Shape

Contractor remote access: the weak link of industrial sites

OT CybersecurityBy AzertyUI Team

An industrial site works with many outside parties: machine builders, integrators, maintenance providers. To save time, many have installed their own remote access over the years. The result: multiple entry paths, often unknown to IT and rarely monitored.

What we see most often

  • A 4G modem plugged straight into a PLC for remote maintenance of a machine.
  • Remote-control software installed on a SCADA workstation, with a shared password.
  • A VPN permanently open to the industrial network, for a contractor who intervenes a few times a year.
  • Maintenance accounts never disabled after a contract ends.

Principles of controlled remote access

  • A single entry point: a gateway or access bastion, rather than one path per contractor.
  • Named accounts with strong authentication, never shared accounts.
  • On-demand access: opened for an intervention, approved by the operator, closed afterwards.
  • A limited scope: the contractor reaches only their machine, not the whole network.
  • Traceability: who connected, when, to what, and ideally a session recording.

Where to start

The first step is an inventory: physically locate modems and routers, list installed access software, review remote maintenance contracts. It is one of the first items of our OT cybersecurity assessment, and a central topic for sites in scope of NIS2, which requires supply-chain security.

For sectors with many dispersed sites, such as water and energy, it is often the most cost-effective project.

Related Tags

  • Accès distants
  • Bastion
  • Cybersécurité OT
  • NIS2
  • OT Cybersecurity
  • Remote access
  • Remote maintenance
  • Télémaintenance

Share This Article

Shape