Day 10 – Remote Access in OT: Necessary, But High Risk Remote access is one of the most important — and most dangerous — capabilities in OT security. Manufacturing plants depend on it. Vendors need it to troubleshoot equipment. Engineers need it to support production. Operations teams need it to reduce downtime. But if remote access is poorly designed, it can become a direct path into the plant floor. OT remote access is risky because many environments were originally designed for local, physical access — not persistent external connectivity. Common weaknesses include: • Direct VPN access into OT networks • Shared vendor credentials • No MFA at the OT boundary • Unrecorded remote sessions • Persistent access after support work ends • Direct RDP, VNC, or SSH to HMIs and engineering workstations • Vendor tools installed without monitoring • No clear owner for third-party access In a manufacturing environment, this can become a serious issue. Example: A packaging equipment vendor connects remotely to troubleshoot a drive issue. Without proper controls, that vendor session may have broad network access, shared credentials, no session recording, and no automatic expiration. If the vendor account is compromised, the attacker may not need malware or a zero-day. They already have a trusted path into the environment. A secure OT remote access model should include: • Industrial DMZ jump server as the mandatory access point • PAM-brokered sessions • MFA before entering the DMZ • Just-in-time access tied to a work order • Named individual vendor accounts • Session recording and monitoring • Time-limited connections with automatic termination • No split tunneling • No direct RDP or SSH from IT into OT • Access scoped to specific assets, protocols, and time windows • Regular vendor access reviews ZTNA is also becoming important in OT, but it must be implemented carefully. Traditional VPN grants network-level access. ZTNA should broker access to specific OT assets through identity-aware, policy-controlled connections. But in OT, Zero Trust is not just a product. It is an operating model: • Verify identity. • Validate device posture. • Scope access. • Limit duration. • Record the session. • Monitor behavior. • Revoke immediately when the work is complete. AI SOC can also strengthen remote access monitoring by correlating PAM logs, VPN events, firewall traffic, OT NDR alerts, asset inventory, and change records. For example, if a vendor session occurs outside an approved window and is followed by unexpected PLC communication, that should become a high-priority alert. The key principle: Remote access should never mean open access. In OT, every remote connection must be owned, approved, scoped, monitored, recorded, and revocable. Because in manufacturing, remote access is not just an IT convenience. It is a production, safety, and business continuity risk. #SCADA #RemoteAccess #PAM #ZTNA #ManufacturingSecurity #CyberSecurity
Remote Access Capabilities
Explore top LinkedIn content from expert professionals.
Summary
Remote access capabilities allow users to connect to systems, networks, or devices from a distance, making it possible to troubleshoot, manage, and monitor equipment without needing to be onsite. This technology is vital for maintaining productivity and security in environments like manufacturing plants, building management systems, and remote work scenarios.
- Define secure entry: Always require a dedicated access point and individual authentication to help prevent unauthorized connections and protect sensitive assets.
- Monitor and record: Enable session monitoring and recording so you can track remote activity, quickly spot anomalies, and maintain accountability for all users.
- Control access duration: Set clear time limits and immediate revocation policies for remote sessions to minimize risks once work is completed.
