Frequently asked questions about BifrostConnect
Last updated: September 2026
This page answers the questions security teams, OT engineers, vendors and auditors ask about BifrostConnect: how outbound-only, hardware-based remote access works, which access method fits which task, how sessions are encrypted and governed, how the architecture maps to NIS2, the Danish energy-sector rules and IEC 62443, and what the Bifrost Unit needs to run. Every answer is aligned with the published OT Best Practice Guide, Part 1 and Part 2, version 1.21 (June 2026).
1. About BifrostConnect
What is BifrostConnect?
BifrostConnect is a Danish, hardware-based remote access solution for operational technology (OT) that gives vendors and technicians ad hoc, outbound-only access without a VPN. It needs no software on the OT equipment and opens no inbound port on the OT network. It combines a battery-powered hardware unit (the Bifrost Unit), a governance platform (Bifrost Manager) and three access methods under the product brand Unified Out-of-Band Access. Access exists only while the OT side has opened a session; between sessions there is no standing path.
What is Unified Out-of-Band Access?
Unified Out-of-Band Access is BifrostConnect’s product brand for one platform that combines three access methods, central access management, session accountability and secure file transfer on a single hardware hub, the Bifrost Unit. The three access methods are Direct Native Access, Direct Tunnel Access and Clientless Tunnel Access. “Out-of-band” means the access path is logically or physically independent of the customer’s operational network, so it remains usable when that network is degraded, isolated or compromised.
What is the Bifrost Unit?
The Bifrost Unit is the physical access broker in every BifrostConnect deployment: a compact, battery-powered hardware unit with built-in 4G/LTE, Wi-Fi, Ethernet, serial, HDMI and USB-C connections, manufactured in Denmark. It sits at the boundary of the OT equipment or network, initiates an outbound-only connection on port 443 and accepts no inbound connections. Every unit is produced as either an Attended unit (on-site staff authorise each session on the device) or an Unattended unit (an administrator initiates sessions through Bifrost Manager).
Who is BifrostConnect for?
BifrostConnect is built for organisations that must give vendors, integrators and their own technicians remote access to operational technology and critical infrastructure, and for the vendors who perform that work. Typical users are water and wastewater utilities, energy and district heating operators, industrial automation and manufacturing, pharma and life science, testing, inspection and certification, logistics, transportation and maritime, and banking and financial services. The published OT guide is written for CISOs, OT security architects, compliance officers and risk managers at critical infrastructure operators, and for the system integrators and vendors who work into their OT.
Why does BifrostConnect say it begins where VPNs end?
Because a VPN gives a remote user a standing network path into the OT segment, and that path exists whether or not anyone is using it. BifrostConnect replaces the standing path with brokered, time-bound, recorded and revocable sessions that exist only while the OT side has opened them. The problem is not VPN as a technology; NIST SP 800-82 Rev. 3 recognises VPN as a valid component of remote access. The problem is flat, persistent, multi-purpose remote access without per-session brokering, time-bounding or evidence. Where VPNs end, BifrostConnect.
Is BifrostConnect a VPN?
No. A VPN extends the network to the remote user and leaves an always-listening concentrator at the OT boundary. BifrostConnect does not extend the network by default: with Direct Native Access the technician sees a video stream of the endpoint and never joins the OT network, and with Direct Tunnel Access the technician receives scoped, session-only connectivity to specified endpoints, initiated outbound by the Bifrost Unit. Nothing on the OT side listens for an inbound connection, so the attack surface when no session is active is closed rather than reduced by configuration.
Where is BifrostConnect made and based?
The Bifrost Unit is manufactured in Denmark, and BifrostConnect ApS is based at Islands Brygge 55, 2300 Copenhagen S, Denmark. The published OT Best Practice Guide carries a technical review by Mikael Vingaard of ICSRange.
2. How it works
How does a BifrostConnect session work from start to finish?
A BifrostConnect session moves through five states: closed by default, authorised, opened, active and closed again, and the Bifrost Unit initiates the connection outbound at every stage. An administrator first defines the access policy in Bifrost Manager (who, which unit, which scope, which time window). The technician authenticates with multi-factor authentication and the session starts only if it matches that policy. While active, the scope is enforced and the session is bounded to the approved window and endpoints. At close, the tunnel is destroyed, any recording is finalised and the audit trail is complete; privilege returns to zero until the next authorised session.
What is the OT Island Principle?
The OT Island Principle is a single directional rule: OT calls out, OT never receives. The operational zone initiates outbound sessions to an external broker when work is needed and does not accept inbound connections from any external network, so inbound paths are structurally absent rather than blocked by configuration. In a BifrostConnect deployment the Bifrost Unit is the enforcement point of this principle at the OT boundary. The principle is anchored in NIST SP 800-207 Tenets 3 and 6 and IEC 62443-3-3 SR 1.13.
What does outbound-only mean for my firewall?
