Skip to Content
Home / OT Security

OT.security by WALLIX: connect people to production, safely

PAM4OT is WALLIX's access platform built for industrial control systems. It secures remote maintenance, engineering access and file transfers without touching fragile legacy equipment.

Why OT access needs its own answer

Third-party exposure

Vendors and integrators reach PLCs and HMIs with little visibility. It is the leading attack path into OT.

Regulatory pressure

IEC 62443, NIS2 and NERC CIP require authentication, traceability and password management for industrial access.

Legacy, low-maturity systems

Controllers that cannot be patched or run agents are prime targets for state-backed attackers.

300+WALLIX OT customers worldwide
150+WALLIX partners specialised in OT
20+ yearsof PAM built first for an oil and gas refinery
24/7WALLIX support across Europe, the Americas and Asia Pacific

What PAM4OT covers

Secure remote access

Central HTTPS portal with MFA and approval workflows for every external OT session.

Universal Tunneling

PROFINET, S7, DNP3, IEC 61850 and other industrial protocols through the PAM proxy, with no jump servers.

Secure file transfer

SFTP with live antivirus and DLP analysis through ICAP, replacing USB sticks and shadow internet links.

VNC and SCADA support

Full VNC support, including overlays, for legacy SCADA and DCS consoles without disrupting sessions.

Password vault

Central control of OT credentials with rotation, session recording and a full audit trail.

Delegated vendor enrolment

OT teams onboard third parties themselves in real time, so maintenance is not blocked on IT.

  • Agentless
  • HTML5 access
  • Native SSH tunnel
  • Just-in-time access
  • On-premises, SaaS or hybrid
  • CSPN certified
  • IEC 62443-4-1 in progress

Where WALLIX sits in your plant

We design PAM4OT around the Purdue model. The Bastion and Access Manager sit in the industrial DMZ, so no user reaches the control network without passing through them.

Engineering tools such as TIA Portal keep working through Universal Tunneling, and the seamless connection mode needs no admin rights on the engineer's laptop.

How we run OT projects
Level 4
Enterprise: ERP, email, web servers
Level 3.5
Industrial DMZ: WALLIX Bastion and Access Manager, AV decontamination, patch server
Level 3
Operations: MES, historian, Active Directory
Level 2
Supervision: SCADA, HMI, engineering stations
Level 1
Control: PLC, safety PLC, RTU
Level 0
Field: sensors, valves, pumps, robots

WALLIX in the field

Published WALLIX OT references, summarised.

European aerospace manufacturer

One secure entry point for external maintenance experts across 11 plants in Europe and Japan: 650 critical shop-floor machines, 180 remote connections and 99.99% uptime, run by WALLIX in its cloud.

Global electric utility

Internal and external privileged access to 22 industrial sites controlled through WALLIX Bastion, with evidence of every sensitive operation.

Bonduelle, food processing

Contractor access to SCADA, PLC and supervision systems brought under control by a small team, with passwords managed despite high contractor turnover.

SIAAP, water treatment for Greater Paris

Contractor access to critical SCADA equipment approved, recorded and traced, replacing unsecured jump servers between IT and OT.

WALLIX OT customers worldwide include

QatarEnergyTotalEnergiesSaudi Electricity Co.ArcelorMittalFramatomeSUEZRATPParis AéroportBonduelle