-
-
I need ongoing support for my building control system what can a BAS provider do remotely? Preventative maintenance for Building Automation Systems (BAS) or Building Management Systems (BMS) increasingly leverages remote capabilities, allowing for efficient system monitoring, diagnostics, and updates without the need for on-site presence. Here are some key preventative maintenance tasks that can typically be performed remotely: 1. System Monitoring and Diagnostics Real-Time Monitoring: Utilizing software to continuously monitor system performance and parameters such as temperature, humidity, energy consumption, and system alerts. Trend Analysis: Analyzing data trends to identify potential issues before they become critical, such as increasing energy usage that might indicate equipment failure. 2. Software Updates and Patches Firmware Updates: Remotely updating firmware for controllers, sensors, and other components to ensure the latest security patches and features are in place. Software Upgrades: Applying software updates to improve system performance, add new functionalities, or address known issues. 3. Alarm Management Alarm Configuration and Optimization: Adjusting alarm settings to ensure critical alerts are prioritized and false alarms are minimized. Alarm Response: Quickly addressing system alerts remotely to diagnose and, in some cases, resolve issues without needing to dispatch a technician. 4. Parameter Adjustments Control Setpoints: Remotely adjusting setpoints for temperature, humidity, CO2 levels, etc., based on occupancy patterns or environmental changes. Scheduling: Updating system schedules for HVAC, lighting, and other controlled systems to match building usage, thus optimizing energy consumption. 5. Data Backup and Recovery System Backups: Performing regular backups of system configurations and data to prevent loss in case of a hardware failure or other issues. Recovery Procedures: In case of system failure, remotely restoring system configurations and parameters from backups. 6. Remote Calibration This might be more limited compared to physical calibration but can include adjustments based on known calibration curves or by comparing sensor readings across the system. 7. Energy Management Energy Usage Analysis: Remotely reviewing energy consumption data to identify inefficiencies. Implementing Energy Savings Measures: Adjusting system settings to reduce energy consumption without compromising comfort or safety. These tasks leverage the connectivity and smart capabilities of modern BAS/BMS to maintain optimal performance and reliability. The ability to perform these tasks remotely not only increases the efficiency of maintenance efforts but also significantly reduces the need for physical visits, which can be especially beneficial in large or geographically dispersed properties.
-
𝗪𝗲 𝘂𝘀𝗲 𝗮 𝗩𝗣𝗡. That's a good start—but it's not an OT remote access strategy. VPN, Jump Host and PAM are not competing technologies. They solve different problems, and the strongest OT architectures use them together. 🔹 𝗩𝗣𝗡 • Encrypts the communication path to the OT network. • Authenticates remote users. • Does not control privileged activities after the connection is established. 🔹 𝗝𝘂𝗺𝗽 𝗛𝗼𝘀𝘁 • Provides a single hardened entry point into the OT environment. • Centralizes remote access and improves session visibility. • Helps reduce opportunities for lateral movement. 🔹 𝗣𝗔𝗠 (𝗣𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲𝗱 𝗔𝗰𝗰𝗲𝘀𝘀 𝗠𝗮𝗻𝗮𝗴𝗲𝗺𝗲𝗻𝘁) • Protects privileged credentials through credential vaulting. • Enables just-in-time and time-bound privileged access. • Provides session recording, auditing and accountability. 💡 𝗔 𝘀𝗶𝗺𝗽𝗹𝗲 𝘄𝗮𝘆 𝘁𝗼 𝗿𝗲𝗺𝗲𝗺𝗯𝗲𝗿: 🚪 VPN → Gets you to the door. 🏢 Jump Host → Controls which room you can enter. 📝 PAM → Records what you did and ensures you only had the right privileges for the right time. 𝗥𝗲𝗰𝗼𝗺𝗺𝗲𝗻𝗱𝗲𝗱 𝗢𝗧 𝗿𝗲𝗺𝗼𝘁𝗲 𝗮𝗰𝗰𝗲𝘀𝘀 𝗮𝗿𝗰𝗵𝗶𝘁𝗲𝗰𝘁𝘂𝗿𝗲: Vendor / Engineer ⬇ VPN ⬇ Jump Host ⬇ PAM ⬇ OT Assets (PLC • HMI • Historian • Engineering Workstation) 𝗞𝗲𝘆 𝘁𝗮𝗸𝗲𝗮𝘄𝗮𝘆: A VPN secures the connection. A Jump Host secures the entry point. A PAM solution secures privileged access. Together, they provide a far more resilient remote access architecture for OT than any one technology alone. #OTSecurity #ICSSecurity #IndustrialCybersecurity #RemoteAccess #PAM #JumpHost #ZeroTrust #VendorAccess #IEC62443 #CriticalInfrastructure
-