Outbound-only means the Bifrost Unit opens every connection itself, to the BifrostConnect Service on port 443, and listens on no inbound port, so no inbound firewall rule is needed on the OT network. The outbound channel uses TLS on port 443 and carries WebRTC and MQTT over WebSocket Secure; the network must allow that traffic and must not disable WebRTC over UDP. If the network requires a proxy, the unit is set to HOST mode and the BifrostConnect Service domains are whitelisted.
What is Zero Standing Privilege, and how does BifrostConnect implement it?
Zero Standing Privilege means no access exists between sessions: every session is requested, evaluated against current policy, opened for a bounded window and revoked at close. BifrostConnect implements it through administrator-defined access policy in Bifrost Manager (per user, per unit, per subnet), session-based teardown for Direct Native Access, and time-bound subnet mappings for Direct Tunnel Access through Time-Based Access on the Advanced plan and the Dedicated Cloud tier. The principle is anchored in NIST SP 800-207 Tenets 3 and 6 and IEC 62443-3-3 SR 2.1 and SR 2.6.
What is the difference between an Attended and an Unattended Bifrost Unit?
An Attended Bifrost Unit requires someone on site to authorise each session on the device, while an Unattended Bifrost Unit lets an administrator start sessions through Bifrost Manager without on-site presence. The Attended unit displays an 8-digit time-based one-time password on its screen, generated by a physical button press with a 60-second default lifespan, and has a physical disconnect button; the operator must enter the code together with their credentials. The Unattended unit authenticates the administrator with credentials plus multi-factor authentication in Bifrost Manager. Each unit is produced as one or the other for its lifespan; the two are not interchangeable at runtime.
Does equipment connected to a Bifrost Unit get internet access?
No. The Bifrost Unit does not act as a modem or router for the equipment behind it. The unit uses its own 4G/LTE, Wi-Fi or LAN connection only to reach the BifrostConnect Service outbound; the OT equipment receives no internet path through the unit and no inbound path from the internet.
Can a technician’s computer join the OT network through BifrostConnect?
With Direct Native Access, no: the technician’s computer receives a video stream of the endpoint and has no IP-level access to any OT asset, so lateral movement from that computer is architecturally impossible. With Direct Tunnel Access, the computer receives temporary, scoped IP connectivity to the endpoints named in the subnet mapping, for the session only; its own IP address never appears on the OT network because the Bifrost Unit masquerades the source address. Unsolicited inbound traffic is blocked by default.
What happens if the internet connection or the BifrostConnect Service is unavailable?
New sessions cannot start, existing sessions may continue, and the Bifrost Unit never accepts an inbound connection during the outage. If the unit cannot reach the BifrostConnect Service, it retries the outbound connection at a configurable interval and resumes normal operation when reachability returns; established sessions are end-to-end tunnels that may continue if stable. If Bifrost Manager is unreachable, an active session continues until its natural end (browser close, code expiry or window end), new sessions cannot be authorised, and audit events are synchronised to Bifrost Manager when reachability is restored. The architecture fails closed: no un-audited or unauthenticated session can be established.
Does BifrostConnect still work when the customer’s own network is down?
Yes. The Bifrost Unit reaches out over its own cellular path (4G/LTE, or an external satellite antenna), independent of the production WAN, so responders keep a clean out-of-band path to the OT equipment even when the production network is isolated or compromised. No inbound path is opened into the OT zone, and an IT-side compromise stays contained. This is the island-mode and business-continuity role of the unit, and it maps to BEK 260 §74 on alternative communication for incident response.
3. Access methods
Which remote access methods does BifrostConnect offer?
BifrostConnect offers three access methods on one platform: Direct Native Access, Direct Tunnel Access and Clientless Tunnel Access, plus two file transfer modes, Direct File Transfer and Offline File Transfer. Direct Native Access gives browser-based KVM, serial terminal and SSH control of the endpoint with no software installed on either side. Direct Tunnel Access gives a WireGuard-based IP tunnel from a lightweight client on the technician’s computer to a Bifrost Unit in the OT environment. Clientless Tunnel Access is designed to provide IP or serial communication with no software on either side.
What is Direct Native Access?
Direct Native Access is browser-based, hardware-level console access (KVM, serial terminal and SSH) to a single endpoint through one Bifrost Unit, delivered as a WebRTC video stream with no network-layer connectivity. The technician’s computer never joins the OT network and has no IP path to any OT asset, which makes it the highest-isolation access method. It requires no software installation on either side, gives BIOS-level access, keeps production data on the premises, and can be enforced as view-only by removing the USB cable. It is one-to-one, needs video, mouse and keyboard I/O on the endpoint, and is latency sensitive.
What is Direct Tunnel Access?
Direct Tunnel Access is a WireGuard-based, identity-bound IP tunnel from a lightweight installed client on the technician’s computer (macOS and Windows) to a Bifrost Unit in the OT environment. Subnet mappings give scoped access to multiple endpoints and let several technicians work on the same endpoint in parallel, so it supports one-to-one, one-to-many and many-to-one patterns. Connectivity is session-scoped and unsolicited inbound traffic is blocked by default; the technician’s IP address never appears on the OT network. Subnet mappings become time-bound with Time-Based Access on the Advanced plan or Dedicated Cloud. Direct Tunnel Access does not include port-forwarding.
