OT CybersecurityBy AzertyUI Team

An industrial site works with many outside parties: machine builders, integrators, maintenance providers. To save time, many have installed their own remote access over the years. The result: multiple entry paths, often unknown to IT and rarely monitored.
What we see most often
- A 4G modem plugged straight into a PLC for remote maintenance of a machine.
- Remote-control software installed on a SCADA workstation, with a shared password.
- A VPN permanently open to the industrial network, for a contractor who intervenes a few times a year.
- Maintenance accounts never disabled after a contract ends.
Principles of controlled remote access
- A single entry point: a gateway or access bastion, rather than one path per contractor.
- Named accounts with strong authentication, never shared accounts.
- On-demand access: opened for an intervention, approved by the operator, closed afterwards.
- A limited scope: the contractor reaches only their machine, not the whole network.
- Traceability: who connected, when, to what, and ideally a session recording.
Where to start
The first step is an inventory: physically locate modems and routers, list installed access software, review remote maintenance contracts. It is one of the first items of our OT cybersecurity assessment, and a central topic for sites in scope of NIS2, which requires supply-chain security.
For sectors with many dispersed sites, such as water and energy, it is often the most cost-effective project.
Related Tags
- Accès distants
- Bastion
- Cybersécurité OT
- NIS2
- OT Cybersecurity
- Remote access
- Remote maintenance
- Télémaintenance


