Viridor operates Energy-from-Waste (EfW) facilities across the UK, converting non-recyclable waste into energy while maintaining strict environmental, safety, and operational standards.
To keep these facilities running reliably, internal engineers and third-party specialists require secure remote access to a broad range of critical operational technology (OT) systems.
Over time, Viridor's remote access capabilities evolved to support the company's growing operational needs.
Some systems were accessed through vendor-managed VPNs, while others relied on dedicated devices, multiple sets of credentials, or other connection methods. While these approaches met the needs of individual systems, remote access workflows varied widely across the environment. This created administrative complexity and made it difficult to apply consistent governance and oversight.
Based on the experience of Viridor Chief C&I Engineer Matthew Hopkins.
20 minutes → 30 seconds to connect to a remote site
Up to 1 hour saved per engineer, per day through faster remote access
1 hour → A few minutes to enable remote support for critical systems
Weeks → 10 minutes to provision secure, role-based access for new users
9 geographically distributed sites deployed in just 10 weeks, with one day of implementation per site
Centralized visibility, session monitoring, and role-based access
Eliminated endpoint software installation with agentless access for third-party vendors
During a review of changes made to an essential operational system, the team recognized an opportunity to strengthen the auditability of remote activity. While existing tools supported secure access, they offered limited visibility into remote sessions and system changes.
As remote access became increasingly important across Viridor's geographically distributed operations, the organization wanted a solution that combined secure connectivity with centralized oversight. The goal was to simplify how remote access was managed while giving the team full visibility into who was connecting and what they could do while connected, along with a comprehensive audit trail of all remote activity.
"That was a real key moment to say, right, we need to make all changes visible and auditable," said Chief C&I Engineer Matthew Hopkins.
Viridor worked with Capula, an industrial systems integrator, to evaluate several remote access platforms.
“Capula gave us an excellent overview of the secure remote access (SRA) providers which were suitable for our use case. Their clear, unbiased advice helped us to ultimately select Cyolo as the best choice for Viridor,” said Hopkins.
For Hopkins and his team, the project was about more than just replacing VPNs and other legacy access tools. They wanted to establish a consistent, centralized approach to secure remote access that would give the organization complete control over who could connect and what they could access.
With Cyolo, Viridor achieved exactly that. Multiple remote access methods were consolidated into a single solution with role-based access controls, session monitoring, and auditing capabilities.
Perhaps most importantly, systems that had previously been accessible only through vendor-managed VPNs became directly available to authorized Viridor personnel. This change fundamentally altered how the company manages third-party access.
Instead of relying on external organizations to govern access, Viridor gained the ability to manage, monitor, and audit remote sessions directly. The team can now clearly see who accessed a system, when they connected, and what they did during each session. For critical systems, additional controls including approval workflows and session recording provide a complete audit trail.
The result is not only greater visibility, but a level of operational control that had previously been out of reach.
Ease of deployment and day-to-day management were also important considerations for Viridor as it evaluated various secure remote access solutions.
Cyolo stood out because its solution did not require deep technical expertise. Hopkins' initial concerns faded almost immediately during the proof of concept.
“I was a little apprehensive at first, but deployment was far simpler than I expected,” said Hopkins. “The platform is incredibly straightforward to deploy and manage.”
The streamlined, straightforward deployment allowed Viridor to roll out the Cyolo solution across nine facilities located throughout the UK in just 10 weeks. Implementation at each site took only a single day, with no disruption to operations.
This simplicity extends to the day-to-day experience for both administrators and end users.
One of the first benefits Viridor experienced after deploying Cyolo was dramatically faster connection times.
Connecting to a site used to require multiple steps and a lengthy connection process before work could begin.
Today, by contrast, engineers can connect to facilities across the UK in about 30 seconds.
But now, with Cyolo, it's just a link on my desktop. Then I open up my phone for multi-factor authentication, and within 30 seconds I'm dialed into a site providing support.”
This translates into significant productivity gains. Each connection saves 15 to 20 minutes, and because Hopkins routinely accesses multiple sites each day, the impact quickly compounds.
By eliminating cumbersome connection processes, Cyolo gives engineers more time to focus on higher-value work.
Faster connection speeds also help minimize operational disruption when systems require specialist support. Previously, connecting third-party vendors through externally managed VPNs could take up to an hour. In some cases, site personnel even had to physically reconnect equipment before a remote connection could be established.
With Cyolo, the right experts can now connect in minutes instead of hours, reducing downtime and helping prevent what might otherwise become a costly operational disruption.
Provisioning remote access for new users once involved coordinating across multiple teams, vendors, and service providers. Depending on the system and the stakeholders involved, the process could take weeks.
Today, that same effort can often be completed in around 10 minutes, with users receiving role-based access to the specific applications and systems they need.
"I can generally set up someone's remote access and apply their roles and the devices they're permitted to access within 10 minutes,” said Hopkins.
The impact extends beyond faster provisioning. It has completely changed how the Viridor team responds to new access requests.
By making secure access easier to deliver and manage, Cyolo has become more than a security solution — it has become a business enabler.
Today, Cyolo serves as Viridor's standard solution for secure remote access across its Energy-from-Waste operations.
What began as an effort to improve auditability and strengthen governance ultimately evolved into a broader transformation of how the organization manages remote access. With Cyolo, Viridor now has the speed, visibility, and control needed to securely support employees, contractors, and third-party vendors across nine geographically distributed facilities.
By standardizing remote access across its operations, Viridor has enabled its lean OT team to respond faster, reduce downtime, strengthen compliance, and simplify access management — all without compromising security or operational agility.
Cyolo secures every connection across critical infrastructure and operational technology (OT) with a full-stack Secure Connectivity Platform that unifies remote privileged access and zero trust microsegmentation. Leading manufacturers, utilities, and data centers rely on Cyolo for surprisingly simple secure connectivity.
To learn more, schedule a demo.