Executive Summary
With new requirements from the North American Electric Reliability Corporation’s Critical Infrastructure Protection (NERC-CIP) standard looming, a leading power generation company faced a strict compliance deadline with no clear solution. Their legacy remote access tools were inefficient, costly, and non-compliant. They needed a fix—fast. Enter Xona: a secure, centralized, and effortlessly deployed platform that transformed their access control strategy in days.
The Challenge
A leading power generation company was facing a deadline to comply with new NERC-CIP-003-9 regulations. Their existing remote access solution – built around legacy VPNs – was cumbersome, difficult to manage, and vulnerable to attack.
Their Key Challenges Included:
- Regulatory Gaps – The latest NERC-CIP updates included stricter remote access requirements, yet their existing tools lacked the necessary offline MFA and centralized access controls.
- Inefficient Access Management – Disabling user access required manual intervention, creating security risks and compliance headaches.
- High Operational Costs – Maintaining secure remote connections across 70+ sites meant frequent on-site IT visits, driving up expenses and response times.
- Security Exposure – VPN-based access left critical assets vulnerable to transient endpoints, increasing the attack surface.
With compliance deadlines approaching, they needed a modern, secure, and scalable solution—one that would not only meet regulatory requirements but also improve operational efficiency across their distributed infrastructure.
XONA SOLUTION
The customer selected the Xona Platform to address their compliance and security needs. Unlike traditional VPN-based solutions that require complex configurations and expose critical systems to insecure user endpoints, Xona operates with zero-trust principles and completely isolates insecure user endpoints from critical systems. Further, dedicated remote access capabilities and having on-premise multifactor authentication (MFA) with no external connectivity were key differentiators aligned with the NERC-CIP requirements.
The customer deployed Xona across approximately 70 sites in a matter of days. By pre-configuring the Xona devices, the customer’s cybersecurity team could ship them to remote locations and have local staff quickly get them up and running. This streamlined deployment approach has saved considerable time and resources compared to traditional on-site implementation.
The customer quickly discovered they could take advantage of other Xona capabilities during their deployment. With Xona’s secure file transfer capabilities, the customer can store site recovery data for quick recovery of devices in the event of a disaster recovery scenario.
Xona’s centralized access management capabilities have also significantly benefited the customer. The customer can now quickly provision, monitor, and terminate user access to critical assets, ensuring compliance with NERC-CIP standards. Additionally, Xona’s offline MFA capability has provided an extra layer of security that further strengthens their security posture. Using the Xona solution, the customer can now securely and remotely manage and troubleshoot issues across their distributed sites, reducing the need for costly on-site visits and improving overall efficiency.
THE XONA DIFFERENCE
Meets Regulatory Compliance Requirements for Secure Remote and Local Access
Increases Cost Savings and Improves Overall Efficiency
Protects Critical Infrastructure and Data with Centralized Access Management
Customer Testimonials
“Xona has allowed our lean IT team to manage and troubleshoot issues remotely across all our sites. This has reduced the need for costly on-site visits and improved our overall operational efficiency.”