Part 1 introduces a section on compensating controls for legacy equipment. This section describes what BifrostConnect can and cannot do for legacy OT and where the boundary lies between BifrostConnect’s coverage and the asset owner’s supplementary controls.
Bifrost Unit (with serial console port), Clientless Tunnel Access.
Many legacy PLCs and RTUs accept only RS-232 or RS-485 serial connections. The Bifrost Unit provides a serial console port and can broker session-based access to a serial device behind it.
The IP-side properties of the brokered session (authenticated operator, time-bounded access, session recording where SessionGuard or AccessGuard is deployed, audit log export to customer SIEM) apply to the IP path between the operator and the Bifrost Unit; the serial side is a controlled extension of that session. The operator never gets a flat IP path to the legacy device.
This satisfies the Part 1 ‘Serial connections via protocol converters’ compensating control.
Where the asset owner has a deliberate air gap, the air gap itself is the primary control – and BifrostConnect is not designed to bridge it. The Bifrost Unit needs an outbound IP connection to the BifrostConnect Service to function, so it must sit on the IT side of the gap, never inside the air-gapped OT zone. The strongest deployment pattern uses BifrostConnect to harden the boundary on either side of the gap rather than to cross it:
- On the IT side: deploy a Bifrost Unit on the staging workstation that prepares signed media for transfer. Vendor access to this workstation is then identity-bound, time-bounded, and recorded.
- On the OT side: keep human-and-procedural brokering in place (controlled media transfer, chain-of-custody, multi-engine malware scanning via a data-diode file security gateway).
- Combined effect: BifrostConnect supplements rather than substitutes for the air gap procedures, and the audit trail covers everything the vendor touched on the IT side.
Procure BifrostConnect with this scope in mind: it strengthens the perimeter of an air-gapped installation, but it does not replace the gap.
Bifrost Unit at the boundary, Direct Native Access for screen-level interaction.
Many legacy automation platforms cannot run AccessGuard or any other endpoint-resident agent. The applicable BifrostConnect pattern is to wrap the legacy device behind a Bifrost Unit deployed at the boundary of a small dedicated VLAN.
The legacy device contributes nothing to its own security; the Bifrost Unit contributes the identity, time-bounding, recording, and log-export properties externally.
Direct Native Access (KVM, serial, SSH session types) is the typical access modality because the operator interacts with the legacy device through whatever console the device offers, with no modification to the device itself.
The asset owner is responsible for the firewall rules that deny all paths into the dedicated VLAN except via the Bifrost Unit.
Some legacy OT failure modes are operational rather than technical: a device with a single shared password, a legacy operating system that cannot be patched, proprietary firmware that the device vendor will not document. BifrostConnect handles the human-session governance around these devices; the asset owner’s operational compensating controls handle the rest. The combination is what produces a defensible control envelope:
- Controlled engagement scheduling: every vendor touch on a legacy device happens through a Bifrost Unit session, time-bounded, identity-bound, and recorded. The session record is the audit artefact even when the device itself produces none.
- Supervisor co-presence: for the highest-risk legacy interactions, require an on-site operator to be present (Attended Bifrost Unit with physical TOTP, or Direct Native Access with operator screen-share). The four-eyes principle compensates for the device’s inability to enforce identity itself.
- Pre- and post-engagement integrity baselines: capture a known-good baseline before the session (configuration export, firmware hash where readable, file-system snapshot), and re-validate against that baseline after the session. Anomalies surface in the SOC without relying on the device’s own logging.
- Authorized application scope: where AccessGuard is in scope, scope the launchable applications to exactly what the engagement needs. Where AccessGuard is not in scope, encode the equivalent constraint in the change-management ticket and verify against the recording.
These controls do not change the legacy device. They put the device inside an envelope that is identity-bound, time-bounded, recorded, and reviewable – which is what the regulator is looking for.