A smart meter goes on a wall and stays there for 15 years. It has no spare memory, no operating system worth patching, and no way to run a security client. The substation RTUs and grid sensors around it are built the same way. Then an auditor asks the utility to prove that third party access to those devices is controlled, logged, and revocable.
At most utilities the answer is still a VPN. It was the answer in 2010, and nothing has replaced it since.
A VPN builds an encrypted tunnel between two points and authenticates whoever holds the credentials. For a laptop reaching a corporate file share, that is a reasonable design. For a metering estate it creates four specific problems.
A VPN needs client software at both ends of the tunnel. A residential meter does not run one. Neither does an RTU or a grid sensor. So the tunnel terminates upstream, at a concentrator or a head end gateway, and everything behind that termination point sits on a flat network. The meters end up inside the tunnel without ever being authenticated by it.
Once a session is open, the credential holder reaches whatever the route allows. A meter reading contractor who needs 400 devices in one region receives the routing table. Restricting that means firewall rules someone has to write, maintain, and later prove to an auditor.
Flat networks let a compromised device talk to its neighbours. On a metering estate the neighbours number in the hundreds of thousands. A VPN concentrator records that a session opened. It does not record which devices spoke to each other once it did.
NIS2 auditors ask which supplier reached which device, when, and what they did there. VPN logs answer the first half of that question at best. They show an authenticated session from an IP address. They do not show the commands issued to a meter.
Three separate layers do the work a VPN was asked to do alone. Keeping them separate matters, because a procurement team will be told by someone that a single product covers all three.
Every meter and grid device carries an identity that exists before it reaches a network. That identity is what policy attaches to. A device with no identity of its own inherits the trust of whatever it sits behind, which is how flat metering networks happen in the first place.
SecureNet is private networking. Device traffic routes over a private APN with a static or dynamic private IP and lands directly in the utility data centre or in AWS, Azure, GCP, or Alibaba. The public internet is removed from the path rather than encrypted across.
Private networking on its own is not security. A private APN hides traffic but does not defend it. Inside the APN the estate remains flat unless something enforces policy.
Enforcement sits in the network and the cloud, not on the meter. IXT delivers Zscaler ZTNA through the SIM, so devices initiate traffic outbound and no ports are exposed inbound. Each device reaches the specific application it is authorised to reach and nothing else. Illumio maps the traffic in real time and flags behaviour that does not match the policy.
In IXT's model, "Zero Trust SIM" means those three things together: SIM identity, SecureNet private networking, and a Zero Trust layer enforced at the network layer.
Most utilities run a mixed estate. Meter vendors, head end system suppliers, substation automation vendors, and metering service providers all need to reach their own equipment. A VPN grants each of them a route into the network and then relies on rules to hold them there.
Privileged Remote Access replaces that. A vendor engineer opens a browser session to one device, brokered through the Zero Trust Exchange. The session is time limited, recorded, and co-viewable by the utility's own engineer. No client software is installed on the vendor's machine and no IP route is granted into the estate.
For an audit, the useful part is the recording. The question stops being which supplier held a credential and becomes what that supplier did on that device at 14:20 on a Tuesday.
Energy is in scope as a highly critical sector, and NIS2 places accountability at board and C-suite level. That changes who owns the answer.
IXT Zero Trust addresses the Article 21(2) technical controls: access control, network segmentation, incident detection, supply chain access, audit trail, and continuous authentication. Grid device access sits squarely inside supply chain access, which is where most utilities have the least evidence today.
Be clear about the boundary. IXT Zero Trust does not make a utility NIS2 compliant on its own. Risk documentation, incident response plans, staff training, and supplier governance frameworks remain the utility's responsibility. Zero Trust supplies the technical controls and the evidence. It does not supply the programme around them.
Replacing legacy VPNs on a metering estate sounds like a field operation. It does not have to be one, because the change happens in the network rather than on the meter.
Yes. That is the reason it applies to metering at all. Standard Zero Trust deployments assume an agent on the endpoint. Meters and RTUs have no agent to install, so enforcement moves to the network and the cloud instead. The device does nothing differently.
A private APN keeps traffic off the public internet, which matters. Inside it, the network stays flat and unmonitored. Segmentation, traffic visibility, and session level enforcement are separate work.
Devices with an IXT SIM move onto the new model without physical access, because identity and policy live in the network. Devices on another provider's SIM need a connectivity change first, which for most utilities happens at the natural replacement point.
Browser based access needs no software on the vendor's side and no hardware on the utility's. The work is defining which vendor reaches which devices, during which hours, and who reviews the recordings.
No. Zero Trust produces the session data and the traffic map. Detection, response, and the people who run it stay where they are. The two feed each other.
Most connectivity platforms report SIM status and usage on a 24 to 48 hour delay. The IXT CMP shows every SIM live: status, usage, location, session logs. When a district of meters goes quiet, the delay decides whether the utility finds out today or on Thursday.
If the metering estate still runs on tunnels terminating at a concentrator, the vendor access path is the place to look first. It carries the most risk, produces the least evidence, and changes without touching a single meter.
Ask us how it works for your deployment. Book a demo at ixt.io