SaiFlow and Palo Alto Networks Partner to Deliver Zero Trust Secure Remote Access for Distributed Energy OT Networks

Ron Tiberg Shachar
and
,
Ron Tiberg Shachar
Sep 2026
XCharge C6 SLAC Exploit Flow

Overview

Distributed energy OT sites - solar, wind, battery energy storage systems (BESS), substations, and EV charging infrastructure - require frequent remote access for operational support, commissioning, maintenance, and repair by technicians, vendors, and support engineers. Because these sites are decentralized, multivendor, and distributed across regions and countries, granting and managing that access securely has become one of the hardest operational problems energy operators face.

To close this gap, SaiFlow and Palo Alto Networks have partnered to deliver secure, zero trust remote access purpose-built for distributed energy OT sites and devices - unifying technician and vendor access, privileged session brokering across a global multivendor fleet, and zero trust network connectivity into a single workflow.

The Challenge

Traditional approaches to remote access - static VPNs, shared credentials, and ad hoc file transfer tools - create broad, persistent attack surfaces that don't provide session visibility or accountability. They also make it difficult to consistently enforce least-privileged access across a large, globally distributed fleet. Energy operators need a way to grant fast, auditable access without compromising security or operational continuity.

The Joint Solution

The integration scopes and approves every remote session using real-time OT device and site context, correlates live session activity with energy telemetry to detect irregular behavior, and natively supports distributed energy protocols. Three components work together end to end:

  • SaiFlow Energy Runtime Security Platform - the session broker at the center of the workflow. Because SaiFlow natively understands protocols including Modbus, DNP3, OPC UA, MQTT, MMS, and OCPP, it scopes and approves every access request using site, device, user role, and network identity. Once a session is live, SaiFlow correlates technician activity with real-time energy telemetry to verify that session activity aligns with the asset's actual behavior.
  • Palo Alto Networks Idira® - a next-generation identity security platform built on Palo Alto Networks' privileged access management foundation. Idira extends zero standing privileges (ZSP) to every identity, including external vendors and technicians, eliminating VPN and bastion dependencies in favor of browser-based, just-in-time (JIT) access scoped to a specific task. Every session is isolated and fully recorded for audit and compliance.
  • Palo Alto Networks Prisma® Access - the Palo Alto Networks SASE solution, securing every remote connection with consistent, cloud-delivered policy. Traffic is encrypted on every leg of the journey, decrypted and inspected in the Prisma Access cloud against SWG, FWaaS, CASB, ZTNA, and threat prevention policies, then re-encrypted and forwarded - ensuring consistent inspection regardless of where users connect.

Together, sessions are requested via SaiFlow, which scopes access to the site and device and routes it to Idira for JIT, ZSP approval, and session recording. Prisma Access decrypts, inspects, and re-encrypts traffic in the cloud, keeping every leg encrypted en-route to site control systems, managed network switches, and energy OT/IoT devices such as solar, wind, BESS, inverters, and substations. At the site, only the existing IPsec/VPN gateway is required - typically a Prisma SD-WAN device or site router - so there's no SaiFlow hardware to deploy or maintain, enabling rapid fleet-wide scale without truck rolls.

__wf_reserved_inherit
Joint solution architecture for secure remote access

Key Benefits

  • Eliminate standing remote-access risk with just-in-time, task-scoped access to distributed energy OT sites.
  • Replace VPNs and shared logins with a single console to manage every remote session across multivendor, global site fleets.
  • Close the blind spot between login and action by tracking both who logged in and what actions they take.
  • Go beyond generic access control to approve every session with site, device, and grid-edge telemetry context.

Real-World Use Cases

Secure JIT Remote Access

External vendors and technicians need access to distributed energy OT sites across global regions, but that access is often broad, persistent, and poorly audited - forcing operators to choose between blocking essential work or accepting unaudited standing access to critical sites. With the joint solution, SaiFlow brokers every remote access session end to end, enforcing Idira JIT access, ZSP, and full privileged session recording. Each session is encrypted from the technician's browser to Prisma Access, inspected against ZTNA and threat prevention policies, and re-encrypted before reaching the site, giving operators a single, auditable workflow for operational support, guided assistance, remote commissioning, and remote repair - without granting persistent access to any individual site or device.

Secure Northbound and Southbound File Transfer

Keeping energy sites current requires constant file exchanges - OS, firmware, and diagnostic data updates - that are hard to manage securely at global scale, and traditional tools often can't verify file integrity or show which user or session initiated a given transfer. In the joint solution, every file transfer moves through the same brokered session as interactive access, inheriting the same security controls: Prisma Access scans files for malware and enforces DLP policy before they reach or leave the site, while Idira ties each transfer to the privileged session, user, and device for a complete audit trail. Southbound, operators push OS updates, firmware, and configuration changes to site systems and OT/IoT devices; northbound, logs, diagnostics, and monitoring data return through the same channel for centralized reporting - delivering a verifiable chain of custody without a separate file-transfer tool.

Stronger Together

By combining SaiFlow's energy-native session brokering with Palo Alto Networks' identity security and SASE capabilities, energy operators gain a single, auditable way to grant fast, contextualized remote access - without the standing risk of VPNs and shared credentials, and without compromising operational continuity across a global, multivendor fleet.

Table of Contents