Cybersecurity
Secure remote access in OT environments: the most underestimated attack vector
Remote access to OT environments exploded after the pandemic, but security practices never caught up. Here is why it became the attackers' favorite entry vector.

The OT remote access boom
Before 2020, remote access to industrial environments was the exception. Technicians were on site, vendors intervened physically, OT networks were isolated by definition. Then everything changed: mobility restrictions made remote access the only way to keep plants running, and what had been an exception became the norm.
Three years later, the picture is paradoxical: the vast majority of OT environments have active remote access connections, often installed in a hurry during the emergency and rarely reviewed afterwards. These connections stayed open even when no longer needed, proliferated with a different solution for every vendor, and were rarely folded into existing security programs.
The result: remote access is today the most used entry vector in attacks against industrial environments. Not because it is technically the most sophisticated, but because it is the least guarded.
Why remote access is dangerous in industrial environments
In IT environments, remote access is a problem that has been managed for years. Corporate VPNs, mandatory MFA, granular access policies, session recording: an entire ecosystem of mature solutions exists.
In OT, none of this transfers automatically. The reasons are structural:
- Weak authentication: many legacy SCADA and HMI systems do not support MFA. The lowest common denominator ends up being a username and a password shared among different technicians.
- Vendor credentials: the vendors that install the plant leave default access credentials behind. In the best case they are changed; in reality they often stay unchanged for years.
- Permanent vs. occasional access: an IT technician connects to the corporate network every day. An OT maintainer reaches a PLC once every six months. But the connection stays open 24/7.
- No visibility: unlike IT environments, where access logs are centralized and analyzed, in OT remote access often happens without leaving any traceable record.
VPN, RDP, proprietary tools: the real landscape
In a typical industrial plant, completely heterogeneous remote access solutions coexist. The corporate VPN covers perhaps 40% of cases. The rest is a patchwork: TeamViewer installed by whoever was on shift, direct RDP access to a SCADA workstation, proprietary tools from the automation vendor, cellular connections over 4G modems wired directly to the PLC.
This fragmentation creates three problems:
- Incomplete inventory: nobody knows how many remote access points exist. It is not unusual to discover active connections that no one remembered opening.
- Inconsistent policies: each solution has its own rules, often configured by the vendor that installed it without any coordination with the security team.
- Impossible audit: consolidating access logs from different systems is technically complex and often simply not done.
How to build secure remote access for OT
The solution is not to eliminate remote access, but to structure it. The goal is to replace the chaos with a single, controlled, monitored channel.
The principles that follow require dedicated remote access and privileged access management (PAM) tools, a category distinct from OT monitoring platforms like MON5: they are the gateway that enforces the rules, not the layer that observes them.
The core principles:
Just-in-time access: connections should not be permanent. A technician who needs to work on a PLC requests access, obtains a temporary session that expires automatically, and the window closes at the end of the job. There is no always-open door.
Strong authentication everywhere: even where the target system does not support MFA natively, the remote access gateway can enforce it before establishing the session to the OT device. MFA happens at the perimeter entry, not on the end system.
Segregation by zone: an automation vendor that needs to reach a specific production line should not have visibility into the entire OT network. The principle of least privilege applies geographically: access only to the systems it has been authorized for, nothing else.
Session recording and audit trail: every remote access session must be recorded and reviewable. Not only who connected and when, but also what they did. In the event of an incident, it is the difference between understanding what happened and groping in the dark.
Access monitoring and audit
Secure remote access is not a problem you solve once. It is a continuous process that requires:
- Regular inventory of active connections: at least quarterly, with a formal approval process for every new connection.
- Vendor review: every vendor with access should be subject to a periodic verification of privileges. Expired contracts, staff who have left the vendor company, completed scopes of work: all reasons to revoke access.
- Anomaly alerting: out-of-hours access, unusually long sessions, connections from unfamiliar IPs. These weak signals often precede an incident.
Controlled remote access does not eliminate risk, but it drastically reduces the exposed surface and increases the chance of detecting anomalous behavior before it becomes an incident.
The MON5 angle
MON5 does not replace a remote access gateway: it makes the accesses visible and monitorable. Taking inventory of remote access connections is the first step, but many of those opened over the years appear in no document. MON5's DISCOVER phase passively reconstructs the network topology and surfaces active sessions toward the outside, including the ones no one remembered authorizing, without stopping production.
Once accesses are mapped, the continuous monitoring of the PROTECT phase flags the anomalous behavior described in this article: out-of-hours sessions, connections from unusual IPs, atypical durations. MON5 observes and reports, but the enforcement of just-in-time, MFA and session recording stays with the dedicated remote access tools. To find out how many open doors really exist in your network, start with an OT assessment.
Related articles

Cybersecurity
Default credentials in OT systems: a more widespread problem than you might think
Admin/admin, 1234, the vendor's factory credentials: how many OT installations still have access protected by default passwords? More than you would expect. How it happens, how attackers find it, and how to fix it without stopping production.
Cybersecurity
OSINT on Industrial Plants: What Attackers Find Before You Do
Before launching an attack, threat actors look for publicly available information about their targets. Shodan, Censys and other OSINT tools can find OT systems exposed on the internet in seconds. Understanding what they see is the first step to reducing your own exposure.
Cybersecurity
OT Network Segmentation: from the Purdue Model to IEC 62443 Zones in Production
Network segmentation is the OT security control with the best cost/effectiveness ratio. From the Purdue model to IEC 62443 zones, how to implement it in production without stopping the plant.
Do you have visibility into your OT network?
MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.