AGP Picks
View all

Dispel launches identity proofing for OT remote access

9 hours ago
By AI, Created 12:00 UTC, Aug 03, 2026, AGP -

Dispel unveiled Dispel Identity at Black Hat USA 2026, adding government ID checks and biometric matching to OT remote access decisions. The product is designed to verify the person behind a credential, not just the credential itself, as industrial operators face rising risk from shared logins and AI-enabled impersonation.

Why it matters: - OT remote access often relies on credentials alone, which creates risk when passwords are shared, sessions stay open, or logins are handed off. - Dispel Identity is designed to verify the actual person behind a login for systems where a single remote action can affect physical operations and safety. - The launch targets utilities, energy, manufacturing, and other regulated industries that need stronger identity assurance for third-party access.

What happened: - Dispel announced Dispel Identity at Black Hat USA 2026 in Las Vegas on Aug. 3, 2026. - The product adds identity proofing to OT remote access through government ID checks and biometric matching to the NIST IAL2 standard. - Dispel said the launch expands its OT secure remote access platform with identity assurance built into the access decision. - The product is available now within the Dispel Zero Trust Engine. - Dispel will demo Dispel Identity live at Black Hat USA 2026. - Organizations can request a demo at book a demo.

The details: - Dispel Identity uses an accredited provider to confirm a person’s identity in three stages: resolution, validation, and verification. - Resolution confirms the applicant is a distinct, real person. - Validation confirms the government-issued ID is genuine. - Verification uses a liveness check and facial match to confirm the person matches the ID. - Once verified, the identity is tied to a single record, and each connected account maps back to that record. - Verification runs independently of the login path, so a slow identity provider does not block access. - The platform includes a central IAL2 identity verification and fraud-indicator stack. - Dispel says the service supports documents from all 195 countries and uses FRVT-benchmarked face matching for 1:1 verification and 1:N identification. - Native integrations support Microsoft Entra, Okta, PingIdentity, and any SAML or OIDC provider, including hybrid environments with social sign-on and local accounts. - The privacy architecture includes U.S.- or EU-located processing, GDPR data minimization, BIPA-compliant consent and deletion controls, an independent eIDAS audit, and certification under the EU-U.S. and Swiss-U.S. Data Privacy Frameworks, with UK extension. - Biometric data is stored in a non-reversible, non-reconstructable format.

Between the lines: - The announcement reflects a shift from credential-based access control to person-based verification for industrial environments. - Dispel is positioning identity assurance as a response to AI-enabled impersonation and contractor-account reuse, two issues that make remote OT access harder to trust. - The company is also tying the product to compliance needs, including IEC 62443-3-3 requirements for unique user identification, account management, and non-repudiation. - Dispel is framing the product as an extension of on-site identity checks that are already common in regulated industries, but not consistently applied to remote sessions.

What's next: - Dispel says operators can set policy-based triggers for identity proofing by user type, asset risk score, session forensics score, or geography. - The company says access can be blocked automatically when a person is denied, which removes the need for manual follow-up across multiple shared or linked accounts. - Dispel says the platform now combines secure remote access, session risk scoring, compliance evidence, industrial data streaming, and identity proofing in one system. - The company expects the product to support offboarding, contractor control, and high-risk session review with auditable evidence.

The bottom line: - Dispel Identity tries to close a long-standing OT security gap: knowing not just which account connected, but which person actually did.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Switzerland Weekly

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Switzerland Weekly

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.