What is Clientless Tunnel Access?
Clientless Tunnel Access is designed to give you IP or serial communication between the technician’s computer and the OT endpoint without installing software on either side. It is intended for environments where the technician’s computer is not allowed to be online, and to provide a pure hardware security boundary that is only active while a session is live, for sites where the assurance level or a segmentation requirement during vendor access calls for it. Contact BifrostConnect to match it to your scenario.
Which BifrostConnect access method should I choose?
Choose Direct Native Access for screen-level work and Direct Tunnel Access when the technician’s own software must send IP traffic to the endpoint. Consider Clientless Tunnel Access where no software may be installed on either side and the technician’s computer may not be online. Direct Native Access fits commissioning, troubleshooting, rebooting or reinstalling operating systems, incident response, and any case where you want physical assurance that no data leaves the premises. Direct Tunnel Access fits engineering software on the technician’s computer, remote desktop to an engineering station, firmware uploads and multi-user access, where software may be installed on that computer and it may be online. The published guide’s rule: prefer Direct Native Access where the task allows, reserve Direct Tunnel Access for tasks that need IP-level interaction, and document the choice per task.
Can I transfer files with BifrostConnect?
Yes, through two dedicated modes: Direct File Transfer, an identity-bound and audited transfer over the Bifrost Unit’s outbound channel, and Offline File Transfer, an air-gapped media pattern for OT zones with no IP path. Offline File Transfer requires KVM access to the endpoint and/or a USB port that accepts an external drive; a KVM session on its own does not move files. Direct Tunnel Access sessions can carry files where the tunnel is configured for it. For regulated sites the guide recommends an inline file security gateway (multi-engine scanning and content disarm) ahead of vendor uploads.
Does BifrostConnect work with serial (RS232) devices and legacy PLCs?
Yes. The Bifrost Unit has a serial console port and brokers session-based access to a serial device behind it, so the technician never gets a flat IP path to the legacy device. The identity, time-bounding, recording and audit properties of the brokered session apply on the IP side between the technician and the unit; the serial side is a controlled extension of that session. For legacy platforms that cannot host any software, the guide’s pattern is to wrap the device behind a Bifrost Unit in a small dedicated VLAN and use Direct Native Access through whatever console the device offers, with no change to the device itself.
Will BifrostConnect work with all my devices?
BifrostConnect works with any device that supports KVM, IP communication over LAN, serial RS232 communication or SSH terminal access. For KVM the endpoint must accept a USB keyboard and mouse (HID over a single USB cable) and output video over USB-C, HDMI, DVI, VGA, DisplayPort or Mini DisplayPort; the Bifrost Unit supports 480p, 720p and 1080p.
Can one Bifrost Unit control several systems?
Yes. For KVM, one Bifrost Unit connected to a KVM switch can manage several systems. For IP-based work, Direct Tunnel Access subnet mappings give scoped access to multiple endpoints behind one unit and let multiple technicians access them in parallel.
4. Security, encryption and the hardware trust boundary
How is BifrostConnect traffic encrypted?
BifrostConnect encrypts the control plane with TLS 1.2 or 1.3, Direct Native Access sessions end-to-end with WebRTC DTLS-SRTP between the browser and the Bifrost Unit, and Direct Tunnel Access traffic with WireGuard. The WireGuard implementation uses ChaCha20-Poly1305 with Curve25519 key exchange and BLAKE2s, and private WireGuard keys never leave the technician’s client. The relay service operates as a TURN server and cannot decrypt the traffic it relays.
Can BifrostConnect see or store what happens inside my sessions?
No. BifrostConnect does not look at, store or handle production data; it only facilitates the secure transfer. The BifrostConnect Service relays session signalling and cannot decrypt session content, and Bifrost Manager handles access decisions only, with no access to production data or recordings. The telemetry BifrostConnect stores is limited to session duration and count, the WAN IP of the Bifrost Unit, approximate cell-tower location for 4G, battery and signal strength, traffic statistics and the unit’s serial number. No session content is stored and the Bifrost Unit has no GPS.
Does BifrostConnect log keystrokes or mouse movements?
No. BifrostConnect does not look at, store or handle production data, and that includes keystrokes and mouse movements; it only facilitates the secure transfer. The Service cannot decrypt sessions, and Bifrost Manager logs access events only (who, when, which unit, session start and end). Where a customer deploys AccessGuard or SessionGuard for audit evidence, they are designed to live-stream and record the session’s screen and keystrokes into storage the customer owns, and BifrostConnect cannot access that material; that is by design. The published guide’s principle is that session evidence must sit with the asset owner, not with the third party doing the work.
How is the Bifrost Unit itself protected against attack?
The Bifrost Unit runs a stripped industrial embedded Linux with no local users, no SSH, no local web services and no physical service or debugging ports, and it communicates only over port 443. Its system-on-chip secure-boot fuses are burnt at manufacture and are non-reversible, so the unit cannot boot alternative firmware; firmware updates are signed, verified on the unit before they are applied, delivered over the air only and postponed during active sessions. Unique device keys are generated and stored on each unit. A compromised unit cannot be reached inbound, cannot be logged into locally and cannot be re-flashed, which is why the guide treats the unit as a trust boundary a software agent on a customer host cannot match.
