®
  • Home
  • Company
    • Overview
    • Customers
    • Careers
  • Platform
  • Industries
    • Mobile Network Operators
    • Enterprise Overview
    • Automotive
    • Campus
    • Logistics
    • Manufacturing
    • Mining
    • Oil & Gas
    • Ports
    • Utilities
  • Resources
    • Press Releases
    • Blogs
    • Downloads
    • Events
  • Partners
    • Partner Program
    • Partner Portal
  • Connect
  • Home
  • Company
    • Overview
    • Customers
    • Careers
  • Platform
  • Industries
    • Mobile Network Operators
    • Enterprise Overview
    • Automotive
    • Campus
    • Logistics
    • Manufacturing
    • Mining
    • Oil & Gas
    • Ports
    • Utilities
  • Resources
    • Press Releases
    • Blogs
    • Downloads
    • Events
  • Partners
    • Partner Program
    • Partner Portal
  • Connect
Facebook Twitter Instagram Youtube Linkedin

Protecting Industrial IoT with Expeto and ZTNA

December 8, 2021 /Posted byBrian Anderson

Part 6 of 8: Pairing Expeto with ZTNA for Device to Application Trust

Virtual Private Networks (VPN) are dead.  Long live the VPN ?  There is much confusion when it comes to the best methods of protecting IoT data at rest and inflight.  For years, setting up a VPN over public internet or even on private circuits was seen as “just how it’s done”.  

The Old Way

VPNs provide point-to-point connections between networks that allow devices to communicate using a supposedly “trusted” transport method.  However, the VPN often allows for lateral movement on, queries about and possible packet capture as a side effect of being “on the network”.  This is a problem – and one that is often overlooked in the world of Shadow Operational Technology (OT).  When business units deploy Shadow OT solutions without consultation from IT, any given vendor could recommend using a VPN with little consideration of risk because “that’s just how it’s done”.

The New Way

Expeto Wireless mitigates part of the Enterprise risk equation for Shadow OT by offering the Enterprise full control over a trusted underlay network using cellular connectivity.  However, there is often still an urge to put a VPN overlay network on top.  Zero Trust Network Access (ZTNA) provides an alternative.  Most industrial sensors or other OT devices have a specific purpose and report data to a specific application such as an IoT Broker service.  ZTNA can set up an application to device trust association on demand.  Various metadata properties from the user, device and – with Expeto – even the cellular network can be used to enforce intent based policies.  ZTNA does not put the device “on the network”, it provides a software defined perimeter allowing secure access to applications without exposing them to the broader network.  Lateral movement, queries and other hijinks are forbidden.

What about data sovereignty and strict regulatory obligations, including privacy?  Many business verticals have strict rules around where and how data can flow.  In Australia, for example, certain critical infrastructure is forbidden from traversing the public internet or leaving the country.  Healthcare also offers many classic cases where strict data privacy control must be met.  Using a generic SIM card with a generic ZTNA service may unknowingly violate these obligations resulting in serious repercussions.  Why?  The flow of data is not deterministic and auditable.  

The trusted network underlay offered by Expeto empowers the Enterprise to control and attest to the known path data will travel.  ZTNA creates a dynamic trust association between the application and the device to ensure data is protected by policy and encrypted along the path.  Expeto users can even terminate data directly onto a hyperscaler service of their choice along with ZTNA services also within their own domain.  This combination ensures the device to application trust relationship is intact without ever touching the public Internet.

Put Your Trust in Expeto

As digital transformation continues to gain momentum in the industrial space, more and more devices will be added to the enterprise domain of attestation and accountability.  Corporate IT may not always be directly involved in specific solutions from 3rd party vendors.  Standardizing on a data communication platform that offers full enterprise control from SIM to server reduces the attack vectors and residual risk by default.  Policy enforcement can be set up with support from Corporate IT and Security, then broadly deployed to in-house IT and 3rd party Shadow OT devices with far less worry so long as both use the enterprise standard issue SIM card with ZTNA enabled.

Expeto offers the experience, expertise and an Enterprise First platform to deploy and manage public and private networks according to mission critical business needs.


To read more in Brian Baird’s Shadow OT series, click below!

      • Shadow OT Is Coming. Are You Prepared?
      • Shadow OT in Telecom. Friend or Foe?
      • From Surviving to Thriving Family Farms with Private Mobile Networks
      • Retailer Resilience in the Age of Amazon
      • Shadow OT in the Age of Covid-19
      • Race Ahead with Expeto
Tags: Data Security, enterprise, IoT, Shadow OT
Customer Challenges are Gifts ...
Customer Challenges are Gifts – Be Thankful
What Would Tony Stark Do?

Related posts

Read more

The Expeto Advantage for Enterprises: Overcoming the Limitations of Traditional Mobile Connectivity

March 18, 2025
In today’s rapidly evolving business landscape, enterprises are increasingly reliant on mobile connectivity to power critical operations across geographically distributed locations. However, traditional APN-based solutions... Continue reading
The Expeto Advantage for Mobile Operators: Unlocking New Value in the 5G Era
Read more

The Expeto Advantage for Mobile Operators: Unlocking New Value in the 5G Era

February 28, 2025
In today’s competitive telecommunications landscape, mobile operators face increasing pressure to maximize their network investments while meeting evolving enterprise demands. The Expeto platform offers a... Continue reading
Seamless Device Activation at Scale: How a Global MVNO Managed Peak Holiday Demand
Read more

Seamless Device Activation at Scale: How a Global MVNO Managed Peak Holiday Demand

February 12, 2025
A global MVNO faced the challenge of activating over 35,000 devices across multiple continents during peak holiday demand. Traditional telecom solutions couldn't scale to meet... Continue reading
Read more

Coverage Capacity and Control: Why Collaboration between Enterprises and Mobile Operators is Essential for Industry 4.0

November 5, 2024
Simplifying Mobile Network Connectivity for Next-Generation Devices We’re moving into an era where business operations and profitability depends on automation using connected devices. Ensuring seamless... Continue reading
Read more

Revolutionizing Enterprise Connectivity: The Power of Hybrid Mobility

September 18, 2024
In an era where the number of connected assets is skyrocketing, enterprises are seeking cutting-edge connectivity solutions to ensure peak performance. These solutions must cater... Continue reading

Comments are closed

With Expeto
You’ve Got Connectivity Covered

See Features & Benefits

Copyright © 2025 • Expeto, Inc. All Rights Reserved. Privacy Policy

  • USD / $
    • EUR / €
    • This is just for demo
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Do not sell my personal information.
Cookie SettingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT