
Cyber-Physical Systems (CPS) Security
Dispel Zero Trust Engine
Secure remote access for OT and industrial control systems with sub-30-second connections.
Dispel Zero Trust Engine Overview
What it does
Dispel Zero Trust Engine is a secure remote access and connectivity platform for operational technology (OT), industrial control systems (ICS), and cyber-physical systems from Dispel, founded in 2014 by Ethan Schmertzler (Co-CEO) and Ian Schmertzler (President) and headquartered in Austin, Texas with offices in New York, Washington DC, and Tokyo. The company has raised $28M in total funding, pioneered network-level Moving Target Defense (MTD) technology with 43+ patents, and was recognized as 2024 Cyber Defense Magazine Hot Company in Zero Trust Platform category and 2017 Gartner Cool Vendor.
How it works
The platform provides three core capabilities across a unified solution: OT Secure Remote Access enables sub-30-second connections to mission-critical assets (vs. traditional 7-12 minute connection times), replacing complex jump servers and VPNs; OT Data Streaming enables secure, encrypted real-time data transfer between industrial assets and cloud analytics for predictive maintenance and AI; and OT Threat Monitoring delivers 24/7 SOC protection with anomaly detection, session recording, and SIEM/SOAR integration. The proprietary Moving Target Defense technology continuously mutates attack surfaces by dynamically changing network configurations, IP addresses, and infrastructure in real-time, creating ephemeral, compostable infrastructure that prevents persistent footholds. The platform supports all 65,000+ TCP/IP protocols including SSH, RDP, VNC, and proprietary OT protocols (Modbus, DNP3, BACnet, OPC-UA), with OTFusion capability unifying fragmented OT DMZ architectures to reduce operational complexity by 30%.
Credentials and traction
Dispel Zero Trust Engine holds SOC 2 Type II and ISO 27001 certification. Dispel was named a Gartner Cool Vendor in Cyber-Physical Systems Security, 2025, and is listed as a Representative Vendor in the 2026 Gartner Market Guide for Cyber-Physical Systems Secure Remote Access. The company also received a 2026 Global InfoSec Award for Hot Company in Secure Remote Access. Dispel secures remote access across electric utilities, water and wastewater, oil and gas, manufacturing, defense, and federal agencies.
Key Capabilities
mapped to solution categoriesBrokers remote access for third-party vendors, OEM technicians, contractors and internal engineers with just-in-time provisioning, time-limited credentials, per-asset and per-session least privilege and approval workflows, replacing always-on VPN and jump-host access to OT networks.
Monitors remote sessions in real time so that supervisors can watch, join or terminate them, and records every session with full protocol-level capture for forensic review and regulatory compliance, without introducing latency that would affect OT system operation.
Provides secure remote access to OT environments with no internet connectivity using a data diode-compatible or hardware broker architecture, without requiring an internet-connected OT network.
Moves files such as firmware, patches and project files into and out of OT sessions through a controlled transfer channel that scans every file for malware before release, replacing USB media and unmonitored uploads.
Brokers native engineering-tool sessions (vendor programming software, RDP, VNC, SSH and OT protocol tunnels) so that remote engineers and OEM technicians can perform hands-on operations, maintenance and firmware upgrades on equipment, not only view-only or jump-host access.
Checks endpoint health (OS patch level, EDR presence, disk encryption, certificate validity) at each access request, enforcing minimum device security standards before granting application access.
Re-evaluates user and device trust signals throughout an active session, revoking or stepping down access when anomalous behavior is detected, not just at authentication time.
Grants access to individual named applications rather than network segments, users and devices can only reach explicitly authorized applications regardless of network position.
Provides access to browser-based internal applications through a reverse proxy without requiring a device agent, enabling secure access from unmanaged or contractor devices.
Routes web application access through a remote or local isolated browser to prevent malicious content on application pages from reaching the endpoint.
Hides internal applications from the public internet and unauthorized users, accepting inbound connections only after the trust broker authorizes a named user and device.
Classifies discovered assets and traffic flows into Purdue Model levels (Level 0-4), supporting IEC 62443 zone and conduit documentation and compliance assessment.
Connects OT security to enterprise security operations either as a single converged console for IT and OT or through integration paths into SIEM, SOAR, ITSM, CMDB, NAC and firewall tooling, forwarding alerts and asset data with OT context (asset criticality, Purdue level, process impact) preserved so that SOC analysts can act without OT specialization. Assign only when integrations preserve OT context or run bidirectionally; basic syslog forwarding is standard across the niche.
Baselines normal device communication patterns (command frequency, connection pairs, timing) and operational state, alerts on deviations that indicate reconnaissance, manipulation or lateral movement, and rates severity by asset criticality and process impact rather than by anomaly size alone. Products differ in whether baselines self-tune over time to operational and environmental changes or require ongoing manual tuning.
Controls local and remote user access to OT assets through brokered, identity-verified sessions with live monitoring and full audit trails, either as a native platform capability or by integrating with and monitoring third-party secure remote access tools. Native access management versus monitoring of customer-selected tools is the main difference between products.
Tracks OT security posture against IEC 62443, NIS2, NERC CIP and other sector regulations by mapping discovered assets, zones, vulnerabilities and controls to specific requirements and producing audit-ready compliance reports and gap lists. Usability of the tracking workflow varies widely.
Continuously varies network paths, IP addresses, and network configurations so attackers cannot reliably map or target stable routes to protected systems, rendering previously collected reconnaissance obsolete.
Schedules and triggers randomization events randomly, routinely, or on demand, including reconfiguration driven by predictive threat intelligence inputs, with AI and machine learning continuously adapting defenses in real time.
Limits lateral movement and code execution even when identities or credentials are compromised, reducing the blast radius of ransomware and destructive attacks.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
Start a shortlist with Dispel Zero Trust Engine
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.