Skip to main content
Blog & Insights

Secure Remote Access For Industrial IT And OT Systems

Secure remote access lets industrial organisations diagnose faults, update systems, monitor equipment and support machines without always sending an engineer to site. Uncontrolled connections can expose operational technology (OT) systems to unauthorised access, malware, lateral movement and unrecorded changes. Controls should protect production continuity as well as the connection.

Key Point

Secure Remote Access Is More Than An Encrypted Connection

A complete approach controls the user, device, destination, permitted activity, access period, monitoring and the method used to revoke or isolate a connection.

What Is Secure Remote Access?

Secure remote access is controlled and authenticated access to organisational systems from another location. In an industrial environment, it allows an authorised engineer, employee, original equipment manufacturer (OEM) or contractor to reach approved operational resources through defined security controls without giving them unrestricted access to the wider network.

Those resources can include programmable logic controllers (PLCs), human-machine interfaces (HMIs), supervisory control and data acquisition (SCADA) systems, industrial PCs, robots, drives, engineering workstations, remote gateways and machines at customer or distributed sites.

Encryption is only one part of the process. Identity checks, access restrictions, monitoring and reliable revocation are also needed so legitimate work can take place without creating unnecessary exposure.

Why Secure Remote Access Is Different In Industrial IT And OT

Information technology (IT) guidance cannot simply be copied into OT. Industrial environments combine long equipment lifecycles, legacy controllers, limited maintenance windows, uptime requirements and safety constraints. A remote change may affect a running process rather than only business data.

Responsibility is also shared between IT teams, OT engineers, OEMs, system integrators and contractors. The UK National Cyber Security Centre (NCSC) recommends limiting exposure, centralising connections, hardening OT boundaries, limiting compromise, logging activity and planning isolation. Industrial controls therefore need to protect availability, safety and production continuity as well as confidentiality.

What Are The Security Risks Of Industrial Remote Access?

The main risks come from weak governance, excessive permissions and poorly controlled connection paths. Common weaknesses include:

  • Shared engineering accounts
  • Permanent supplier credentials
  • Excessive network access after login
  • Directly exposed PLCs, HMIs or remote desktop services
  • Unauthorised access tools or gateways
  • Unmanaged contractor laptops
  • Missing multi-factor authentication (MFA)
  • Unpatched remote access software
  • Limited session logging
  • Changes made without approval or version records
  • Lateral movement between assets
  • Access outside approved maintenance periods
  • No defined incident disconnection process

Consequences include downtime, loss of control, unplanned changes, safety concerns, data exposure and slower investigations. Controls reduce these risks by limiting the route, user and permitted activity.

How Does Secure Remote Access Work In Industrial Environments?

  1. Request. An authorised engineer or third party requests access for a defined task.
  2. Authenticate. Their identity is checked, ideally using MFA.
  3. Authorise. Policy determines which machine, protocol or application they can use.
  4. Connect. An encrypted connection is established through an approved gateway, broker or platform.
  5. Restrict. Access is limited to the required asset and period.
  6. Record. The session is logged and monitored.
  7. Revoke. Access is removed when the work is complete.

Good secure remote access does not place the remote user inside the whole OT network. An industrial gateway can create a controlled path to the intended machine without exposing industrial assets directly to the public internet.

Secure Remote Access Vs A Traditional VPN

A virtual private network (VPN) can form part of secure remote access, but the terms are not interchangeable. A VPN provides an encrypted communication path. A complete industrial process also governs identity, scope, duration, permissions, monitoring and revocation.

Consideration Traditional Broad-Access VPN Industrial Secure Remote Access
Access scope May reach a wider network Specific machine or service
Authentication Standard user authentication Unique accounts and MFA
Duration May remain available Can be time-limited
Asset control Often network-based Machine, application or protocol-specific
Third-party access Harder to administer at scale Individual vendor permissions
Monitoring Connection logs Session and activity records
OT suitability Depends on configuration Built around industrial workflows

This does not mean every VPN is insecure. A properly configured industrial VPN can work with segmentation, MFA, least privilege and monitoring. Zero-trust network access (ZTNA) and secure access service edge (SASE) may influence architecture, but industrial design must still reflect machines and consequences.

Core Controls For Secure Industrial Remote Access

Asset And Connection Visibility

Know which remote access routes exist, who owns them and which assets they reach. Identify undocumented gateways, old vendor accounts and unmanaged software.

Unique Accounts And Multi-Factor Authentication

Give each user an identifiable account with appropriate authentication and permissions. Shared engineering logins make access harder to control and investigate.

Least-Privilege And Time-Limited Access

Grant only the required machine, service or protocol and only for the necessary period. Use approvals, maintenance windows and prompt account removal.

