Michael Burns
Michael Burns, MBA, PMP, CPIM, is director of manufacturing and quality at FreeWave Technologies, where he leads manufacturing, quality, inventory and production planning across a high-mix electronics environment. With more than 15 years of experience in aerospace, advanced manufacturing and electronics production, he specializes in scaling complex operations, implementing ERP and MES systems and advancing Lean continuous improvement initiatives. Before joining FreeWave, Burns held engineering and operations leadership roles at ABSL Space Products, Sierra Space and Sierra Nevada Corporation, supporting large-scale aerospace programs involving advanced spaceflight systems and complex composite structures. He holds a BS in Mechanical Engineering and an MBA from the University of Colorado Boulder, along with PMP and CPIM certifications. Burns is focused on practical operating strategies that help high-mix manufacturers improve throughput, maintain quality and scale production without losing flexibility.
How zero trust remote access is changing the economics of engineering productivity in high-mix electronics manufacturing
If you ask engineers in a high-mix electronics facility how much of their day they spend actually solving problems versus getting to them, the honest answer is usually uncomfortable. Walking to a machine to pull data, loading a program onto a controller that can’t be reached any other way, coordinating with IT to get clearance for a USB transfer and none of that shows up in utilization reports, but it accumulates. Across a full production shift, the overhead is significant. Some of our engineers were logging over a mile a day before we addressed it.
The USB drive workflow is worth digging into a bit because it tends to get normalized. It’s slow, yes. But the bigger issue is that it’s essentially untraceable at the data level. A drive goes in, files move, the drive comes out. If that happens a hundred times a month across multiple machines and multiple operators, maintaining a defensible audit trail becomes genuinely difficult. For a facility supporting regulated programs like defense electronics, aerospace assemblies, semiconductor supply chain work operating under ITAR or EAR, “difficult” and “defensible” don’t belong in the same sentence.
Legacy Equipment Isn’t Going Anywhere
The other piece of this and it’s one that tends to get underestimated outside of operations, is the installed base problem. A meaningful portion of the machines running in electronics manufacturing facilities today (SMT placers, reflow ovens, inspection systems, test equipment) were qualified and validated years ago on Windows XP or Windows 7.
"A zero-trust architecture designed specifically for the operational edge, where legacy assets, isolated networks and regulated data are the normal conditions rather than edge cases, doesn’t create that trade-off. It just removes the friction that was already there."
That’s not negligence; it’s the reality of machine qualification cycles. Revalidating a piece of capital equipment to run on a modern OS takes time and carries process risk that most operations managers aren’t willing to absorb unless they absolutely have to. So, the machines stay as they are, and connectivity to them is a problem that gets worked around rather than solved.
Most modern remote access tools don’t run on legacy operating systems, which means those assets are effectively unreachable without physical presence. You can have excellent network security everywhere else and still have a gap there that nobody has a clean answer for.
Building the Solution on Our Own Floor
We developed and deployed the FreeWave Zentry™ solution and applied it to our own needs, in our own facility. Our facility runs a high-mix SMT and test environment with Samsung and Hanwha placement machines, Europlacer screen printers, Heller reflow ovens and, we were dealing with both problems at once: the access friction and the legacy OS barrier. We needed something that worked in an isolated network, met our compliance requirements and didn’t require us to touch the machine controllers to implement it.
The Zentry solution is a zero trust Remote Engineering Access Platform. The architecture authenticates every user and device at every connection with no persistent open ports, no static tunnels, nothing sitting exposed on the network waiting to be found. Sessions are encrypted with AES-256 and logged endto-end. For the legacy equipment, we deployed small industrial interface nodes alongside the existing controllers rather than modifying the machines themselves. The node handles the encrypted connection; the machine software sees nothing different. Qualification status intact.
After deployment, engineers could connect directly from their workstations to any enrolled device on the floor. Program deployments, process data collection, remote diagnostics — all of it moved off the physical access model. IT owns user provisioning; manufacturing engineering manages device enrollment. The division of responsibility was intentional: we wanted IT to maintain control over who has access without becoming the daily gatekeeper for every engineering task.
What Compliance Actually Looks Like in Practice
The compliance story matters for this audience, so it’s worth being specific. All connections and stored session data remain within U.S. infrastructure, which satisfies ITAR and EAR data jurisdiction requirements. The platform operates across approved VLANs without bridging to external networks, so air-gap isolation is preserved. Automated session logs support AS9100 Clause 8.5.1 (control of production and service provision) and Clause 9.1.2 (monitoring and measurement of processes) without requiring anyone to manually maintain records. That last part matters more than it sounds because manual audit trail maintenance is where compliance programs tend to develop gaps over time.
Routine IT involvement after initial setup is minimal. We’ve found that once the security vetting is done and users are provisioned, the system runs without IT touching it day-to-day. That was a meaningful operational improvement for a team that was already stretched.
The Boader Argument
There’s a persistent belief in manufacturing operations that security investment comes at the cost of operational agility and that locking things down necessarily means slowing things down. In our experience, that’s mostly a product of trying to apply enterprise IT security frameworks to environments they weren’t built for. A zero-trust architecture designed specifically for the operational edge, where legacy assets, isolated networks and regulated data are the normal conditions rather than edge cases, doesn’t create that trade-off. It just removes the friction that was already there.
For semiconductor and advanced electronics manufacturers, the engineering access problem is worth solving directly rather than working around. The workarounds have costs that are easy to undercount until something goes wrong.
