Remote Access in OT: Inevitable, But Never Uncontrolled

Remote access is now part of industrial operations. But in OT, remote access without governance is not convenience. It is exposure.

During the COVID-19 pandemic, remote access became a lifeline.

Travel stopped. Vendors could not reach sites. Engineers had to support plants from home. Operations teams had to keep production running with limited staff and limited physical access.

Many organizations had no choice but to move fast. And they did.

Some extended IT VPNs into OT environments. Some enabled remote support tools quickly. Some allowed vendors to connect directly to keep systems running. Some accepted temporary exceptions because the plant could not wait.

At the time, many of these decisions were understandable. But temporary access has a habit of becoming permanent. And in OT, what remains unmanaged eventually becomes risk.

The Remote Access Legacy We Still Live With

In industrial environments, many remote access pathways created during emergency periods remain active today.

  • Some are documented.
  • Some are partially understood.
  • Some are owned by vendors.
  • Some are known only to a small group of engineers.
  • Some are simply forgotten.

This is where the concern begins. Remote access is not the problem by itself. Uncontrolled remote access is the problem.

When remote access is always open, poorly monitored, weakly authenticated, or fully controlled by a third party, it becomes a direct path into the operational environment.

And in OT, that path may lead to systems that affect production, safety, reliability, and recovery.

Why OT Remote Access Is Different

In IT, remote access usually connects people to business applications, files, email, or cloud systems.

In OT, remote access can connect people directly or indirectly to:

  • Process control networks
  • Engineering workstations
  • HMIs and SCADA systems
  • PLCs and controllers
  • Safety-related systems
  • Vendor support interfaces
  • Operational data and critical assets
  • That changes the risk completely.

OT remote access is not only a cybersecurity matter. It is an operational risk matter.

A weak remote access path can affect Availability, Safety, production continuity, process reliability, incident recovery, and regulatory confidence.

This is why OT remote access cannot be treated as a standard IT connectivity issue. The consequences are different.

The Most Common OT Remote Access Mistakes

The same patterns keep appearing across industrial environments:

  • Always-on VPN tunnels into OT networks
  • Shared vendor accounts
  • Weak or missing multi-factor authentication
  • Commercial remote support tools used without proper governance
  • Vendor-controlled jump servers with limited visibility for the asset owner
  • Remote access paths that bypass segmentation
  • No session recording
  • No site-level approval
  • No clear ownership of who can connect, when, and why
  • No practical way to terminate a session immediately
  • Remote access exceptions that were never removed

None of these issues is rare.

They are common because they were often created under pressure. But pressure does not remove risk. It only explains how the risk was introduced.

The Core Principle: The Asset Owner Must Stay in Control

A mature OT remote access model starts with one simple principle:

The asset owner must remain in control of every remote session.

Not the vendor alone. Not the remote support tool alone. Not the IT team alone. Not a forgotten VPN profile.

The asset owner must know the answers to the following 8:

  • Who is connecting
  • Why are they connecting
  • What they can access
  • When the session starts
  • Who approved it
  • What actions were performed
  • When the session ended
  • Whether the session can be terminated immediately

If these answers are not clear, remote access is not governed. It is only available. And availability without control is not resilience.

What Good OT Remote Access Should Include

OT remote access should be designed with safety, reliability, and accountability in mind.

At a minimum, it should include the following 10 features:

  • Site-level initiation and approval
  • Multi-factor authentication for all users
  • Named accounts, not shared credentials
  • Role-based access based on least privilege
  • Time-bound access windows
  • Segmentation between remote access zones and critical control networks
  • Session logging, monitoring, and recording where appropriate
  • The asset owner's ability to terminate any session
  • Periodic review of users, vendors, and access paths
  • Documented emergency access procedures and Integration with incident response planning

These are not advanced features.

They are foundational controls. In OT, remote access should never be treated as a simple convenience feature. It should be treated as a controlled operational process.

The Zero Trust Question

Many remote access solutions today use the phrase “zero trust.” But in OT, zero trust should not be accepted as a marketing claim.

It must be proven by design. The real questions are simple:

  • Who initiates the session?
  • Who approves it?
  • Is access temporary or always open?
  • Can access be limited to specific systems?
  • Is the session visible to the asset owner?
  • Is activity logged and recorded?
  • Can the session be terminated immediately?
  • Does the vendor retain any access the asset owner cannot see or control?

If the asset owner cannot see it, approve it, limit it, and stop it, then it is not truly governed access.

It might be protected by a vendor claim, but it isn't controlled by the operation. That difference is important.

One Size Does Not Fit All

There is no universal remote access model for OT.

A water utility, refinery, power plant, airport, manufacturing facility, building automation environment, and pipeline operation may all need different models.

  • The right design depends on:
  • Operational criticality
  • Safety impact
  • Process sensitivity
  • Vendor dependency
  • Existing network architecture
  • Regulatory expectations
  • Site maturity
  • Segmentation model
  • Incident response capability
  • Business continuity requirements
  • This is why tool-first thinking often fails.
  • Buying a remote access platform is not the same as governing remote access.
  • The better sequence is:
  • Define the operational risk.
  • Define the access governance model.
  • Define who owns approval and control.
  • Define what must be logged and what must be monitored.

Then select and configure the technology to support that model. Technology should support governance. It should not replace it.

Questions Every OT Leader Should Ask

Before trusting any remote access model, OT leaders should ask:

  • Can site personnel approve or deny every remote session?
  • Is every session tied to a named user?
  • Are shared vendor accounts eliminated?
  • Is multi-factor authentication enforced?
  • Is access limited by role, system, purpose, and time?
  • Are remote sessions logged, monitored, and recorded?
  • Can the organization immediately terminate a session?
  • Are vendor connections reviewed regularly?
  • Are emergency access procedures documented?
  • Is remote access included in tabletop exercises and incident response plans?
  • Are old remote access exceptions still active?

If the answer is unclear, the risk is already there.

The OT CISO View

Remote access is not going away.

In fact, it will become more important as industrial organizations deal with workforce shortages, remote engineering models, vendor support dependency, AI-enabled operations, and globally distributed technical teams.

The answer is not to reject remote access.

The answer is to govern it.

OT needs remote access that supports operations without exposing them.

It must be secure enough for cybersecurity. Practical enough for engineers. Visible enough for asset owners. Controlled enough for operations. And auditable enough for leadership.

That is the balance.

Remote access in OT should never be based on hope. It should be based on control.

If you cannot approve it, limit it, monitor it, record it, and terminate it, you do not truly govern it.

And if you do not govern remote access in OT, someone else may eventually use it against you.

Previous
Previous

OT Incident Response: It's Not About Speed. It's About Safety.

Next
Next

When Customer Data Is Hit but Power Stays On: Lessons from the Emera breach