TL;DR: KuppingerCole’s Leadership Compass on secure remote access for OT/ICS argues that IT/OT convergence is widening attack surfaces while policy-enforced, session-monitored access becomes operationally necessary across critical sectors, according to SSH Communications Security. The governance shift is clear: remote access now depends on time-bound, auditable identity controls, not generic connectivity.
At a glance
What this is: KuppingerCole’s leadership compass frames OT/ICS secure remote access as an identity governance issue, not just a network connectivity problem.
Why it matters: IAM, PAM, and NHI teams need to treat industrial remote access as policy-enforced, session-monitored identity control because legacy OT environments cannot rely on generic remote connectivity.
Context
Secure remote access for OT/ICS sits at the point where identity governance meets industrial operations. The article argues that once IT and OT networks are interconnected, access control is no longer only about network reachability; it becomes about who can enter a production environment, for how long, and under what conditions.
Industrial systems still include legacy equipment that was not designed with modern authentication, encryption, or audit expectations. That creates an identity problem for remote administration because access has to be layered in at the bridge point, not assumed inside the plant.
The result is a shift from generic remote connectivity toward policy-enforced, monitored access that supports maintenance, incident response, and uptime without exposing sensitive process layers. For OT/ICS programmes, that is a governance change as much as a technical one.
Key questions
Q: What breaks when OT remote access is still treated as a connectivity problem?
A: When industrial remote access is treated as simple connectivity, teams lose the ability to enforce identity context, monitor session behaviour, and contain lateral movement. That creates a trust gap between successful login and safe operation. In OT and ICS environments, the failure is not authentication alone but the absence of governed access boundaries around the session.
Q: Why do time-bound remote sessions matter in OT/ICS environments?
A: Time-bound sessions reduce standing exposure in environments where maintenance access is necessary but risky. They limit how long a privileged path exists, which is crucial when legacy systems cannot enforce strong controls locally and when every remote support session must be defensible later.
Q: What are the signs that remote access controls are too broad for sensitive internal systems?
A: Remote access is too broad when users can reach more systems, files, or functions than their job requires, especially if clipboard, file transfer, or unrestricted shell access is left open by default. Another warning sign is access that stays active after role changes. If sessions are not restricted, recorded, or tied to specific targets, the control boundary is already too loose.
Q: Should OT security teams use the same access model for maintenance and emergency support?
A: No. Emergency access may need faster activation, but it should still be brokered, monitored, and limited by the same identity controls as planned maintenance. The difference is in the activation path, not in the requirement for accountability.
Technical breakdown
Why OT remote access becomes an identity control point
In OT/ICS environments, the industrial network is often segmented by the Purdue model, with the most sensitive process layers protected from direct access. Remote access solutions sit around Levels 3 and 3.5, where operators and vendors perform maintenance, configuration, and emergency support without opening direct paths into Levels 1 and 2. That means the control is not simply transport over a VPN. It is an identity decision about which user, session, protocol, and time window are allowed to touch operational assets. In practice, identity becomes the enforcement layer for legacy industrial estates that cannot absorb modern authentication natively.
Practical implication: Model OT remote access as privileged identity governance, not as a generic network service.
How session monitoring and time-bound access reduce industrial risk
The article contrasts secure remote access with broad remote connectivity by emphasizing policy enforcement, session monitoring, MFA, and time limits. Those controls matter because OT environments must preserve availability while preventing uncontrolled movement across fragile systems. Time-bound access reduces standing exposure, session logging creates forensic traceability, and protocol-specific controls limit what a user can actually do once connected. This is especially important where legacy devices lack native authentication or encryption, because the access broker has to carry the security burden that the endpoint cannot.
Practical implication: Require short-lived, auditable sessions with protocol restrictions for every privileged industrial connection.
Why identity controls matter more than generic remote tools in OT/ICS
Generic remote desktop or VPN tools typically provide connectivity first and governance second. In OT/ICS, that is backwards. Industrial operators need controls that can preserve uptime while preventing malware propagation and lateral movement between production segments. The article points to zero-trust style access, real-time logging, and integration with SIEM and SOAR as the operational layer that makes remote support defensible. The technical point is that visibility without policy is not enough, and policy without session evidence is not auditable. Secure remote access therefore functions as both a control plane and an evidence plane for industrial identity activity.
Practical implication: Choose remote access designs that generate enforcement evidence, not just connectivity telemetry.
Threat narrative
Attacker objective: The objective is to gain operational reach into industrial systems through legitimate remote access paths and use that access to disrupt, alter, or observe critical processes.
- Entry occurs through remote support paths that reach OT/ICS assets without direct exposure of the most sensitive process layers. That entry point is attractive because maintenance and emergency access are operationally necessary.
- Credential or session misuse becomes the next risk when access is not time-bound, monitored, or protocol-specific. In that condition, a legitimate remote path can be abused to move laterally or alter systems that should have remained insulated.
- Impact follows if malware propagation, unauthorized configuration change, or unsafe operational activity reaches production assets. In OT, the consequence is not only data loss but disruption to safety, uptime, and physical processes.