🔥 NETWORKING INTERVIEW CHALLENGE: Remote Troubleshooting Mastery Scenario: Data center with 7 switches in a rack - suddenly one uplink cable fails. You're working remotely with no physical access to equipment, can't see status LEDs, and can't touch hardware. The Challenge: How do you identify the faulty switch using only remote management tools? Pro Engineer's 4-Step Remote Troubleshooting Approach: 🔍 Step 1: Connectivity Analysis Use ping and traceroute commands to map network topology Identify where connectivity breaks occur in the path 🔍 Step 2: CDP/LLDP Discovery Execute 'show cdp neighbors' on all accessible switches Missing neighbor relationships reveal the faulty switch location 🔍 Step 3: Interface Status Review Run 'show ip int brief' across all devices Look for ports showing 'down/down' status or error-disabled states 🔍 Step 4: Log Analysis Check system logs with 'show log' command Identify link flap events and CRC errors pointing to hardware failure Why This Question Matters: This scenario tests real-world network troubleshooting skills that every network engineer faces. It demonstrates logical thinking, systematic approach, and mastery of essential networking protocols and commands. Perfect for assessing candidates' ability to work under pressure and solve complex problems without physical access - a critical skill in today's remote-first IT environment. #NetworkEngineering #ITInterviews #Troubleshooting #NetworkAdmin #TechCareers
-
Internet traffic from remote devices is one of the most underestimated blind spots in enterprise security. Remote work is now a permanent reality. Employees connect from home networks, coffee shops, hotels, and public Wi-Fi. While secure tunnels like DirectAccess allow access to corporate resources, Internet traffic may still bypass the company network if it is not properly controlled. When this happens, security teams lose visibility. Corporate filtering, inspection, and monitoring policies may no longer apply to remote devices. The good news? Microsoft Intune can help mitigate this risk. By enforcing the right policy through the Intune Settings Catalog, organizations can control how Internet traffic is routed when remote clients connect to the corporate network. Instead of relying on network location or user behavior, traffic control becomes enforced by policy. This ensures that security controls remain active even when users work outside the office. Why This Matters Without proper traffic routing controls, remote access may allow: • Internet traffic to bypass corporate security inspection • Reduced monitoring of remote user activity • Increased exposure when connecting from public networks With Microsoft Intune, organizations can: ✅ Route remote Internet traffic through the corporate network ✅ Maintain visibility and monitoring outside the office ✅ Enforce corporate security filtering policies ✅ Strengthen endpoint and remote access security ✅ Support Zero Trust security principles In this article, I show how to configure this policy using Microsoft Intune, assign it to device groups, monitor deployment status, and validate enforcement directly on the endpoint. Because in modern endpoint security, remote traffic should never become a blind spot. How is your organization controlling Internet traffic for remote devices today? Full tunnel? Split tunnel? Secure proxy? Or Intune-managed policies? #MicrosoftIntune #EndpointSecurity #WindowsSecurity #ZeroTrust #CyberSecurity
-
Anthropic’s “Remote Control” for Claude Code is being framed as convenience, run your AI coding agent from mobile. Everyone’s calling this a mobile feature. It’s not. It’s an infrastructure shift. The headline is remote access from your phone. The real story is in the architecture. Useful. But not the interesting part. The interesting part is what doesn’t move to the cloud. Execution stays local, your machine, your filesystem, your environment. The phone or browser is just a window into a live session. Not a new instance. Not a cloud replica. The same active state continues. Three architectural signals: 1. Local execution, remote interface No inbound ports. TLS-secured, short-lived credentials. The security boundary stays on your machine. 2. Stateful session continuity You’re not starting a new prompt. You’re attaching to an active session closer to SSH than chatting with a bot 3. Explicit environment isolation Each Claude Code instance runs its own remote session. No shared state. No cross-session bleed. Subtle at the feature level. Significant at the infrastructure level. The pattern is clear: AI coding tools are evolving from stateless chat interfaces to persistent agents embedded inside local dev environments. That changes how we think about: • Developer security boundaries • Workflow control • What “AI in the stack” means when the agent has stateful access The mobile interface is the surface layer. As local AI agents become persistent and stateful, how are you thinking about your dev security posture?
