Home/Blog/Industrial Cybersecurity

Semtech and Palo Alto Networks Bring Zero Trust to Remote Industrial Assets

A new integration pairs Semtech's AirLink 5G/LTE edge routers with Palo Alto Networks firewalls and automated certificate management, aimed at utilities and critical-infrastructure operators securing thousands of distributed, often unmanned, field sites.

Industrial CybersecurityOct 9, 2026Smart Machines & Factories Blog

Semtech and Palo Alto Networks announced on September 24, 2026, that they have completed a product integration combining Semtech's AirLink secure edge 5G/LTE routers and network-management portfolio with Palo Alto Networks' Next-Generation Firewalls (NGFWs), built around Next-Generation Trust Security (NGTS) and Zero Touch Public Key Infrastructure (ZTPKI). The goal: extend Zero Trust architecture out to the industrial edge, where utilities and critical-infrastructure operators manage thousands of remote, often unstaffed assets over wired, cellular, and satellite links.

What the Integration Actually Does

Integration Summary

  • AirLink connectivity. Semtech's routers establish encrypted IPsec tunnels automatically to Palo Alto firewalls across cellular, satellite, and wired networks, while supplying device and network context data.
  • PAN-OS enforcement. Palo Alto Networks adds real-time App-ID traffic classification and AI-driven threat detection, with policy enforcement that stays consistent as assets move across networks.
  • Automated certificate lifecycle. NGTS and Zero Touch PKI automate certificate provisioning, renewal, and machine-identity management — eliminating manual credential configuration across remote field assets.
  • Target users. Utilities and public-sector operators running distributed industrial IoT fleets: substations, pipeline monitoring, water infrastructure, and similar unmanned sites.

"We are extending Zero Trust security to the industrial edge by combining resilient AirLink cellular connectivity with continuous asset visibility," said Mitch Rappard, Palo Alto Networks' director of technical solutions, in the companies' announcement. Kinana Hussain, Semtech's VP of AirLink Networking Solutions, framed the pairing as addressing both halves of the problem at once: "Securing distributed industrial assets requires both trusted connectivity at the edge and robust enforcement at the core." The integration will be showcased at the Utility Broadband Alliance Summit & Plugfest in Fort Worth, Texas, this October — where UBA executive director Bobbi Harris called it "exactly the kind of integrated, standards-aligned approach our members expect."

Why Certificate Automation Is the Real Story

Most industrial Zero Trust pitches lead with network segmentation or firewall policy. What makes this announcement notable is the emphasis on certificate lifecycle automation as a first-class feature rather than an afterthought. Manual PKI has long been the quiet failure point in OT Zero Trust rollouts: a certificate that expires on a remote relay cabinet, a substation controller, or a pipeline sensor site doesn't get noticed until the device drops off the network — and dispatching a technician to a remote or unmanned location just to re-provision credentials is expensive and slow.

By routing certificate provisioning and renewal through Zero Touch PKI tied directly to the AirLink router's own identity, the integration removes a dependency that scales badly as fleets grow from dozens to thousands of connected sites. It also closes a gap that attackers specifically look for: devices running on stale, overdue, or weakly managed certificates are a common entry point into otherwise well-segmented OT networks.

What It Means for Fleet Operators

  1. Evaluate certificate sprawl first. Before adopting any vendor's Zero Trust stack, inventory how certificates are currently provisioned and renewed across remote assets — this is where most manual-process risk lives.
  2. Treat edge routers as policy enforcement points, not just connectivity. The value here comes from the router feeding device/network context into the firewall layer, not just carrying traffic.
  3. Plan for mixed connectivity. Fleets spanning cellular, satellite, and wired links need consistent policy enforcement regardless of transport — a requirement this integration is explicitly built around.
  4. Watch the UBA Plugfest results. Interoperability demonstrations at events like this are where integration claims get tested against real multi-vendor field conditions.

Automating machine-identity management is the same engineering problem whether the fleet is five thousand utility routers or a handful of custom IIoT gateways: certificates, API keys, and device credentials need a lifecycle that doesn't depend on someone remembering to rotate them manually. YuSMP Group builds exactly this kind of automated provisioning and identity management into custom industrial and enterprise software.

Sources: Industrial Cyber and Palo Alto Networks tech brief (September 24, 2026).

← Back to Blog Smart Machines & Factories Blog