Company
Support
Login
BifrostConnect BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel

    Create a Zero Trust network without VPN Tunneling

    Clientless Serial Tunnel

    Establish a Serial (RS232) connection without borders

    Offline File Transfer

    Transfer files without exposing endpoints to the internet

  • Who We Help
    Case Studies
    Damgaard Automatik Case Study
    SGS Case Study
    Luságua Case Study
    Operational Technology
    Engineering & Commissioning
    Cybersecurity & Compliance
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • OT Cybersecurity
    Best-practice Guide for Secure 3rd party remote access in OT
    NIS2 Remote Access WHITE PAPER
    Blog
Contact Us
BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel
    Clientless Serial Tunnel
    Offline File Transfer
  • Who We Help
    Cybersecurity & Compliance
    Engineering & Commissioning
    Operations
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • Support
  • OT Cybersecurity
    OT Cybersecurity Landscape: Denmark 2027
    NIS2 Remote Access WHITE PAPER
    Blog
Book a Demo
Contact Us

Getting Started

12
  • Admin
    • Set up your organization
    • User roles and permissions
  • Onsite User Guides
    • Onsite Step Guide
    • Connect KVM
    • Connect IP Tunnel
    • Connect Offline File Transfer
    • Connect USB Tunnel
    • Connect Serial Tunnel
    • Connect SSH
    • Connect Serial Terminal (Console Access)
  • Datasheets
    • Technical Specifications
    • Requirements

Technical Support

2
  • Feedback & Feature requests
    • Share your ideas and feedback
  • Report a bug
    • Reporting Bugs 

Release Notes

21
  • 2026
    • Remote Access Interface Release 25 June 2026
    • Direct Tunnel Release 1 June 2026
    • Bifrost Release 13 January 2026
  • 2025
    • Bifrost Release 30 Oktober 2025
    • Bifrost Release 19 August 2025
    • Bifrost Release 30 June 2025
    • Bifrost Release 11 February 2025
  • 2024
    • Bifrost Release 04 December 2024
    • Bifrost Release 16 November 2024
    • Bifrost Release 2 Oktober 2024
    • Bifrost Release 14 August 2024
    • Bifrost Release 7 May 2024
    • BifrostConnect Firmware V4.8.0
  • 2023
    • BifrostConnect Firmware V4.7.0
    • BifrostConnect Firmware V4.6.0
    • BifrostConnect Firmware V4.5.0
    • BifrostConnect Firmware V4.4.0
  • 2022
    • BifrostConnect Firmware V.4.3.2
    • BifrostConnect Firmware V.4.3.1
    • BifrostConnect Firmware V.4.2.0
  • 2021
    • BifrostConnect Firmware V.4.0.0

Best Practice Guide

14
  • About this guide
  • Core Framework
  • Architecture & Principles
  • Threat Context
  • Zero Standing Privilege
  • Four OT Access Patterns
  • Degraded Mode & Legacy Equipment
  • Defence in Depth
  • Compliance & Implementation
  • Residual Risks
  • Definitions
  • References
  • Operational Lifecycle 
  • Procurement Appendix

Implementing the OT Best Practice Framework with BifrostConnect

13
  • Overview and Framework Mapping
  • Threat Model
  • Scenario Implementation – Scenario 1
  • Scenario Implementation – Scenario 2
  • Scenario Implementation – Scenario 3
  • Scenario Implementation – Scenario 4
  • Product Reference
  • Architecture & Differentiation
  • Hardening & Deployment Guidance
  • Security Architecture Reference
  • Legacy OT & Air-Gapped Environments
  • Incident Response & Degraded Mode
  • Sources & References
  • Home
  • Knowledge Center
  • Implementing the OT Best Practice Framework with BifrostConnect
  • Legacy OT & Air-Gapped Environments
View Categories

Legacy OT & Air-Gapped Environments

LEGACY OT EQUIPMENT
How does BifrostConnect handle legacy serial connections to PLCs and RTUs?

Part 1 introduces a section on compensating controls for legacy equipment. This section describes what BifrostConnect can and cannot do for legacy OT and where the boundary lies between BifrostConnect’s coverage and the asset owner’s supplementary controls.

Bifrost Unit (with serial console port), Clientless Tunnel Access.