What multi-factor authentication does BifrostConnect use?
Bifrost Manager enforces multi-factor authentication on every administrator account through Auth0, and it cannot be disabled at organisation level. An Attended Bifrost Unit adds a physical factor: an 8-digit time-based one-time password generated on the device by a button press, with a 60-second default lifespan, entered together with the operator’s credentials. An Unattended Bifrost Unit authenticates the administrator with credentials plus multi-factor authentication in Bifrost Manager. Enterprise single sign-on (SAML 2.0, OAuth 2.0, Active Directory or LDAP via Auth0) is delivered on the Dedicated Cloud and on-premises tiers, so your own identity provider and its hardware-token or conditional-access policies can govern sign-in.
Is BifrostConnect a Zero Trust architecture?
BifrostConnect implements the per-session, closed-by-default access model that NIST SP 800-207 describes: access is granted per session (Tenet 3) and authentication and authorisation are dynamic and enforced before access is allowed (Tenet 6). No resource on the OT side listens for callers; the technician requests, Bifrost Manager decides against policy, and the Bifrost Unit opens the session outbound. The published guide also uses the joint CISA guide Adapting Zero Trust Principles to Operational Technology (29 April 2026) as a second anchor for the same principle.
What does BifrostConnect not protect against?
BifrostConnect does not protect against a vendor computer that is compromised before the session, a compromised identity layer, misuse inside an approved session, or threats outside the third-party access path. If a vendor laptop already carries malware, the session faithfully transports what the operator does; mitigations are vendor endpoint hygiene contracts, endpoint detection on the technician’s computer and preferring Direct Native Access so the computer gets no IP-level access. Recording and SIEM alerts support detection and revocation, not prevention, of misuse inside a legitimate window. Phishing of asset-owner staff, IT-side compromise pivoting through other paths, physical attacks on the unit and protocol vulnerabilities in the OT endpoint sit outside what a remote access broker can address, which is why the guide places BifrostConnect in a layered architecture with endpoint detection, OT intrusion detection and procedural controls.
What makes hardware-based remote access safer for critical equipment?
Hardware-based remote access through a Bifrost Unit reduces the attack surface because nothing on the OT side listens for an inbound connection. It removes the always-on tunnel, exposes no inbound port, keeps the technician’s computer off the OT network and moves the trust boundary onto dedicated hardware nobody logs into. Endpoints are never exposed to the internet, their IP addresses stay hidden and port scans through the unit are impossible because nothing listens inbound. Every session is tied to a named individual with multi-factor authentication, scoped to approved endpoints and bounded in time. A dedicated unit does not inherit the users, services, patch state and exploitable surface of a general-purpose host running a software agent.
5. Governance, recording and evidence
What is Bifrost Manager?
Bifrost Manager is the governance platform and control plane of BifrostConnect: it holds identities, groups, access policy, just-in-time access windows, the audit log and the SIEM integration. It handles access decisions only and never touches production data or session recordings. Its role model is least privilege: a Privileged User operates within assigned groups, an Administrator within the organisation, and any scope change requires an explicit role change. Multi-factor authentication is mandatory on administrator accounts, every administrator action is audit logged, and enterprise single sign-on is delivered on the Dedicated Cloud and on-premises tiers.
What is Time-Based Access?
Time-Based Access makes Direct Tunnel Access subnet mappings time-bound, so a vendor’s network path exists only inside an approved window instead of permanently. On the entry plan, Direct Tunnel Access subnet mappings are permanent; on the Advanced plan and the Dedicated Cloud tier, Time-Based Access converts the default-permanent posture to default-just-in-time. The published guide recommends it for organisations operating under NIS2 Article 21(2)(i) or BEK 260 §55 stk. 2, because it matches the Zero Standing Privilege principle.
Which Bifrost Manager deployment tiers exist, and which features need which tier?
Bifrost Manager is delivered on a common cloud (Plug & Play plan and Advanced plan), as a Dedicated Cloud, or on-premises. Time-Based Access for Direct Tunnel Access requires the Advanced plan or the Dedicated Cloud tier. Enterprise single sign-on (SAML 2.0, OAuth 2.0, Active Directory, LDAP) and native SIEM forwarding require Dedicated Cloud or on-premises. The guide advises procuring the right tier at the start so the single sign-on trust chain and the SIEM pipeline exist before the first vendor session.
What audit trail does BifrostConnect provide?
Bifrost Manager records authentication events, access grants and denials, session start and end, recording metadata and every administrator action, and ties each session to a named individual, because there are no shared accounts. On the Dedicated Cloud and on-premises tiers these events are forwarded natively to the customer’s SIEM. The audit trail is captured by the Manager and Service for every session; because the Service brokers every session, a session cannot be established while the Service is unreachable, so there is no un-audited degraded session.
What is AccessGuard?
