TL;DR: Remote access has shifted from a maintenance convenience to a primary CPS attack vector, with weak VPNs, jump servers, and shadow access creating broad, poorly governed entry paths, according to SSH Communications Security citing Gartner. Secure operations now require identity-centric controls, just-in-time access, and command-level restriction, because network access no longer equals safe operational access.
At a glance
What this is: This is an analysis of why CPS remote access has become a primary identity risk, with Gartner framing legacy VPN-style access, shadow access, and broad network trust as the core problem.
Why it matters: It matters because operators now have to govern remote access as an operational identity control, not just a connectivity layer, especially where physical safety, uptime, and auditability depend on precise privilege scope.
Context
Remote access for cyber-physical systems is no longer an occasional maintenance exception. It has become a standing operational dependency across industrial and critical infrastructure environments, which means identity governance now has to account for routine access paths that were once temporary.
The governance gap is that many organisations still treat remote connectivity as if network admission is the same thing as safe operational access. In CPS environments, that assumption fails because the same session can expose devices, applications, and commands that directly affect physical processes.
Gartner's Market Guide for CPS Secure Remote Access is the trigger for this analysis, but the underlying issue is broader: legacy IT remote access models were built for systems that tolerate broad connectivity, not for environments where a single overbroad session can affect safety and resilience.
Key questions
Q: What breaks when CPS remote access is granted through broad VPN-style connectivity?
A: Broad VPN-style connectivity breaks the assumption that authenticated network presence equals safe operational access. In CPS environments, that model exposes devices and commands through a single trust decision, which is too coarse for safety-critical operations. The result is overbroad privilege, weak accountability, and access paths that can outlive the task they were meant to support.
Q: Why do shadow access paths create more CPS risk than visible managed access?
A: Shadow access creates more risk because it bypasses formal approval, review, and logging processes, so security teams cannot reliably see who connected, what they reached, or whether the access was still justified. In CPS, that lack of visibility is especially dangerous because access may reach systems that directly affect physical operations and safety.
Q: What are the signs that CPS remote access is not governed tightly enough?
A: Common signs include unmanaged OEM tunnels, contractor accounts with broad reach, duplicate remote tools across plants, and sessions that can issue write commands without task-specific approval. If security teams cannot answer which identities can reach which devices at command level, the governance model is already too loose.
Q: How should teams balance operational uptime with CPS remote access control?
A: Teams should preserve uptime by constraining access, not by widening trust. The practical balance is to keep remote support available while limiting each session to the approved asset, approved time, and approved command set. That approach protects operations without treating permanent network reach as a substitute for governance.
Technical breakdown
Why legacy VPN and jump server models break in CPS
Traditional VPNs and jump servers were designed to move users into a trusted network segment, not to govern what they can do inside a production industrial environment. Once authenticated, the session often carries broad network-level reach with limited awareness of device state, process context, or command sensitivity. That works poorly for CPS because the risk is not just data access, but write actions against assets that control physical operations. The technical failure is the absence of fine-grained authorization at the device, application, and command layers, which leaves too much trust attached to the connection itself.
Practical implication: treat network access as an entry condition, not as a sufficient control for CPS operations.
How shadow access defeats remote access governance
Shadow access is undocumented or unmanaged remote connectivity created by OEMs, contractors, or employees outside formal governance workflows. The issue is not simply that these links exist, but that they bypass visibility into who connected, from where, to which asset, and under what approval. In CPS environments, this creates a parallel access plane that standard access reviews and firewall rules may never fully capture. Because these sessions often sit outside enterprise identity controls, they also make audit trails incomplete and incident response slower. The governance problem is fragmented ownership across operations, security, and third parties.
Practical implication: inventory every remote path into CPS and classify any unmanaged connection as an identity control gap.
Why secure operations needs command-level control and session recording
Gartner's framing of secure operations reflects a shift from protecting the transport channel to protecting the action itself. In CPS, protocol-aware remote access can inspect native industrial commands and distinguish between safe diagnostic activity and dangerous write operations. That is materially different from generic session monitoring, because the control has to understand protocol semantics, not just record traffic. Just-in-time access and elimination of standing privilege matter here because they limit the window in which an operator, vendor, or contractor can issue sensitive commands. Session recording then becomes part of accountability, not merely forensics.
Practical implication: enforce least privilege at command level and require session evidence for high-risk operational actions.
Breaches seen in the wild
- SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.
- Schneider Electric Jira breach 2024: Credentials linked to a Lumma infostealer infection gave Hellcat access to Schneider Electric's Jira; 40GB and 400,000 user rows claimed.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Remote access has become an identity problem before it is a networking problem. The article shows that CPS operators are no longer dealing with occasional inbound connectivity. They are managing persistent operational access that can directly shape physical outcomes, which means the trust boundary has moved from the firewall to the identity session. The practitioner conclusion is that remote access governance now belongs in identity security programmes, not in isolated infrastructure teams.
