Vendor and integrator remote access is one of the most common entry points into OT networks, and also one of the hardest to get right without slowing down maintenance. I'm comparing the approaches I see most often and would like to hear what works in your plants and substations.
1. Vendor-managed VPN or remote tool installed on a station PC
Fast and convenient, but often always-on, shared credentials, and little visibility into what the vendor actually does.
2. Central jump host / remote access gateway owned by the asset owner
MFA, individual accounts, session recording, and access only to the specific devices needed. More work to set up, and vendors sometimes push back.
3. On-demand access
The connection is disabled by default and enabled per job (ticket or phone call), with a time limit and someone from operations watching the session.
Things I try to verify regardless of the approach:
- No direct path from the internet or corporate IT to the control network
- Named accounts per technician, never a shared vendor login
- Access limited to the devices in the work order, not the whole zone
- Logic downloads and firmware changes logged and reviewed afterwards
- A tested way to cut the connection immediately
Questions for the group:
- Which model do you use, and how did vendors react?
- Has anyone managed session recording for serial or proprietary engineering tools?
- How do you handle emergency access at 2 a.m. without leaving the door open the rest of the year?
1. Vendor-managed VPN or remote tool installed on a station PC
Fast and convenient, but often always-on, shared credentials, and little visibility into what the vendor actually does.
2. Central jump host / remote access gateway owned by the asset owner
MFA, individual accounts, session recording, and access only to the specific devices needed. More work to set up, and vendors sometimes push back.
3. On-demand access
The connection is disabled by default and enabled per job (ticket or phone call), with a time limit and someone from operations watching the session.
Things I try to verify regardless of the approach:
- No direct path from the internet or corporate IT to the control network
- Named accounts per technician, never a shared vendor login
- Access limited to the devices in the work order, not the whole zone
- Logic downloads and firmware changes logged and reviewed afterwards
- A tested way to cut the connection immediately
Questions for the group:
- Which model do you use, and how did vendors react?
- Has anyone managed session recording for serial or proprietary engineering tools?
- How do you handle emergency access at 2 a.m. without leaving the door open the rest of the year?
