New capabilities help eliminate blind spots and extend secure, identity-based access across operational environments without disrupting workflows—helping secure every remote session, application, and device connected to critical infrastructure.

Cyolo, a leading provider of secure remote privileged access for operational technology (OT) and cyber-physical systems (CPS), has announced the launch of several major new capabilities, headlined by Cyolo Third-Party VPN Control (patent pending). This groundbreaking feature within the company’s Cyolo PRO (Privileged Remote Operations) solution delivers visibility and access control for enforced third-party VPN and direct connections—without requiring changes to production infrastructure or vendor workflows.
In today’s increasingly connected industrial environments, even organizations with mature security programs face a critical blind spot: third-party connections they cannot govern or even see. Some vendors insist on using their own legacy VPNs, site-to-site tunnels, or proprietary “black box” gateways on OT networks, forcing plant managers and industrial operators to accommodate external methods that operate outside of their control. These opaque and unmanaged pathways pose significant risks, leaving organizations unaware of who is connecting, when, where, and what activities are occurring inside their most sensitive networks.
The new Third-Party VPN Control capability helps close this gap by enabling visibility and access policy enforcement—even when externally managed VPNs or hardware gateways are used.
This Cyolo PRO release includes additional enhancements tailored to address critical access and collaboration needs in cyber-physical environments:
Instant Collaboration Link: A browser-based, one-time secure link enabling session owners to invite multiple external participants (e.g., vendors, auditors, and engineers) into RDP, SSH, or VNC sessions with security controls—no agent installation required.
Secure Remote Assistance: Native, secure technical support for both user-initiated and helpdesk-initiated sessions, allowing organizations to deliver timely assistance while maintaining complete security and operational governance.
Asset Access Hub: Offers a comprehensive view of assets across various business contexts (e.g., function, vendor) and technical attributes (e.g., IP address, zone, access status), enabling administrators to assign accurate, role-based permissions efficiently.
As always, Cyolo PRO integrates seamlessly with legacy remote connectivity setups and supports Zero Trust principles by segmenting access.
“With today’s virtual environments, third-party vendors are essential for the unbroken continuity of industrial operations and critical infrastructure—both vital for the economy and national security. However, third-party access methods too often introduce unacceptable risks,” said Almog Apirion, CEO and Co-Founder of Cyolo. “We are always thinking about the real-world challenges our customers face and endlessly innovating to solve those problems. This latest advance represents the next step in the transformation of OT and CPS access—making it more agile, secure, and seamless for administrators and end users, without forcing vendors to change the tools they rely upon.”
With these advanced new capabilities, organizations gain:
Zero Trust for VPNs: Segments and restricts third-party access to approved assets, reducing lateral movement risk.
Access Visibility: Real-time insight into incoming access sessions.
Compliance-Ready Architecture: Aligns with NERC CIP, ISA/IEC 62443, ISA99, and NIST 800-82 standards.
Broad Compatibility: Integrates with all legacy remote connectivity suppliers.
These updates underscore Cyolo’s commitment to delivering flexible, secure access solutions tailored for the evolving needs of industrial and critical infrastructure environments.