2 Oktober 2024
    • Bifrost Release 14 August 2024
    • Bifrost Release 7 May 2024
    • BifrostConnect Firmware V4.8.0
  • 2023
    • BifrostConnect Firmware V4.7.0
    • BifrostConnect Firmware V4.6.0
    • BifrostConnect Firmware V4.5.0
    • BifrostConnect Firmware V4.4.0
  • 2022
    • BifrostConnect Firmware V.4.3.2
    • BifrostConnect Firmware V.4.3.1
    • BifrostConnect Firmware V.4.2.0
  • 2021
    • BifrostConnect Firmware V.4.0.0

Best Practice Guide

14
  • About this guide
  • Core Framework
  • Architecture & Principles
  • Threat Context
  • Zero Standing Privilege
  • Four OT Access Patterns
  • Degraded Mode & Legacy Equipment
  • Defence in Depth
  • Compliance & Implementation
  • Residual Risks
  • Definitions
  • References
  • Operational Lifecycle 
  • Procurement Appendix

Implementing the OT Best Practice Framework with BifrostConnect

13
  • Overview and Framework Mapping
  • Threat Model
  • Scenario Implementation – Scenario 1
  • Scenario Implementation – Scenario 2
  • Scenario Implementation – Scenario 3
  • Scenario Implementation – Scenario 4
  • Product Reference
  • Architecture & Differentiation
  • Hardening & Deployment Guidance
  • Security Architecture Reference
  • Legacy OT & Air-Gapped Environments
  • Incident Response & Degraded Mode
  • Sources & References
  • Home
  • Knowledge Center
  • Implementing the OT Best Practice Framework with BifrostConnect
  • Incident Response & Degraded Mode
View Categories

Incident Response & Degraded Mode

INCIDENT RESPONSE LIFECYCLE
What role does BifrostConnect play across the five phases of incident response?
  • 1. Prepare (BifrostConnect: core role) — Zero standing privilege, brokered access and recording in place before any incident: the control baseline.
  • 2. Detect (Customer-side, BifrostConnect supports) — Customer-side activity (SIEM, NDR). BifrostConnect contributes session audit logs as an input, not the detector.
  • 3. Respond (BifrostConnect: core role) — Clean out-of-band access for responders over 4G/LTE, with Manager approval and the Bifrost Unit, independent of the WAN.
  • 4. Recover (BifrostConnect: core role) — Forensic session recordings plus a controlled rebuild path (Manager + Bifrost Unit + AccessGuard / SessionGuard).
  • 5. Learn (Customer-side, BifrostConnect supports) — Customer-side review. The audit trail and recordings feed the post-incident analysis and control improvements.

Island-Mode / Fallback Mode: Critical systems continue running in isolation; access only through BifrostConnect; remote support via 4G/Satellite; maintain operations without reopening the network.

The result: Maintain business continuity; enable remote diagnostics during containment; recover systems safely and efficiently; restore operations without exposing OT to the internet.

ISLAND MODE
How does island mode keep essential OT operations running when the production network is down?

When the production network is down, the out-of-band path keeps essential operations running. The production WAN / IT side may be isolated or compromised and contained, with no path from the IT side to the OT island. Inside the OT island, essential operations (HMI/SCADA, PLC) continue via the Bifrost Unit, which reaches the remote responder through an out-of-band path (4G/LTE or satellite) that is independent of the WAN and outbound-only, giving a clean path with no IT transit.

Why this works: The Bifrost Unit reaches out over its own cellular path (4G/LTE or an external satellite antenna), so responders keep clean access to OT even when the production network is down. No inbound path is opened into the island, and the IT-side compromise stays contained.

DEGRADED MODE
What happens if the BifrostConnect Service is unreachable (WAN outage)?

Part 1 introduces a section on degraded mode operations: what should happen when the central session broker is unavailable. This section describes BifrostConnect’s concrete behaviour in each degraded scenario.

Symptom: the Bifrost Unit cannot reach the BifrostConnect Service. New session requests cannot be initiated through the standard path. Existing established sessions are tunnels that have already been negotiated end-to-end and may continue if the tunnel is stable; new sessions cannot start until the WAN is restored.

BifrostConnect behaviour: the Bifrost Unit retries the outbound connection at a configurable interval and resumes normal operation when reachability is restored. The Unit does not accept inbound connections during the outage; the OT Island Principle is preserved.

DEGRADED MODE
What happens if the BifrostConnect Service is unreachable (WAN outage)?

Part 1 introduces a section on degraded mode operations: what should happen when the central session broker is unavailable. This section describes BifrostConnect’s concrete behaviour in each degraded scenario.

Symptom: the Bifrost Unit cannot reach the BifrostConnect Service. New session requests cannot be initiated through the standard path. Existing established sessions are tunnels that have already been negotiated end-to-end and may continue if the tunnel is stable; new sessions cannot start until the WAN is restored.

BifrostConnect behaviour: the Bifrost Unit retries the outbound connection at a configurable interval and resumes normal operation when reachability is restored. The Unit does not accept inbound connections during the outage; the OT Island Principle is preserved.

DEGRADED MODE
Which BifrostConnect controls never bypass, even in degraded mode?

Audit trail. Session audit is captured by the Manager/Service and forwarded to the SIEM; the Bifrost Unit retains no local audit log. Because the Service brokers every session, a session cannot be established while the Service is unreachable, so there is no un-audited degraded session.

Identity. Every session is tied to a named individual by the Manager/Service identity broker; the Bifrost Unit holds no local user store. If the Manager/Service is unreachable, a session cannot be authenticated and is not established (fail-closed).

Approval. A break-glass session requires an admin to have authorised the degraded mode in advance through Manager configuration; the Bifrost Unit does not invent its own approval.

Time-bounding. Degraded sessions expire automatically; degraded mode is not a stable operating state.

The ten sample procurement clauses in Part 1 form the contractual basis for any third-party OT access engagement with BifrostConnect. Specific clause-by-clause coverage is provided to procurement teams on request as part of the engagement onboarding process.

Updated on July 24, 2026
Legacy OT & Air-Gapped EnvironmentsSources & References
Essentials Logo
Islands Brygge 55
2300 Copenhagen S, Denmark
+45 70 60 20 56
[email protected]
About Us
Release Notes
Privacy Policy
Terms & Conditions
FAQ
Book a Demo
Book a Demo

Subscribe to Our Newsletter

Copyright BifrostConnect ApS. 2026
All Rights Reserved