Many legacy PLCs and RTUs accept only RS-232 or RS-485 serial connections. The Bifrost Unit provides a serial console port and can broker session-based access to a serial device behind it.

The IP-side properties of the brokered session (authenticated operator, time-bounded access, session recording where SessionGuard or AccessGuard is deployed, audit log export to customer SIEM) apply to the IP path between the operator and the Bifrost Unit; the serial side is a controlled extension of that session. The operator never gets a flat IP path to the legacy device.

This satisfies the Part 1 ‘Serial connections via protocol converters’ compensating control.

LEGACY OT EQUIPMENT
Can BifrostConnect bridge an air gap, and where should it be deployed around one?

Where the asset owner has a deliberate air gap, the air gap itself is the primary control – and BifrostConnect is not designed to bridge it. The Bifrost Unit needs an outbound IP connection to the BifrostConnect Service to function, so it must sit on the IT side of the gap, never inside the air-gapped OT zone. The strongest deployment pattern uses BifrostConnect to harden the boundary on either side of the gap rather than to cross it:

  • On the IT side: deploy a Bifrost Unit on the staging workstation that prepares signed media for transfer. Vendor access to this workstation is then identity-bound, time-bounded, and recorded.
  • On the OT side: keep human-and-procedural brokering in place (controlled media transfer, chain-of-custody, multi-engine malware scanning via a data-diode file security gateway).
  • Combined effect: BifrostConnect supplements rather than substitutes for the air gap procedures, and the audit trail covers everything the vendor touched on the IT side.

Procure BifrostConnect with this scope in mind: it strengthens the perimeter of an air-gapped installation, but it does not replace the gap.

LEGACY OT EQUIPMENT
How does BifrostConnect protect proprietary systems that cannot host an agent?

Bifrost Unit at the boundary, Direct Native Access for screen-level interaction.

Many legacy automation platforms cannot run AccessGuard or any other endpoint-resident agent. The applicable BifrostConnect pattern is to wrap the legacy device behind a Bifrost Unit deployed at the boundary of a small dedicated VLAN.

The legacy device contributes nothing to its own security; the Bifrost Unit contributes the identity, time-bounding, recording, and log-export properties externally.

Direct Native Access (KVM, serial, SSH session types) is the typical access modality because the operator interacts with the legacy device through whatever console the device offers, with no modification to the device itself.

The asset owner is responsible for the firewall rules that deny all paths into the dedicated VLAN except via the Bifrost Unit.

LEGACY OT EQUIPMENT
What operational compensating controls apply to legacy OT devices with shared passwords or undocumented firmware?

Some legacy OT failure modes are operational rather than technical: a device with a single shared password, a legacy operating system that cannot be patched, proprietary firmware that the device vendor will not document. BifrostConnect handles the human-session governance around these devices; the asset owner’s operational compensating controls handle the rest. The combination is what produces a defensible control envelope:

  • Controlled engagement scheduling: every vendor touch on a legacy device happens through a Bifrost Unit session, time-bounded, identity-bound, and recorded. The session record is the audit artefact even when the device itself produces none.
  • Supervisor co-presence: for the highest-risk legacy interactions, require an on-site operator to be present (Attended Bifrost Unit with physical TOTP, or Direct Native Access with operator screen-share). The four-eyes principle compensates for the device’s inability to enforce identity itself.
  • Pre- and post-engagement integrity baselines: capture a known-good baseline before the session (configuration export, firmware hash where readable, file-system snapshot), and re-validate against that baseline after the session. Anomalies surface in the SOC without relying on the device’s own logging.
  • Authorized application scope: where AccessGuard is in scope, scope the launchable applications to exactly what the engagement needs. Where AccessGuard is not in scope, encode the equivalent constraint in the change-management ticket and verify against the recording.

These controls do not change the legacy device. They put the device inside an envelope that is identity-bound, time-bounded, recorded, and reviewable – which is what the regulator is looking for.

Updated on July 24, 2026
Security Architecture ReferenceIncident Response & Degraded Mode
Essentials Logo
Islands Brygge 55
2300 Copenhagen S, Denmark
+45 70 60 20 56
[email protected]
About Us
Release Notes
Privacy Policy
Terms & Conditions
FAQ
Book a Demo
Book a Demo

Subscribe to Our Newsletter

Copyright BifrostConnect ApS. 2026
All Rights Reserved