Your IoT devices are exposed.
NIS2 expects you to close that gap.
IoT fleets still run on flat VPNs and exposed IPs. That raises the risk of lateral movement and makes third-party access hard to audit. NIS2 places that expectation on your board directly: adopt Zero Trust principles, network segmentation, and strong identity controls. IXT delivers this shift, from SecureNet's private networking to Zero Trust enforcement at the network edge, without exposing a single device to the internet.
Why Zero Trust
No exposed attack surface Devices and applications stay off the public internet. No open VPN gateways. Every session is inspected and enforced before it reaches your systems.
Least privilege by design Each device gets access only to the application it needs, per session. That follows the zero-trust tenets in NIST SP 800-207.
No lateral movement Segmentation and app-specific paths replace the old model, where anything inside the tunnel was trusted. One compromised device stays contained.
Controlled third-party access Approve only the flows a device needs, for example MQTT or OCPP to defined destinations. Grant time-bound access to a single device or session, and keep a full record of it.
Zero Trust, from access to audit trailSection subhead: Four layers that close the gaps VPNs and flat APNs leave open.
Zero Trust Connectivity, powered by Zscaler ZTNA
No exposed ports. No VPN clients. Nothing to attack. IXT Zero Trust Connectivity eliminates the attack surface by making all traffic device-initiated, with no exposed ports and no VPN clients required on devices. It runs on top of IXT SecureNet's private network layer, then adds per-session enforcement. Every connection routes through the Zscaler Zero Trust Exchange. Nothing connects in. Devices and applications reach only what they're authorised to reach.
Zero Trust Visualisation, powered by Illumio
See every device. Catch what shouldn't be there. IXT Zero Trust Visualisation maps all device traffic in real time, detecting anomalies and enforcing segmentation to contain threats before they spread. You see which devices talk to which endpoints, across the entire fleet, including headless devices that can't run an agent. When a device starts communicating with an unexpected destination, you get an alert.
Privileged remote access
Give a vendor access to one machine, not your whole network. Service technicians and third-party vendors get browser-based access instead of a VPN client. SSH, VNC, and RDP sessions run in the browser, time-limited and fully recorded. No client software to install. No broad network handed to a vendor because access to one machine required it.
Policy-based segmentation
Contain a breach before it spreads, and prove it to auditors. Policy-based segmentation contains a breach to a single device. One compromised sensor doesn't become a route into the rest of your fleet. NIS2 places personal liability at board and C-suite level. IXT Zero Trust addresses NIS2 Article 21(2) technical controls: access control, network segmentation, incident detection, supply chain access, audit trail, and continuous authentication.
The executive risk view
IoT fleets still traverse public networks, flat VPNs and exposed IPs. That increases lateral-movement risk and leaves third-party access hard to audit.
Under NIS2, leaders are expected to adopt zero-trust principles, network segmentation, and strong identity & access management as part of risk-management measures. Translation: move from network trust to per-session, least-privilege access, without exposing devices to the internet.