NIS2 Compliance. Zero Re-Engineering.
Modernize legacy VNC, Rockwell PanelView, and embedded HMI screens with multi-factor authentication, single sign-on, and end-to-end TLS encryption without modifying equipment logic or plant workflows.
Maintain your proven operational technology, achieve full regulatory compliance.
Enabling NIS2 Compliance for VNC Remote Access in Industrial Control Systems
Bring Multi-Factor Authentication and Zero Trust to Legacy Plant Screens
Meet mandatory European NIS2 cybersecurity directives across legacy factory screens, HMIs, and server management consoles. Eliminate weak 8-character passwords and unsegmented VPNs by wrapping native VNC in an identity-aware, encrypted browser portal.
NIS2 & ISA/IEC 62443 Compliant
Multi-Factor Authentication (MFA)
Outbound-only HTTPS
PROBLEM / SOLUTION
The European NIS2 Directive enforces strict cybersecurity risk management mandates on essential industrial infrastructure, requiring verified user identity, continuous multi-factor authentication, and robust traffic encryption. However, thousands of deployed HMIs only support legacy Virtual Network Computing (VNC). Agilicus AnyX bridges this compliance gap without ripping and replacing functional equipment:
The Compliance Dilemma
❌ Shared 8-Character Passwords: Native VNC relies on weak, shared passwords with no username verification, making individual accountability and compliance impossible.
❌ Unencrypted Plant Traffic: Legacy VNC transmits graphical data without encryption, leaving operational telemetry vulnerable to eavesdropping and manipulation.
❌ Prohibitive Rip-and-Replace Costs: Upgrading thousands of working PanelView or Siemens HMIs to support modern protocols requires millions in capital expenditure and plant downtime.
The Agilicus Solution
✅ Hardware-Preserving Compliance: Retrofits legacy VNC endpoints with modern Zero Trust security without altering existing PLC logic, screens, or operator habits.
✅ Identity-Bound MFA & SSO: Ties every connection directly to corporate Single Sign-On and multi-factor authentication, injecting hidden machine credentials automatically.
✅ End-to-End TLS Encryption: Encapsulates VNC into HTTPS over WebSockets in a standard browser, ensuring full data confidentiality and auditability.
Why Industrial Operators Choose Agilicus for NIS2
A proven, friction-free path to NIS2 and ISA/IEC 62443 compliance that satisfies executive risk officers and plant engineers alike.
Multi-Factor Authentication for Legacy HMIs
Mandate biometric or FIDO2/app-based MFA for every remote session before a user can view or interact with plant floor screens.
Automated Password Stuffing
Securely stores and injects internal VNC passwords, ensuring external contractors and operators never see or share physical device credentials.
Verifiable Compliance Audits
Logs every session with verified user identity, exact timestamps, and duration to satisfy strict NIS2 and ISA/IEC 62443 reporting standards.
HOW IT WORKS
1
Deploy Connector
Run the lightweight Agilicus connector within the local HMI or server management subnet.
2
Map Terminal Resource
Define the VNC endpoint in Agilicus AnyX with automated password injection.
3
Enforce SSO & Roles
Assign read-only viewer or interactive control permissions mapped to corporate MFA.
4
Access in Browser
Users open the session in any modern web browser over encrypted HTTPS with full auditing.
Complete NIS2 Compliance. Zero Disruption.
“Agilicus AnyX allowed us to bring our existing Rockwell PanelView and Siemens HMI screens into full NIS2 compliance overnight, delivering multi-factor authentication and complete audit logging without touching plant floor PLC code.”