Skip to content

Semtech And Palo Alto Push Zero Trust Out To The Grid Edge

Semtech's AirLink routers now plug into Palo Alto firewalls, with automated certificates for every field device, as utilities face attackers targeting edge equipment.

Semtech And Palo Alto Push Zero Trust Out To The Grid Edge
Image courtesy: Unsplash

Semtech has finished integrating its AirLink cellular routers with Palo Alto Networks' Next-Generation Firewalls. The aim is to bring zero trust security, a model that verifies every connection instead of trusting anything inside the network perimeter, to the remote edge sites that utilities and other critical infrastructure operators depend on.

Under the integration, announced on 23 September, AirLink 5G and LTE routers deployed at substations, pump stations, pipelines and similar field sites form encrypted tunnels back to Palo Alto firewalls at the core of the network. Certificates and machine identities for those routers are issued and managed automatically, drawing on Palo Alto's Next-Generation Trust Security (NGTS) and Zero Touch PKI (ZTPKI) tools. Traffic from the edge is then inspected by Palo Alto's PAN-OS platform for threats.

The two companies will show the setup at the Utility Broadband Alliance (UBBA) Summit & Plugfest in Fort Worth, Texas, from 13 to 15 October 2026, including a joint technical session on the opening day.

Why The Edge Of The Grid Is The Weak Spot

Critical infrastructure operators have spent years hardening their data centres and control rooms. Their field assets are much harder to protect. A utility may run thousands of small sites spread across a wide region, each with a router, a remote terminal unit or a sensor, often connected over cellular, satellite or private radio links, and rarely visited by staff.

Many of the devices at those sites are operational technology (OT) that was never designed with modern security in mind. They cannot always be patched quickly, and sometimes cannot be patched at all without taking equipment offline or replacing it.

Palo Alto's Mitch Rappard, director of technical solutions, put the concern bluntly in the announcement: "Threats to critical infrastructure are accelerating, with Frontier AI compressing attack timelines while many operational technology assets cannot be patched quickly—or at all."

Governments Have Raised The Alarm

That warning echoes guidance from US authorities. In February 2024, CISA and partner agencies said state-sponsored actors, tracked as Volt Typhoon, had pre-positioned inside US critical infrastructure networks, including in some cases for at least five years, with the apparent aim of being able to disrupt systems in a future crisis. Their methods leaned heavily on compromised edge devices such as small routers.

In 2026, CISA published further guidance on defending against covert networks of compromised devices linked to China-nexus actors. The consistent message across these advisories is that network edge equipment, the routers and gateways that sit between field assets and the wider network, has become a favoured way in.

How The Semtech And Palo Alto Setup Works

The integration pairs two layers that utilities often buy separately.

Trusted Connectivity At The Edge

Semtech's AirLink line, which the company took over with its acquisition of Sierra Wireless, provides rugged 5G and LTE routers built for vehicles, field cabinets and industrial sites. These are the devices that connect remote assets to the operator's network, whether over public cellular, private LTE or other links.

Semtech has been pushing the range further into utilities. In 2025, it added support for the 900 MHz private LTE band used by utilities in the US to its AirLink XR60 5G router, aimed at grid operators building their own networks.

Enforcement At The Core

Palo Alto's Next-Generation Firewalls sit at the other end of the tunnel, inspecting traffic arriving from the field and applying security policy. With the integration, operators can see and control what their edge routers send, and detect threats in real time, from the same PAN-OS management they may already use for the rest of the network.

"Securing distributed industrial assets requires both trusted connectivity at the edge and robust enforcement at the core," said Kinana Hussain, vice president of AirLink Networking Solutions at Semtech.

Identity Is The Glue

The part of the integration most closely tied to zero trust is identity. Each router needs a digital certificate so the firewall can confirm it is talking to a genuine device, and those certificates have to be issued, renewed and revoked over the device's life. Doing that by hand across thousands of sites is slow and error-prone, and expired or poorly managed certificates are a common cause of both outages and security gaps.

The joint solution automates certificate provisioning and machine identity management through Palo Alto's NGTS and ZTPKI. Those capabilities came to Palo Alto with its purchase of CyberArk, which it completed in February 2026. CyberArk had itself acquired machine identity specialist Venafi, and Palo Alto now sells the former CyberArk Certificate Manager as NGTS.

"Machine identities now outnumber human identities by more than 80 to 1," Palo Alto said when it closed the CyberArk deal. In an industrial network, most of those machines are exactly the kind of unattended field devices this integration targets.

What Utilities Are Likely To Look For

The announcement is aimed squarely at utilities, and the choice of the UBBA event underlines that. The alliance brings together utilities and suppliers working on private broadband for the grid.

"Securing utility networks at scale requires partners who understand both the operational realities of the field and the demands of modern cybersecurity," said Bobbi Harris, executive director of the UBBA.

For utility network and security teams, the questions will be practical:

·        How well the setup works across mixed links, since field sites often combine public cellular, private LTE, satellite and wired backhaul.

·        How much of the certificate lifecycle is truly automated, including renewal and revocation when a router is replaced or stolen.

·        How it fits existing firewall policies and OT monitoring tools, instead of adding another console.

·        What it costs to run over the long service life typical of grid equipment.

The companies have not published pricing or deployment figures, so the real test will come from utility pilots and field rollouts.

Part Of A Wider Pattern

Integrations like this reflect a broader shift in industrial IoT. Vendors of connectivity hardware are increasingly packaging security into their products, not leaving it to customers to bolt on later. Regulation is pushing the same way. In Europe, rules such as the Cyber Resilience Act for IoT makers are raising the bar for how connected products are secured and supported over their lifetimes.

For readers newer to the field, our guide to industrial IoT connectivity explains how field devices, gateways and networks fit together in industrial settings, and why the edge is so difficult to secure.

The Bottom Line

The Semtech and Palo Alto integration is not a new product so much as a joining of two existing ones: rugged edge routers on one side and enterprise firewalls and machine identity tools on the other. Its value lies in making zero trust practical at sites where no one is on hand to manage certificates or patch equipment.

With government agencies repeatedly naming edge devices as a route into critical infrastructure, that kind of automation is becoming a baseline expectation for utilities, not an extra. How well it performs across thousands of remote sites is something operators will judge in the field.

Add Morning Tick on Google