AccessGuard is designed to give you station-level access governance on the customer’s own engineering station. It is intended to provide individual accounts with multi-factor authentication for every vendor technician, application-scoped access so the vendor can launch only the tools the work requires, and session recording kept in storage you control. It is intended for the scenarios in the OT guide where the programming software lives on a customer-owned station (Scenarios 1 and 2), and it will provide you with the station-local identity, approval and evidence controls that a small site without enterprise infrastructure otherwise lacks.
What is SessionGuard?
SessionGuard is designed to give you operator-side session evidence when the programming software lives on the vendor’s own laptop. It is intended to provide a recording of the technician’s screen and keystrokes during the session, delivered to storage the customer owns and controls, so the evidence is never under vendor control. It is intended for the OT guide’s Scenarios 3 and 4, where the vendor brings the licensed engineering tools, and it will provide you with per-engagement isolation so evidence from different vendor relationships never mixes.
Where are session recordings stored?
Where session recording is deployed, it is designed to land in storage the customer controls, never with BifrostConnect: on the OT network or engineering station, or on a customer-owned recording server. BifrostConnect cannot access the live stream or the recordings, and that is by design; Bifrost Manager has no access to recordings, and the BifrostConnect Service cannot decrypt session content. The published guide is explicit that session evidence must sit with the asset owner, not with the third party doing the work, and it recommends an acceptance test before go-live confirming that recordings land in customer-controlled storage.
Do session recordings create GDPR obligations?
Yes. Session recordings typically contain personal data within the meaning of the EU General Data Protection Regulation, so the recording policy must define a retention period, storage location and access control, data-subject rights handling and a lawful processing ground. These obligations apply whether or not the OT system is subject to NIS2, and the technical enforcement of recording does not remove them.
Does BifrostConnect integrate with my SIEM, identity provider, PAM, OT intrusion detection and data diode?
Yes, by co-deployment: BifrostConnect works alongside these tools rather than replacing them. Bifrost Manager exports natively to your SIEM (Dedicated Cloud and on-premises), federates identity through SAML 2.0, OAuth 2.0, Active Directory or LDAP via Auth0, and sits upstream of your PAM platform, which keeps credential vaulting and rotation. An OT intrusion detection system runs independently on the OT network and is correlated with BifrostConnect events at the SIEM; there is no API-level integration. A certified data diode provides one-way log export, one-way Historian replication and an inline file security gateway ahead of Direct Tunnel Access uploads.
6. Compliance: NIS2, Danish law, IEC 62443 and other frameworks
Does BifrostConnect make my organisation NIS2 compliant?
No single product makes an organisation NIS2 compliant; BifrostConnect maps to the technical measures in NIS2 Article 21(2) and provides the technical evidence, while the organisational controls remain yours. The measures it maps to are (d) supply chain security, (e) security in network and information systems, (i) access control policies and (j) multi-factor authentication, and its logs support the staged incident reporting in Article 23. For every technical control the published guide lists the organisational control still required: access control policy, supplier risk assessment, contract clauses, periodic access reviews and an incident response plan.
How does BifrostConnect map to the Danish NIS2 Act and BEK 260?
BifrostConnect maps to the Danish NIS2 Act (LOV nr. 434 af 6. maj 2025) §6 on identity-bound access and multi-factor authentication, and for energy entities to Lov om styrket beredskab i energisektoren §§6, 7 and 8 with the technical detail in BEK 260. The BEK 260 provisions the guide maps are §§29-32 (supplier procedures and remote access procedures for direct suppliers), §§51-53 (access control policy, access control and multi-factor authentication), §55 stk. 2 (remote access only during approved, time-limited work), §62 (network segmentation during vendor access), §§64-67 (logging, with §66 stk. 2 nr. 2 covering remote access equipment and §67 stk. 3 a 13-month retention at niveau 4-5) and §74 (alternative communication for incident response, met by the 4G/LTE out-of-band path). Where the guide interprets Danish wording, it follows the SAMSIK guidance on the NIS2 Act (June to August 2025).
How does BifrostConnect map to IEC 62443?
BifrostConnect maps to the IEC 62443-3-3:2019 system requirements that govern third-party access, and the guide anchors vendor programmes in IEC 62443-2-4:2024. The 3-3 requirements are SR 1.1 (human user identification and authentication), SR 1.13 (access via untrusted networks), SR 2.1 (authorisation enforcement), SR 2.6 (remote session termination), FR 5 (restricted data flow) and FR 6 (timely response to events). For vendors, the guide anchors Pattern D in IEC 62443-2-4:2024, the service provider security programme, with SP.07 Remote access. IEC 62443-2-1:2024 requires asset owners to run a full cybersecurity management system; the guide treats third-party access as one chapter of that programme, not the whole book.
Which frameworks does the OT Best Practice Guide anchor in?