Shadow access is the clearest sign that governance has fallen behind operations. When OEMs, contractors, or employees create undocumented remote paths, organisations lose the ability to answer basic control questions about who can reach what and under what conditions. That is not just a visibility issue. It is a lifecycle and accountability issue, because access exists outside formal approval, review, and offboarding processes. The practitioner conclusion is to treat unmanaged remote connectivity as a standing exception requiring remediation, not monitoring alone.
Secure connectivity is the wrong success metric for CPS remote access. The market is moving toward secure operations because broad, authenticated access can still be unsafe when the underlying command set can alter equipment state. Identity-centric Zero Trust, just-in-time access, and standing privilege removal matter because they reduce the amount of operational authority present in any one session. The practitioner conclusion is to measure whether access is operationally constrained, not merely whether it is encrypted.
Protocol awareness is the named concept that separates CPS access from generic remote access. Protocol-aware control means the access layer understands industrial commands well enough to allow benign diagnostics while blocking hazardous actions. That requirement is central because CPS risk lives at the command boundary, not just at login. The practitioner conclusion is to govern remote access on protocol semantics and command intent, not on connectivity alone.
Zero Trust for CPS only works when it reaches the action layer. The article reinforces that generic trust reduction is insufficient if the session still grants broad write capability after authentication. Gartner's emphasis on granular access and audit trails aligns with the broader Zero Trust principle that trust must be continuously justified. The practitioner conclusion is to align CPS remote access controls with device, application, and command scope, not with network reach.
What this signals
Remote access governance for CPS is converging with identity security because the control point is shifting from the network edge to the operational session. That means teams need one view of who can connect, what they can do, and how long that authority exists.
Protocol-aware access: this is the practical dividing line between generic remote connectivity and CPS secure operations. If the access layer cannot distinguish diagnostics from write actions, the organisation is still trusting the connection instead of governing the command.
For practitioners
- Inventory every CPS remote path Map VPNs, jump servers, OEM tunnels, contractor links, and ad hoc remote support paths to the assets they can reach, then identify any path that is not owned by a formal access process.
- Remove standing operational privilege Replace always-on access with just-in-time approval for maintenance and vendor support, especially where the session can reach devices that affect physical processes.
- Constrain access at the command layer Use protocol-aware controls that distinguish diagnostic commands from write or control commands, and deny actions that are not required for the approved task.
- Require session evidence for high-risk access Record and review remote sessions that can change plant state, with logs detailed enough to support audit, incident reconstruction, and operator accountability.
Key takeaways
- CPS remote access is now an operational identity control, not just a transport problem, because the same session can affect physical systems and safety outcomes.
- Legacy VPNs, jump servers, and shadow access leave too much authority in place once a user is authenticated, which weakens visibility and accountability.
- Command-level restriction, just-in-time access, and session recording are the controls that align remote access with secure operations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Broad VPN and jump server sessions give CPS remote users more authority than the task requires. |
| NHI-10 — Human Use of NHI | OEM, contractor, and operator remote paths often rely on shared or misapplied non-human access patterns. | |
| Recommendation — Reduce CPS remote sessions to task-scoped authority and remove standing overprivilege. Separate human-operated support access from machine and vendor credentials in CPS. | ||
| NIST Zero Trust (SP 800-207) | Policy enforcement and continuous verification | The article calls for identity-centric Zero Trust and continuous control over CPS remote sessions. |
| Recommendation — Apply continuous verification to CPS sessions and bind access to device, command, and task context. | ||
| CIS Controls v8 | CIS-5 — Account Management | Shadow access and unmanaged remote accounts are ultimately account lifecycle failures. |
| Recommendation — Inventory, review, and retire every CPS remote access account and tunnel on a governed schedule. | ||
| MITRE ATT&CK | TA0001;TA0008 — Initial Access; Lateral Movement | Weak remote access is the entry path and expansion mechanism described in the article. |
| Recommendation — Map CPS remote access exposure to initial access and lateral movement techniques in detection tuning. | ||
Key terms
- Shadow Access: Shadow access is unauthorised or unmanaged access that continues to exist because a credential, role, or account was forgotten, reused, or never properly revoked. In NHI programmes, shadow access is especially dangerous because it can remain active across cloud, SaaS, and automation layers without obvious human ownership.
- Protocol-aware access: A remote access approach that understands industrial protocol semantics rather than treating all authenticated traffic the same. It can distinguish safe diagnostic commands from potentially harmful write actions, which is essential when the access path can alter physical systems.
- Secure Operations: An access model that protects the work performed after login, not just the login itself. In CPS, secure operations means identity, privilege, and session controls are tuned to physical and safety impact rather than ordinary data access risk.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org