-
Simplifying Secure Remote Access with Point-to-Site VPN Excited to share my detailed documentation on configuring a Point-to-Site (P2S) VPN using Azure! This guide walks through the complete process, from creating a Virtual Network to successfully connecting a local machine to an Azure-hosted VM using a private IP address. P2S VPNs are ideal for secure and cost-effective remote access, making them a go-to solution for modern businesses. If you're looking to enhance your remote work setup or strengthen your network's security, this document is for you. Check it out and feel free to share your feedback! #Networking #VPN #Azure #RemoteAccess #CloudSolutions
-
Industrial control systems: Remote access protocol >> This publication is broken into three sections: >Design principles: The design principles include topics such as time limiting the connection, strong authentication, and the creation of well managed devices. > Implementation principles: The implementation principles provide guidance on good approaches for satisfying the design principles. > The protocol: Once the design and implementation principles have been followed, the specified protocol, or procedure, for remote access may be followed. Top 10 Principles for Secure Remote Access to ICS (from ACSC's Remote Access Protocol) More inside the document 1. Default Deny – No persistent remote access; allow only in critical cases. 2. Network Segmentation – Use strict firewalls, DMZs, and jump boxes. 3. Time-Limited Access – One-time credentials, auto-expire in 24 hrs, disconnect after 30 mins idle. 4. Multi-Factor Authentication – Mandatory MFA with user-specific attribution. 5. Physical Disconnects – Prefer cable removal or keyed switches when not in use. 6. Vendor Device Control – Use dedicated, hardened laptops for Australian ICS only. 7. No Password Sharing – Internal credentials must be typed by asset owner staff. 8. Full Session Logging – Record who connected, what was done, and keep logs for 5 years. 9. Inline Traffic Capture – Monitor sessions with decrypted/full visibility for auditing. 10. Approval + Witnessing – All access approved by senior officers & witnessed end-to-end. Enjoy reading! #icssecurity #Otsecurity
-
**Understanding Cisco IOS: An Overview** 🔹 **What is Cisco IOS?** Cisco IOS (Internetwork Operating System) is a multitasking operating system used on Cisco routers and switches. It provides a command-line interface (CLI) for configuring and managing routing, switching, internetworking, and other network features. 🔹 **Historical Context** Earlier Cisco switches used **CatOS**, a legacy operating system. However, **IOS** has become the industry standard, widely adopted for network configuration and management tasks. 🔹 **First-Time Device Start-up** When a Cisco device (like the Cisco 3745 router) is powered on for the first time, it displays system information such as CPU speed, memory, and interfaces. For example: > "Press RETURN to get started!" 🔹 **How to Access Cisco IOS?** There are three common ways to access IOS: 1. **Console Access** Used for new devices without an IP address. This requires a **rollover cable** (serial) to connect your PC to the device’s console port. 2. **Telnet Access** A method to remotely access IOS over the network using **TCP port 23**. However, Telnet transmits data in clear text, making it insecure for sensitive configurations. 3. **SSH Access** **SSH** is the secure alternative to Telnet, encrypting all data communications via **public-key cryptography** over **TCP port 22**. It is the preferred method for secure remote device management. 🔹 **IOS Modes** IOS operates in different modes to provide flexibility in configuration: 1. **User EXEC Mode** The default mode where only basic commands (ping, telnet) are available. 2. **Privileged EXEC Mode** Accessed by the `enable` command. Here, you can view and change the device configuration. 3. **Global Configuration Mode** Entered using the `configure terminal` command from privileged EXEC mode. It allows device-wide configuration changes. 👉 **Sub-Modes in Configuration** To configure specific components like interfaces, you must enter the corresponding sub-mode. For example, to configure an interface, use the command: `interface FastEthernet 0/1` 🔹 **Conclusion** Understanding the IOS modes and how to access it are fundamental for network engineers and IT professionals. Whether it's through console, Telnet, or SSH access, mastering IOS enables better network management and security. #Cisco #Networking #IOS #NetworkConfiguration #ITProfessional #Tech #CyberSecurity
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development