Join our Newsletter — 33% off our NHI Course

What happens when remote access to critical infrastructure is left unsegmented and poorly governed?

Attackers who gain access can reach systems that affect physical operations, not just data. In water environments, that can mean exposure of PLCs, SCADA components, and other OT devices that control essential services. The result can be service disruption, difficult investigations, and a much larger recovery effort than a conventional IT incident.

Why Unsegmented Remote Access Turns OT into an Enterprise-Wide Exposure

When remote access is not segmented, the path into a business network can become a path into operational technology as well. That matters because OT systems are not just records systems, they are control systems. If remote users, jump paths, or vendor connections can traverse flat trust boundaries, the attacker is no longer confined to IT data, but can reach the systems that run physical processes.

The core issue is trust collapse. A remote access channel that is treated as “just another login” often inherits broad network reach, weak device-to-device isolation, and poor accountability. In critical infrastructure, that combination increases the chance that a compromise of one remote path becomes a compromise of multiple control domains.

Segmentation is the control that limits what a remote session can actually touch. Without it, a stolen credential, abused VPN account, or misrouted support tunnel can connect an outsider to PLCs, SCADA interfaces, historian systems, engineering workstations, or other supervisory components that were never meant to be directly reachable from general-purpose access paths.

This is why remote access governance in critical environments has to be designed around NIST SP 800-207 Zero Trust Architecture, not around simple network reachability. It also aligns with the operational focus of CISA Industrial Control Systems guidance and the critical-infrastructure expectations reflected in EU NIS2 Directive requirements for risk management and access control.

What Goes Wrong When Governance is Weak

Poor governance usually shows up as excessive privilege, weak approval boundaries, long-lived access, and little visibility into who connected, from where, and to what. In OT, those weaknesses matter more because remote access is often granted for maintenance, emergency support, or vendor operations, which makes it tempting to leave standing access in place.

Once that happens, the blast radius expands fast. A compromised support account can be used to pivot from remote administration into control networks, alter configurations, or interrupt process availability. Even when the attacker does not issue destructive commands, the uncertainty created by possible tampering can force operators into containment actions that interrupt service and complicate recovery.

Well-governed environments make that path harder by limiting session scope, enforcing approval for elevated access, and logging enough detail to reconstruct what was touched. Poorly governed environments do the opposite: they reduce detection quality, slow investigations, and make it hard to prove whether a disruption was accidental, malicious, or the result of a remote management error.

For practitioners, the pattern is familiar. Remote access problems are rarely only about connectivity. They are usually about governance failure around trust, privilege, and change control, which is why Ultimate Guide to NHIs — Key Challenges and Risks is useful here as a control reference for overprivilege, visibility gaps, and unmanaged credentials. The same issue appears in real-world compromise cases such as Schneider Electric credentials breach, where exposed credentials created unauthorized access into an industrial environment.

Risk and Threat Considerations

Unsegmented remote access creates a direct attack path from an external foothold into systems that control physical operations. The practical risk is not just data theft, but process disruption, unsafe operational states, and recovery work that can be far more disruptive than a conventional IT incident.

Failure mechanism: An attacker compromises or abuses a remote access channel, then pivots laterally because the network and authorization boundaries do not stop movement from remote entry points into OT supervisory and control assets.

Impact: The attacker may reach PLCs, SCADA components, engineering workstations, or supporting OT services, creating the potential for service interruption, loss of control confidence, emergency shutdowns, and slow, high-friction restoration.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the technical controls, and NIS2 define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC — Access Control Remote access governance depends on limiting who can reach OT assets.
Recommendation — Enforce least-privilege access paths and segment remote sessions to approved OT targets.
NIST Zero Trust (SP 800-207) SC — Policy Enforcement and Segmentation Zero Trust directly addresses untrusted remote access paths into critical systems.
Recommendation — Apply policy enforcement to verify each remote request before allowing OT reachability.
CIS Controls v8 6 — Access Control Management Remote access to critical infrastructure needs account and privilege control.
Recommendation — Restrict and review remote accounts, privileges, and access paths to critical assets.
NIS2 Art. 21 — Cybersecurity Risk-Management Measures NIS2 requires access control and risk management for essential and important entities.
Recommendation — Implement access segmentation and governance as part of ICT risk management.
MITRE ATT&CK T1021 — Remote Services Abused remote services are a common path for attacker lateral movement.
T1219 — Remote Access Software Remote support tooling is often abused to retain access and control systems.
Recommendation — Monitor remote services for unauthorized access and lateral movement into OT zones. Harden and monitor remote access tools for misuse, persistence, and privilege abuse.

Practitioner Guidance

What to prioritise: Treat segmentation and access scope as the first control question, not an afterthought. If a remote session can reach both enterprise IT and OT, assume the blast radius is already too large and reduce the reachable set before expanding monitoring or adding more approval steps.

What to verify: Confirm that every remote path is tied to a named purpose, a bounded target set, and a clear session owner. A good test is whether an operator can explain, from logs alone, which system was accessed, why it was reachable, and how quickly the path can be revoked if the account or vendor is compromised.

Practitioner takeaway: In critical infrastructure, the real control objective is not simply remote access, it is remote access that is constrained enough that a compromise cannot become an operator-to-controller path.