Breaches seen in the wild
- SonicWall SSL VPN account compromises 2025: Attackers used valid credentials to log in to more than 100 SonicWall SSL VPN accounts across 16 environments in October 2025.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Secure remote access is now an identity governance layer for OT/ICS: the article correctly places remote access at the boundary where legacy industrial systems meet modern authentication and audit requirements. In that boundary, the control is not connectivity alone but who can enter, when they can enter, and what they can touch. For practitioners, that means OT access should be governed like privileged identity, not treated as infrastructure plumbing.
The identity risk in OT is standing access to fragile systems: legacy devices often cannot authenticate or encrypt on their own, so the access broker becomes the security control of record. That shifts responsibility to the remote access programme to enforce time limits, protocol scope, and continuous session visibility. The practical implication is that identity assurance must live in the access path, not at the device edge.
Policy-enforced session control is the real alternative to generic remote connectivity: if a remote tool cannot constrain protocol behaviour, bound session duration, and emit audit evidence, it is not adequate for industrial operations. The article shows why zero-trust style access matters in OT/ICS, but the deeper point is governance continuity across maintenance, emergency response, and compliance. Practitioners should treat the session as the governed object.
Operational resilience and identity control are converging in industrial environments: availability requirements do not reduce the need for access control, they intensify it. The better the remote access process supports uptime, the more important it becomes to ensure that each access path is monitored, reversible, and attributable. That is the new baseline for OT/ICS identity programmes.
Industrial remote access needs a named control concept: session-brokered industrial access: this is the pattern where the broker, not the endpoint, enforces identity, protocol, and time constraints for OT support. It matters because it converts remote access from an open path into a governed, inspectable session. Practitioners should design OT access around this control point rather than around convenience-led connectivity.
What this signals
Session-brokered industrial access: OT/ICS programmes should treat the remote access broker as the enforcement point for identity, protocol, and time. That shifts the security conversation from network reachability to governed session behaviour, which is the only model that fits legacy industrial systems.
Industrial environments will continue to need remote support, but the access path has to be narrow enough to preserve safety and broad enough to support uptime. The practical signal for practitioners is that remote access design now belongs in IAM and PAM planning, not only in network operations.
For practitioners
- Define OT remote access as privileged identity flow Classify every industrial remote session as a privileged access event and route it through identity governance rather than network-only approval.
- Enforce short-lived, protocol-specific sessions Set time-bound access windows and limit each session to the protocol needed for the maintenance or support task.
- Require session recording and real-time monitoring Capture industrial remote sessions end to end so investigators can reconstruct configuration changes, commands, and operator actions.
- Separate legacy OT access from general remote connectivity Use a dedicated remote access control path for plant systems so broad VPN or desktop access does not become the default support route.
Key takeaways
- OT/ICS remote access is an identity governance problem because the access layer has to compensate for legacy systems that cannot secure themselves.
- The operational evidence in the article points to policy-enforced, session-monitored access as the control model that matters most for industrial environments.
- Practitioners should govern plant remote access as privileged identity activity, with short-lived sessions, protocol limits, and full auditability.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | OT remote access needs tightly governed entitlements and session scope. |
| Recommendation — Apply PR.AA-05 to restrict industrial remote access by role, purpose, and session boundary. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Time-bound remote access depends on authenticator lifecycle and expiry control. |
| AC-17 — Remote Access | The article is fundamentally about governing remote administrative access into OT/ICS. | |
| Recommendation — Use IA-5 to enforce short-lived authenticators and revoke industrial remote credentials promptly. Apply AC-17 to broker, authorize, and monitor every remote industrial support session. | ||
| CIS Controls v8 | CIS-5 — Account Management | Industrial access must be managed as a lifecycle problem, not an open connection. |
| Recommendation — Use CIS-5 to inventory and control accounts used for OT remote support. | ||
| NIST Zero Trust (SP 800-207) | Section 2.1 — Zero Trust architecture principles | The article's access model relies on continuous verification and narrow trust boundaries. |
| Recommendation — Apply Zero Trust principles to make remote OT access session-based and continuously verified. | ||
Key terms
- Secure Remote Access: Secure remote access is the controlled method of reaching systems from outside their normal operating boundary. In industrial environments it must combine identity verification, session governance, and protocol constraints so that support access does not become unrestricted operational control.
- Session-Brokered Access: A remote access pattern where a broker enforces identity, protocol scope, and session duration before a connection reaches an industrial asset. For OT/ICS, this is the practical way to turn remote support into an auditable control rather than a permanent connectivity channel.
- Purdue Model: The Purdue model is an industrial network segmentation framework that separates enterprise IT from operational control layers. It helps define where remote access may be brokered, which layers are most sensitive, and why direct connectivity into lower OT levels creates unacceptable risk.
- Protocol-specific Access: Protocol-specific access limits a session to the exact industrial protocol required for a task, such as SSH, RDP, Modbus, or OPC UA. This avoids broad network reach and helps prevent misuse, accidental change, and lateral movement across mixed IT and OT environments.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org