TL;DR: Remote access has shifted from a maintenance convenience to a primary CPS attack vector, with weak VPNs, jump servers, and shadow access creating broad, poorly governed entry paths, according to SSH Communications Security citing Gartner. Secure operations now require identity-centric controls, just-in-time access, and command-level restriction, because network access no longer equals safe operational access.
Editorial analysis by NHI Mgmt Group, based on content published by SSH Communications Security: “Why CPS Secure Remote Access Is Shifting from Connectivity to Operations”.
Key questions
Q: What breaks when CPS remote access is granted through broad VPN-style connectivity?
A: Broad VPN-style connectivity breaks the assumption that authenticated network presence equals safe operational access.
Q: Why do shadow access paths create more CPS risk than visible managed access?
A: Shadow access creates more risk because it bypasses formal approval, review, and logging processes, so security teams cannot reliably see who connected, what they reached, or whether the access was still justified.
Q: What are the signs that CPS remote access is not governed tightly enough?
A: Common signs include unmanaged OEM tunnels, contractor accounts with broad reach, duplicate remote tools across plants, and sessions that can issue write commands without task-specific approval.
Practitioner guidance
- Inventory every CPS remote path Map VPNs, jump servers, OEM tunnels, contractor links, and ad hoc remote support paths to the assets they can reach, then identify any path that is not owned by a formal access process.
- Remove standing operational privilege Replace always-on access with just-in-time approval for maintenance and vendor support, especially where the session can reach devices that affect physical processes.
- Constrain access at the command layer Use protocol-aware controls that distinguish diagnostic commands from write or control commands, and deny actions that are not required for the approved task.
Bottom line: CPS remote access is now an operational identity control, not just a transport problem, because the same session can affect physical systems and safety outcomes.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Remote access has become an identity problem before it is a networking problem. The article shows that CPS operators are no longer dealing with occasional inbound connectivity. They are managing persistent operational access that can directly shape physical outcomes, which means the trust boundary has moved from the firewall to the identity session. The practitioner conclusion is that remote access governance now belongs in identity security programmes, not in isolated infrastructure teams.
A question worth separating out:
Q: How should teams balance operational uptime with CPS remote access control?
A: Teams should preserve uptime by constraining access, not by widening trust. The practical balance is to keep remote support available while limiting each session to the approved asset, approved time, and approved command set. That approach protects operations without treating permanent network reach as a substitute for governance.
👉 Read our full editorial: CPS remote access is becoming a primary identity risk