Company
Support
Login
BifrostConnect BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel

    Create a Zero Trust network without VPN Tunneling

    Clientless Serial Tunnel

    Establish a Serial (RS232) connection without borders

    Offline File Transfer

    Transfer files without exposing endpoints to the internet

  • Who We Help
    Case Studies
    Damgaard Automatik Case Study
    SGS Case Study
    Luságua Case Study
    Operational Technology
    Engineering & Commissioning
    Cybersecurity & Compliance
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • OT Cybersecurity
    Best-practice Guide for Secure 3rd party remote access in OT
    NIS2 Remote Access WHITE PAPER
    Blog
Contact Us
BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel
    Clientless Serial Tunnel
    Offline File Transfer
  • Who We Help
    Cybersecurity & Compliance
    Engineering & Commissioning
    Operations
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • Support
  • OT Cybersecurity
    OT Cybersecurity Landscape: Denmark 2027
    NIS2 Remote Access WHITE PAPER
    Blog
Book a Demo
Contact Us

Getting Started

12
  • Admin
    • Set up your organization
    • User roles and permissions
  • Onsite User Guides
    • Onsite Step Guide
    • Connect KVM
    • Connect IP Tunnel
    • Connect Offline File Transfer
    • Connect USB Tunnel
    • Connect Serial Tunnel
    • Connect SSH
    • Connect Serial Terminal (Console Access)
  • Datasheets
    • Technical Specifications
    • Requirements

Technical Support

2
  • Feedback & Feature requests
    • Share your ideas and feedback
  • Report a bug
    • Reporting Bugs 

Release Notes

21
  • 2026
    • Remote Access Interface Release 25 June 2026
    • Direct Tunnel Release 1 June 2026
    • Bifrost Release 13 January 2026
  • 2025
    • Bifrost Release 30 Oktober 2025
    • Bifrost Release 19 August 2025
    • Bifrost Release 30 June 2025
    • Bifrost Release 11 February 2025
  • 2024
    • Bifrost Release 04 December 2024
    • Bifrost Release 16 November 2024
    • Bifrost Release 2 Oktober 2024
    • Bifrost Release 14 August 2024
    • Bifrost Release 7 May 2024
    • BifrostConnect Firmware V4.8.0
  • 2023
    • BifrostConnect Firmware V4.7.0
    • BifrostConnect Firmware V4.6.0
    • BifrostConnect Firmware V4.5.0
    • BifrostConnect Firmware V4.4.0
  • 2022
    • BifrostConnect Firmware V.4.3.2
    • BifrostConnect Firmware V.4.3.1
    • BifrostConnect Firmware V.4.2.0
  • 2021
    • BifrostConnect Firmware V.4.0.0

Best Practice Guide

14
  • About this guide
  • Core Framework
  • Architecture & Principles
  • Threat Context
  • Zero Standing Privilege
  • Four OT Access Patterns
  • Degraded Mode & Legacy Equipment
  • Defence in Depth
  • Compliance & Implementation
  • Residual Risks
  • Definitions
  • References
  • Operational Lifecycle 
  • Procurement Appendix

Implementing the OT Best Practice Framework with BifrostConnect

13
  • Overview and Framework Mapping
  • Threat Model
  • Scenario Implementation – Scenario 1
  • Scenario Implementation – Scenario 2
  • Scenario Implementation – Scenario 3
  • Scenario Implementation – Scenario 4
  • Product Reference
  • Architecture & Differentiation
  • Hardening & Deployment Guidance
  • Security Architecture Reference
  • Legacy OT & Air-Gapped Environments
  • Incident Response & Degraded Mode
  • Sources & References
  • Home
  • Knowledge Center
  • Implementing the OT Best Practice Framework with BifrostConnect
  • Sources & References
View Categories

Sources & References

SOURCES AND REFERENCES
What source documents, regulations, and standards does this guide reference?

Source documents used in Part 2:

  • BifrostConnect, Security Documentation, Version 2.2.2 (February 2026).
  • BifrostConnect, AccessGuard product description.
  • BifrostConnect, SessionGuard product description.
  • Part 1: OT Best Practice Guide, Part 1 (June 2026).

Regulatory sources (shared with Part 1):

  • Directive (EU) 2022/2555, OJ L 333, 14 December 2022.
  • Act No. 434 of 6 May 2025 on measures to ensure a high level of cybersecurity (Danish NIS2 Implementation Act).
  • Styrelsen for Samfundssikkerhed (SAMSIK), Vejledning til NIS 2-loven, June to August 2025.
  • IEC 62443 series: DS/EN IEC 62443-3-3:2019 (system security requirements), DS/EN IEC 62443-2-4:2024 (service provider security programme), DS/EN IEC 62443-2-1:2024 (asset owner cybersecurity programme).
  • Executive Order No. 260 of 6 March 2025, Danish Ministry of Climate, Energy and Utilities.
  • Bekendtgørelse om modstandsdygtighed og beredskab i energisektoren (Danish Executive Order on resilience and preparedness in the energy sector).
  • ISO/IEC 27001:2022.
  • NIST SP 800-82 Revision 3, Guide to Operational Technology (OT) Security, September 2023.
  • NIST SP 800-207, Zero Trust Architecture, August 2020.
  • NIST SP 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations.
  • Joint NCSC, ASD ACSC, CCCS, CISA, FBI, BSI, NCSC-NL, NCSC-NZ, Secure Connectivity Principles for Operational Technology, 18 March 2024.
  • Joint CISA, DoW, DOE, FBI, DOS with NIST contributions, Adapting Zero Trust Principles to Operational Technology, 29 April 2026.
  • Directive (EU) 2022/2557, OJ L 333, 14 December 2022.
  • Regulation (EU) 2016/679 (GDPR).

Co-deployment references:

  • OT-IDS platforms: referenced for deep packet inspection on OT protocols. Co-deployment, not API-integrated.
  • Data diode category: unidirectional gateway, file security gateway (multi-engine malware scanning, content disarm/reconstruction), one-way log export, one-way Historian/database replication. Referenced for compensating controls.
  • Auth0: identity and multi-factor authentication layer used by BifrostConnect Service.
  • Netbird: open-source WireGuard-based tunnelling component used by Direct Tunnel Access.

Threat intelligence:

  • MITRE ATT&CK for ICS. Volt Typhoon: CISA Advisory AA24-038A. Sandworm: Mandiant ‘APT44: Unearthing Sandworm’ (April 2024).
  • SektorCERT, Threat Assessment: The Danish Energy Sector, November 2023.
  • CISA ICS-CERT Advisories: Colonial Pipeline (AA21-131A), Oldsmar (AA21-042A, attribution disputed), TRITON (Dragos ‘TRISIS malware analysis’).
  • CISA Advisory AA23-335A (CyberAv3ngers): IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors.

Disclaimer:

This document is a companion to the Part 1 best-practice framework. Product features described here are accurate as of the publication date (June 2026). Regulatory citations reflect the legal text as of the publication date. Customers should validate enforcement of every stated control during rollout through acceptance testing.

Published by BifrostConnect. Part 2 of a two-part publication. Version 1.21, June 2026. Web: bifrostconnect.com.

Where VPNs end, BifrostConnect.

Updated on July 24, 2026
Incident Response & Degraded ModeOverview and Framework Mapping
Essentials Logo
Islands Brygge 55
2300 Copenhagen S, Denmark
+45 70 60 20 56
[email protected]
About Us
Release Notes
Privacy Policy
Terms & Conditions
FAQ
Book a Demo
Book a Demo

Subscribe to Our Newsletter

Copyright BifrostConnect ApS. 2026
All Rights Reserved