Skip to content

Cybersecurity

Secure remote access in OT environments: the most underestimated attack vector

Remote access to OT environments exploded after the pandemic, but security practices never caught up. Here is why it became the attackers' favorite entry vector.

4 min read
Secure remote access in OT environments: attack vectors and defensive controls

The OT remote access boom

Before 2020, remote access to industrial environments was the exception. Technicians were on site, vendors intervened physically, OT networks were isolated by definition. Then everything changed: mobility restrictions made remote access the only way to keep plants running, and what had been an exception became the norm.

Three years later, the picture is paradoxical: the vast majority of OT environments have active remote access connections, often installed in a hurry during the emergency and rarely reviewed afterwards. These connections stayed open even when no longer needed, proliferated with a different solution for every vendor, and were rarely folded into existing security programs.

The result: remote access is today the most used entry vector in attacks against industrial environments. Not because it is technically the most sophisticated, but because it is the least guarded.

Why remote access is dangerous in industrial environments

In IT environments, remote access is a problem that has been managed for years. Corporate VPNs, mandatory MFA, granular access policies, session recording: an entire ecosystem of mature solutions exists.

In OT, none of this transfers automatically. The reasons are structural:

  • Weak authentication: many legacy SCADA and HMI systems do not support MFA. The lowest common denominator ends up being a username and a password shared among different technicians.
  • Vendor credentials: the vendors that install the plant leave default access credentials behind. In the best case they are changed; in reality they often stay unchanged for years.
  • Permanent vs. occasional access: an IT technician connects to the corporate network every day. An OT maintainer reaches a PLC once every six months. But the connection stays open 24/7.
  • No visibility: unlike IT environments, where access logs are centralized and analyzed, in OT remote access often happens without leaving any traceable record.

VPN, RDP, proprietary tools: the real landscape

In a typical industrial plant, completely heterogeneous remote access solutions coexist. The corporate VPN covers perhaps 40% of cases. The rest is a patchwork: TeamViewer installed by whoever was on shift, direct RDP access to a SCADA workstation, proprietary tools from the automation vendor, cellular connections over 4G modems wired directly to the PLC.

This fragmentation creates three problems:

  1. Incomplete inventory: nobody knows how many remote access points exist. It is not unusual to discover active connections that no one remembered opening.
  2. Inconsistent policies: each solution has its own rules, often configured by the vendor that installed it without any coordination with the security team.
  3. Impossible audit: consolidating access logs from different systems is technically complex and often simply not done.

How to build secure remote access for OT

The solution is not to eliminate remote access, but to structure it. The goal is to replace the chaos with a single, controlled, monitored channel.

The principles that follow require dedicated remote access and privileged access management (PAM) tools, a category distinct from OT monitoring platforms like MON5: they are the gateway that enforces the rules, not the layer that observes them.

The core principles:

Just-in-time access: connections should not be permanent. A technician who needs to work on a PLC requests access, obtains a temporary session that expires automatically, and the window closes at the end of the job. There is no always-open door.

Strong authentication everywhere: even where the target system does not support MFA natively, the remote access gateway can enforce it before establishing the session to the OT device. MFA happens at the perimeter entry, not on the end system.

Segregation by zone: an automation vendor that needs to reach a specific production line should not have visibility into the entire OT network. The principle of least privilege applies geographically: access only to the systems it has been authorized for, nothing else.

Session recording and audit trail: every remote access session must be recorded and reviewable. Not only who connected and when, but also what they did. In the event of an incident, it is the difference between understanding what happened and groping in the dark.

Access monitoring and audit

Secure remote access is not a problem you solve once. It is a continuous process that requires:

  • Regular inventory of active connections: at least quarterly, with a formal approval process for every new connection.
  • Vendor review: every vendor with access should be subject to a periodic verification of privileges. Expired contracts, staff who have left the vendor company, completed scopes of work: all reasons to revoke access.
  • Anomaly alerting: out-of-hours access, unusually long sessions, connections from unfamiliar IPs. These weak signals often precede an incident.

Controlled remote access does not eliminate risk, but it drastically reduces the exposed surface and increases the chance of detecting anomalous behavior before it becomes an incident.

The MON5 angle

MON5 does not replace a remote access gateway: it makes the accesses visible and monitorable. Taking inventory of remote access connections is the first step, but many of those opened over the years appear in no document. MON5's DISCOVER phase passively reconstructs the network topology and surfaces active sessions toward the outside, including the ones no one remembered authorizing, without stopping production.

Once accesses are mapped, the continuous monitoring of the PROTECT phase flags the anomalous behavior described in this article: out-of-hours sessions, connections from unusual IPs, atypical durations. MON5 observes and reports, but the enforcement of just-in-time, MFA and session recording stays with the dedicated remote access tools. To find out how many open doors really exist in your network, start with an OT assessment.

Related articles

Industrial HMI login screen with the password field highlighted, a manufacturing plant in the background

Cybersecurity

Default credentials in OT systems: a more widespread problem than you might think

Admin/admin, 1234, the vendor's factory credentials: how many OT installations still have access protected by default passwords? More than you would expect. How it happens, how attackers find it, and how to fix it without stopping production.

6 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna