TL;DR: Critical infrastructure teams are being judged on browser-based access, scalability and legacy compatibility, while SSH Communications Security’s PrivX OT was recognized by KuppingerCole in secure remote access for OT and ICS and the same week received an honorable mention in Gartner’s 2025 PAM Magic Quadrant, underscoring how critical infrastructure teams are being judged on browser-based access, scalability and legacy compatibility. The real issue is not analyst recognition, but whether PAM controls can govern distributed OT access without weakening operational continuity.
Editorial analysis by NHI Mgmt Group, based on content published by SSH Communications Security: “PRESS RELEASE: SSH Communications Security Recognized as a Leader in all Categories in KuppingerCole’s 2025 Secure OT Access Report”.
Key questions
Q: How should security teams govern remote privileged access in OT environments?
A: They should treat OT remote access as privileged access governance, not simple connectivity.
Q: Why do legacy OT systems make PAM harder to govern?
A: Legacy OT systems often limit how much the control plane can be changed, so organisations rely on compensating access controls instead of refactoring the asset itself.
Q: What breaks when just-in-time access is not aligned to maintenance workflows?
A: Teams start bypassing the control to keep the plant running, which usually recreates standing privilege through exceptions and manual approvals.
Practitioner guidance
- Map OT remote access by operational scenario Separate routine operator access, vendor support, and emergency break-glass use so each path has its own approval, session control, and audit trail.
- Enforce just-in-time access for maintenance work Grant privileged OT access only for a defined task and target scope, then revoke it automatically when the session ends or the maintenance window closes.
- Test legacy-system compatibility against authorization boundaries Validate that browser-based or protocol-agnostic access still preserves least privilege, session isolation, and command-level control on older OT assets.
Bottom line: OT access governance breaks down when teams optimise for compatibility but fail to constrain privilege at the session level.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
OT access governance fails when organisations treat compatibility as the control objective. The article shows that browser access, scalability, and legacy support are being rewarded in the market, but those attributes do not by themselves govern identity risk. In OT, the control question is whether temporary access can be granted without expanding privilege across plants, vendors, and support paths. Practitioners should judge any PAM design by whether it constrains session scope at the moment of use.
A question worth separating out:
Q: Should organisations treat browser-based OT access as a security control?
A: No. Browser-based access is a delivery method, not a governance outcome. It can make access easier to deploy and manage, but the security value comes from the policy layer, including authorization, session oversight, and revocation when the task is complete.
👉 Read our full editorial: SSH PrivX OT recognition highlights PAM gaps in secure OT access