Executive Summary
Zero Trust is one of the most misunderstood concepts in cybersecurity. It is not a product, a software package, or an architecture reserved for large enterprises. It is a framework for making better access decisions.
For PLM environments, Zero Trust means verifying identity, limiting access to what is necessary, considering the condition of the device and connection, and maintaining visibility into activity that could affect engineering data.
Why the Traditional Perimeter Is No Longer Enough
Traditional security assumed that users and devices inside the corporate network could be trusted. That assumption was easier to maintain when applications resided in one data center and employees worked primarily from company offices.
Today, engineering organizations collaborate across locations, cloud services, suppliers, contractors, home offices, and managed or unmanaged devices. A network connection alone does not prove that the user, device, or request is trustworthy.
What Zero Trust Really Means
Zero Trust changes the questions asked before access is granted:
- Identity: Who is requesting access, and how confidently has that identity been verified?
- Business need: Does the user need this application, role, object, or administrative capability?
- Device and connection: Is the device managed, healthy, and connecting through an approved path?
- Context and risk: Is the request consistent with normal behavior, location, time, and policy?
Applying Zero Trust Principles to PLM
| Security Layer | Practical PLM Application |
|---|---|
| Identity | Unique accounts, controlled lifecycle management, stronger authentication for elevated risk |
| Authorization | Windchill roles, teams, domains, contexts, and access-control rules aligned with business responsibilities |
| Privileged access | Separate administrator accounts, limited use, reviewed membership, and protected credentials |
| Devices | Managed engineering workstations, supported operating systems, endpoint protection, and patch compliance |
| Network access | VPN, secure proxy, network segmentation, or zero-trust network access instead of direct Internet exposure |
| Visibility | Authentication logs, Windows and SQL monitoring, Windchill service health, queue and publishing alerts, and capacity trends |
| Recovery | Immutable or offline backups, documented dependencies, and tested recovery procedures |
Least Privilege in an Engineering Environment
Least privilege does not mean making work unnecessarily difficult. It means users receive the access needed for their responsibilities without accumulating broad permissions that are no longer justified.
For Windchill, this may involve reviewing organization and site administrators, context teams, product and library roles, supplier access, service accounts, shared credentials, and access inherited through groups.
Zero Trust Does Not Require an Overnight Transformation
- Establish a reliable identity baselineUse unique accounts, eliminate unnecessary shared access, define account ownership, and strengthen remote or privileged authentication.
- Align access with rolesReview who can administer Windchill, approve changes, access sensitive products, or use integration and service accounts.
- Improve visibilityCentralize important logs where practical and monitor the infrastructure and PLM components that indicate service degradation or unusual behavior.
- Protect the recovery pathEnsure attackers cannot easily destroy every backup copy and confirm that the organization can restore the complete PLM service, not only an isolated database or vault.
- Add context-aware controls as needs matureDevice compliance, conditional access, network segmentation, privileged-access workflows, and risk-based authentication can be introduced where they solve a meaningful problem.
Five Questions to Evaluate Readiness
- Can every person and service accessing the PLM environment be uniquely identified?
- Are remote and privileged access protected beyond a password?
- Do permissions reflect current business responsibilities?
- Can unusual authentication, access, or system behavior be detected promptly?
- Can engineering operations be restored if an account, server, or site is compromised?
The Business Value
Zero Trust supports more than cybersecurity. It can improve onboarding and offboarding, clarify ownership, reduce unnecessary privilege, support supplier collaboration, create stronger audit evidence, and make remote work more sustainable. Most importantly, it helps protect the engineering information and processes that connect design, manufacturing, quality, service, and the broader digital thread.
Advisor’s Perspective
Zero Trust should be treated as a decision-making framework, not a checklist of products. A smaller organization may begin with secure remote access, unique accounts, least privilege, reliable backups, and basic monitoring. A larger organization may add centralized identity, device compliance, adaptive access, and privileged-access governance.
The right approach is the one that addresses the organization’s most important risks while remaining understandable, supportable, and sustainable for the people who must operate it.