Network Segmentation And Boundary Protection

Remote users should not receive unrestricted OT access.
OT cyber security
controls such as firewalls, zones and segmentation help contain connection paths.

Approved Endpoints And Supplier Devices

Consider engineering laptops, contractor devices and support systems before trusting them. Patching and device ownership should form part of the access decision.

Logging, Revocation And Isolation

Record who connected, when, which asset they reached and session duration. Keep a practical method for terminating access, disabling credentials and isolating connections during incidents.

HMS Networks provides a useful example: Ewon with Talk2M supports centralised management, MFA and a connection audit trail. These features do not replace policy, segmentation, endpoint protection or incident procedures.

Secure Remote Access For PLCs, HMIs And Industrial Machines

Remote machine access can support PLC fault diagnosis, HMI alarm review, approved configuration changes, commissioning, monitoring and OEM support at customer sites. It can reduce engineering travel and improve response times.

Ewon remote access is designed for these workflows. Ewon gateways connect engineers to PLCs, HMIs and machines through Talk2M using encrypted VPN communication. The Ewon Cosy+ range is an example for remote troubleshooting and maintenance where access needs to stay controlled and limited to the required machine resources.

Ewon Cosy industrial remote access gateway range

Remote Machine Access

A Controlled Route To The Equipment That Needs Support

An industrial remote access gateway can give an authorised engineer a controlled path to the intended PLC, HMI or machine without opening the wider OT network. This is where products such as Ewon fit naturally into the wider access-control process.

How To Plan Secure Remote Access Across Industrial Sites

  1. Identify assets and existing remote connections.
  2. Define the operational reason for each connection.
  3. Confirm who owns and approves access.
  4. Review user accounts and third-party permissions.
  5. Assess segmentation and external exposure.
  6. Select an architecture suited to the environment.
  7. Configure MFA, role-based permissions and time limits.
  8. Test during an approved maintenance period.
  9. Record and monitor remote sessions.
  10. Review access regularly and remove anything no longer required.
  11. Document an isolation and recovery process.

A network audit is often the right starting point because undocumented assets and unknown access routes cannot be controlled properly.

Choosing A Secure Remote Access Solution

Engineers, IT and OT managers and procurement teams should assess the operating model rather than encryption alone:

  • PLC, HMI and industrial protocol compatibility
  • Support for necessary legacy equipment
  • Encrypted communication
  • MFA and unique user accounts
  • Role-based and time-limited permissions
  • Centralised administration
  • Session and connection logs
  • Fast access revocation
  • Multi-site scalability
  • Product lifecycle and security updates
  • Technical support
  • Integration with existing network and industrial cyber security services

No product automatically makes an organisation compliant with NIS2, IEC 62443, ISO 27001 or another standard. Technology can support relevant controls, but governance, architecture, procedures, people and regular review remain part of the security programme.

Secure Remote Access FAQs

What Is Secure Remote Access?

Secure remote access is controlled and authenticated access to organisational systems from another location. In industry, it should restrict the user to approved machines, applications or protocols and record the connection. Encryption protects communication, while identity, permissions, monitoring and revocation control how that access is used.

Is A VPN Enough For Industrial Remote Access?

A VPN provides encrypted connectivity, but encryption alone does not define who can connect, which asset they can reach or how long access remains open. Industrial access also needs identity controls, restricted permissions, monitoring, endpoint checks, segmentation and a reliable process for revoking or isolating access.

How Can Remote Access Be Used For PLCs And HMIs?

An approved industrial gateway or platform can let authorised engineers troubleshoot, monitor or configure PLCs and HMIs remotely. The connection should be limited to the intended equipment and task, with appropriate authentication and logging, rather than exposing the PLC or HMI directly to the public internet.

How Should Vendor Remote Access To OT Systems Be Controlled?

Give each vendor user an identifiable account and apply MFA, approval, least-privilege permissions and time limits. Record connections and remove access when it is no longer required. Vendors should use an approved route rather than unmanaged gateways or permanent shared credentials.

Does Industrial Remote Access Prevent Every Cyber Incident?

No. Controlled remote access reduces exposure and can limit the effect of compromised credentials or connections, but it is one part of wider OT security. Segmentation, endpoint protection, monitoring, backup, recovery, change control and incident procedures are still needed to protect operational systems and maintain resilience.

Industrial IT And OT Support

Strengthening Secure Remote Access With M.A.C Solutions

Since 1996, we have supported industrial organisations with machine communications, connectivity and OT cyber security. We can assess remote access requirements, select suitable Ewon and networking technology and plan a controlled approach for maintenance, troubleshooting and continuity.

Discuss Industrial Remote Access