The guide anchors in eight frameworks: the EU NIS2 Directive (2022/2555), the Danish NIS2 Act (LOV nr. 434 af 6. maj 2025), BEK 260 with Lov om styrket beredskab i energisektoren, the IEC 62443 series (3-3:2019, 2-4:2024 and 2-1:2024), NIST SP 800-82 Rev. 3, NIST SP 800-207, the joint NCSC Secure Connectivity Principles for OT (18 March 2024) and the joint CISA guide Adapting Zero Trust Principles to Operational Technology (29 April 2026). Part 2 additionally references the CER Directive (2022/2557) for supply chain supervision, DORA Articles 9 to 14 and 28 for financial entities, and GDPR for session recordings. Where a claim cannot be traced to a verified clause, the guide does not make it.
What evidence can I hand an auditor after a BifrostConnect deployment?
An auditor receives an audit trail in which every vendor session carries an individual identity, proof of multi-factor authentication, the approved time window, and session start and end. Where recording is deployed, the session recording sits in customer-controlled storage. On the Dedicated Cloud and on-premises tiers the same events are in the customer’s SIEM for correlation and staged NIS2 reporting. The published guide recommends documenting the acceptance test that proved each control operated as designed, and pairing the technical evidence with the written policies, supplier contracts and access reviews the regulation also expects.
What should we require from vendors in remote access contracts?
The published guide provides ten sample procurement clauses for third-party OT remote access, anchored in IEC 62443-2-4:2024 and BEK 260 §§30-32. They require session brokering with no direct network path outside an active session, multi-factor authentication on every session with one factor independent of the vendor, a security programme aligned with IEC 62443-2-4 SP.01 to SP.12, a cryptographic audit trail retained for at least 13 months, explicit time-bounded approval before each session, automatic and customer-initiated session termination, forced session recording stored under customer control, incident notification within 24 hours, support for the customer’s NIS2 Article 23 reporting, and return or destruction of all credentials within 30 days of termination. The clauses are drafting starting points, not a substitute for legal counsel.
7. Deployment scenarios and OT best practice
What are the four OT access patterns in the BifrostConnect OT guide?
The guide sorts third-party OT access into four patterns along two axes: site scale and where the programming software runs. Site scale means large OT with a SOC, SIEM and PAM versus small OT with no IT staff; the software runs either on a customer-owned station or on a vendor-owned laptop. Pattern A is large OT with a customer station (Scenario 2, lowest residual risk), Pattern B is large OT with a vendor laptop (Scenario 4, most layered defence), Pattern C is small OT with a customer station (Scenario 1, medium residual risk) and Pattern D is small OT with a vendor laptop (Scenario 3, highest residual risk). Each pattern has its own BifrostConnect product mix, and Direct Native Access is optional in all four for commissioning and incident response.
How can a small water utility with no IT staff give vendors secure remote access?
A small utility with no jump host, SIEM or SOC can meet the same regulatory clauses as a large one by placing five controls at the engineering station itself. The five are out-of-band identity verification, time-bound approval from the site owner, offline multi-factor authentication at the station, local session recording and one-way log export. The claim that a small site without enterprise infrastructure cannot meet NIS2 or the Danish energy-sector law is false; the fix is process design, not infrastructure investment. In BifrostConnect terms this is Scenario 1: an unattended Bifrost Unit at the boundary of the engineering station’s network, Direct Tunnel Access for the vendor, Bifrost Manager for access decisions and audit, and AccessGuard, which is designed to add the station-level identity, application scope and recording controls. The unit gives the site an outbound-only posture and a 4G/LTE out-of-band path for incident response.
What if the vendor brings their own laptop with the engineering licences?
A vendor-owned laptop at a small site is the highest-risk case in the OT guide, so the controls must sit at the boundary between the laptop and the OT equipment. The guide calls it Scenario 3, Pattern D, and its minimum viable controls are per-session multi-factor authentication across the chain, session brokering through a hardware appliance at the site so there is no direct VPN from the laptop, forced session recording outside the vendor’s machine regardless of where the licence lives, time-bound access measured in hours, and export of session logs to the asset owner. In BifrostConnect terms: an unattended Bifrost Unit as the gateway, Direct Tunnel Access or Direct Native Access for the vendor (Direct Native Access gives the laptop zero network access), Bifrost Manager for policy, and SessionGuard, which is designed to give you the operator-side recording delivered to customer-owned storage.
How does BifrostConnect fit a large OT site that already has a SOC, SIEM and PAM?
At a large site BifrostConnect takes the access-and-governance layer and integrates with the SOC, SIEM, PAM and identity provider that are already there. The Bifrost Unit sits at Purdue Level 3 or in the industrial DMZ, Bifrost Manager runs on Dedicated Cloud or on-premises with single sign-on to the enterprise identity provider and native SIEM forwarding, and vendor groups get just-in-time access windows. The existing PAM platform keeps credential vaulting and rotation, endpoint detection stays on the engineering stations, an OT intrusion detection system covers protocol-level inspection on the wire, and a certified data diode can carry one-way log export and Historian replication. These are Scenarios 2 and 4 in the guide; correlation of BifrostConnect events with the other tools happens in the SIEM.
Can BifrostConnect be used with air-gapped systems?
No, BifrostConnect is not designed to bridge an air gap; it hardens the perimeter around one. The Bifrost Unit needs an outbound connection to the BifrostConnect Service, so it sits on the IT side of the gap. On the IT side, a Bifrost Unit on the staging workstation that prepares signed media makes vendor access to that workstation identity-bound, time-bounded and recorded. On the OT side the human and procedural brokering stays in place: controlled media transfer, chain of custody and malware scanning through a data-diode file security gateway. Offline File Transfer covers the media movement itself. For genuinely isolated equipment the guide treats the air gap as the primary control and BifrostConnect as a supplement, never a replacement.
Where does the Bifrost Unit sit in the Purdue model?
Third-party access typically targets Purdue Levels 2 and 1, where engineering tools meet controllers, and the Bifrost Unit is placed at the boundary that protects them. In a large site that is Level 3 or the industrial DMZ at Level 3.5; in a small site it is the boundary of the engineering station’s network or the closed network around the PLC. The Purdue model runs from Level 5 (enterprise) through Level 4 (business logistics), Level 3 (site operations), Level 3.5 (OT DMZ with jump host or vendor proxy), Level 2 (HMI and SCADA) and Level 1 (PLC and RTU) to Level 0 (sensors and actuators), with blast radius increasing toward Level 0.
How does BifrostConnect support incident response and business continuity?
BifrostConnect gives incident responders a clean out-of-band path to the OT equipment over 4G/LTE, independent of the production WAN, so essential operations can continue while an IT-side compromise stays contained. Before an incident, Zero Standing Privilege, brokered access and recording form the control baseline; during response, Bifrost Manager approval plus the Bifrost Unit provide the responder path without opening any inbound exposure; during recovery, session recordings (where deployed) and a controlled rebuild path support forensics and restoration. The out-of-band path maps to BEK 260 §74 on alternative communication for incident response.
What are the first steps toward secure third-party OT access?
The OT guide recommends five actions in the first 30 days, none of which requires new procurement. Inventory every active third-party remote access path into OT; verify that default credentials have been changed on all jump hosts, VPN concentrators and shared accounts; enable session logging on the channels you already have; sort your assets into Patterns A to D; and plan the migration of every always-on tunnel toward time-bounded access. Days 30 to 90 introduce a session broker, multi-factor authentication and per-session approval; days 90 to 180 turn on recording and SIEM alarming; after 180 days the programme moves to vendor onboarding, contract clauses and joint incident playbooks.
Does BifrostConnect replace my existing security tools?
No. BifrostConnect occupies the access-and-governance layer for human sessions and is designed to co-deploy with specialists in the other layers. Keep endpoint detection and response on engineering stations, an OT intrusion detection system for protocol-level inspection, your PAM platform for credential vaulting, your industrial telemetry backbone for machine-to-machine data, and your zero trust network access platform for enterprise IT. The guide’s principle is defence in depth: no single control is load-bearing, and each layer stays with its specialist.
8. Hardware, connectivity and requirements
What are the Bifrost Unit’s technical specifications?
The Bifrost Unit measures 124 x 87 x 27 mm, weighs 249 g and runs for approximately two hours on its industrial UL2054-certified battery. It has a 2-inch TFT display, 6 GB of internal storage and IP20 classification. Connections are Ethernet RJ45 (10/100 Mbit, PoE charging), Wi-Fi 802.11n 2.4 GHz, a 4G LTE Cat-4 modem with a nano-SIM tray, RS232, HDMI (480p, 720p, 1080p), USB-C (video input, keyboard and mouse output, recharging), Micro-USB (recharging, keyboard and mouse, RS232 emulation, USB tunnel sessions), Bluetooth 4.0 and an SPDT relay output. Maximum power consumption is 9 W. It runs an industrial embedded Linux upgraded over the air, in either Attended or Unattended mode.
How does the Bifrost Unit connect to the internet: 4G, LAN or Wi-Fi?
The Bifrost Unit connects to the BifrostConnect Service over 4G/LTE, Wi-Fi or Ethernet LAN, always outbound on port 443. For 4G the unit takes a nano-SIM (IoT or M2M SIM recommended, roaming or non-roaming), the SIM must be provisioned with a static or public IP on the cellular network, the network must be IPv4, any PIN or PUK lock must be disabled and the default APN is “internet”. Wi-Fi is 802.11n 2.4 GHz with WPA or WPA2 PSK/AES. LAN is 10/100 Mbit Ethernet, full duplex. Hardware revision 1.0 covers the European LTE bands and revision 1.5 adds the North American bands.
What network and firewall requirements does BifrostConnect have?
The network the Bifrost Unit sits on must allow outbound traffic on port 443 with SSL/TLS and must not disable WebRTC over UDP; no inbound rules are required. If the network requires a proxy, the unit is configured in HOST mode and the BifrostConnect Service domains are whitelisted. A load balancer must be disabled for the unit, because the Service does not support dynamic changes of the unit’s WAN or LAN IP address. The same requirements apply on the operator side: the computer using the BifrostConnect web interface must allow WebRTC, which Chromium-based browsers enable by default.
Does the Bifrost Unit require a static IP address?
No static IP is required to reach the Bifrost Unit on the LAN, because the unit initiates every connection outbound. For cellular use, the SIM card must be provisioned with either a static IP or a public IP on the mobile network.
How is the Bifrost Unit powered and charged?
The Bifrost Unit charges over Micro-USB, over USB-C or over a PoE-compatible LAN connection (48 V), and runs for approximately two hours on its battery. The battery is an industrial UL2054-certified 3.7 V, 2000 mAh cell with a maximum draw of 9 W, and hardware revision 1.5 powers on automatically when AC or DC input is connected. The battery, together with the built-in LTE modem, is what gives the unit an out-of-band path that is independent of the customer network.
What happens when I connect the Bifrost Unit to a device?
Each port on the Bifrost Unit has a defined role, and connecting it needs no software on the target device. USB-C carries video input from the device plus keyboard and mouse output to it, and charges the unit. HDMI streams the device’s video output to the unit. Micro-USB provides keyboard and mouse, RS232 emulation and USB tunnel sessions. RS232 carries serial terminal and serial tunnel sessions. The Ethernet port carries network, PoE charging and IP tunnel sessions. Bluetooth 4.0 acts as a keyboard and mouse input.
Which browsers work with BifrostConnect?
BifrostConnect sessions and Bifrost Manager run in Chromium-based browsers: Google Chrome, Chromium and Microsoft Edge. WebRTC must be enabled in the browser, which is the default in Chromium-based browsers.
Which cables do I need for a Bifrost Unit?
For KVM, use a high-quality USB-C data cable (USB 3.1 Gen 2 or above) or an HDMI 2.0 shielded cable for video plus a Micro-USB data cable for keyboard and mouse. For a serial terminal, use a DB9 RS232 null-modem cable, a USB-OTG data cable for USB-based serial, or a console cable. SSH and IP tunnel sessions need a good-quality Ethernet cable, a serial tunnel needs a DB9 RS232 cable (sometimes null-modem), and a USB tunnel needs a Micro-USB OTG cable with the connected device either externally powered or able to run on 0.5 A. BifrostConnect recommends its own cables when troubleshooting video or network issues.
In which environments can the Bifrost Unit operate?
The Bifrost Unit operates between 5 and 40 °C, at up to 85 percent non-condensing relative humidity, at altitudes up to 3,600 metres, and carries an IP20 ingress protection rating. It must not be exposed to direct sunlight for prolonged periods, and firmware updates should be applied when they are published.
9. Guides, documentation and getting started
Where can I download the BifrostConnect OT Best Practice Guide?
Both parts of the guide are free downloads on bifrostconnect.com/tours/. Part 1 is “Framework for 3rd party access to OT” (version 1.21, June 2026, 43 pages, vendor-neutral, technically reviewed by Mikael Vingaard of ICSRange) and Part 2 is “Implementing BifrostConnect” (version 1.21, June 2026, 66 pages). Part 1 is at bifrostconnect.com/wp-content/uploads/2026/06/BEST-PRACTICE-GUIDE-PART-1_Framework-for-3rd-party-access-to-OT_v1.21.pdf and Part 2 at bifrostconnect.com/wp-content/uploads/2026/06/BEST-PRACTICE-GUIDE-PART-2_Implementing-BifrostConnect_v1.21.pdf.
What is the difference between Part 1 and Part 2 of the OT guide?
Part 1 is the vendor-neutral framework; Part 2 maps each of its controls to a BifrostConnect deployment. Part 1 covers the threat model, five core principles, four access patterns, compensating controls for legacy equipment, degraded-mode rules, a compliance crosswalk across five frameworks and ten sample procurement clauses, written so any defensible solution can be measured against it. Part 2 covers product mapping, per-scenario configuration, compliance evidence tables, co-deployment with SIEM, OT intrusion detection, PAM and data diodes, hardening of the trust boundaries, and an explicit list of what BifrostConnect does not protect against. Part 1 makes no claim that BifrostConnect is the only way to implement it.
What other BifrostConnect documentation is available?
The Tours and Tutorials page collects the product tours, the Security Documentation, the technical pages and the presentations in one place. It offers three interactive product tours (Bifrost Unit hardware guide, Bifrost Manager, and the browser-based Remote Access Interface), the Security Documentation (version 2.2.2), the Technical Requirements and Technical Specifications pages in the Knowledge Center, the Executive Summary and Company Presentation (July 2026), and a two-page brief on secured remote ad hoc support for OT machine stops. The Knowledge Center also carries the Release Notes.
How do I get started with BifrostConnect?
Start with a demo or a proof of concept: book a demo on bifrostconnect.com or call +45 70 60 20 56. A Bifrost Unit needs no software installation on the equipment it protects; it is connected to the target device or the closed network around it, given an outbound path over 4G, Wi-Fi or LAN, and paired with an access policy in Bifrost Manager. The published guide recommends deciding the Bifrost Manager tier, the recording layer and the access method per task before the first vendor session, and running an acceptance test as the go-live gate.