TL;DR: KuppingerCole’s Leadership Compass on secure remote access for OT/ICS argues that IT/OT convergence is widening attack surfaces while policy-enforced, session-monitored access becomes operationally necessary across critical sectors, according to SSH Communications Security. The governance shift is clear: remote access now depends on time-bound, auditable identity controls, not generic connectivity.
Editorial analysis by NHI Mgmt Group, based on content published by SSH Communications Security: “Securing Industrial Operations: KuppingerCole Provides an Analysis of the Growing Role of Secure Remote Access in the OT/ICS Market”.
Key questions
Q: What breaks when OT remote access is still treated as a connectivity problem?
A: When industrial remote access is treated as simple connectivity, teams lose the ability to enforce identity context, monitor session behaviour, and contain lateral movement.
Q: Why do time-bound remote sessions matter in OT/ICS environments?
A: Time-bound sessions reduce standing exposure in environments where maintenance access is necessary but risky.
Q: What are the signs that remote access controls are too broad for sensitive internal systems?
A: Remote access is too broad when users can reach more systems, files, or functions than their job requires, especially if clipboard, file transfer, or unrestricted shell access is left open by default.
Practitioner guidance
- Define OT remote access as privileged identity flow Classify every industrial remote session as a privileged access event and route it through identity governance rather than network-only approval.
- Enforce short-lived, protocol-specific sessions Set time-bound access windows and limit each session to the protocol needed for the maintenance or support task.
- Require session recording and real-time monitoring Capture industrial remote sessions end to end so investigators can reconstruct configuration changes, commands, and operator actions.
Bottom line: OT/ICS remote access is an identity governance problem because the access layer has to compensate for legacy systems that cannot secure themselves.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Secure remote access is now an identity governance layer for OT/ICS: the article correctly places remote access at the boundary where legacy industrial systems meet modern authentication and audit requirements. In that boundary, the control is not connectivity alone but who can enter, when they can enter, and what they can touch. For practitioners, that means OT access should be governed like privileged identity, not treated as infrastructure plumbing.
A question worth separating out:
Q: Should OT security teams use the same access model for maintenance and emergency support?
A: No. Emergency access may need faster activation, but it should still be brokered, monitored, and limited by the same identity controls as planned maintenance. The difference is in the activation path, not in the requirement for accountability.
👉 Read our full editorial: Secure remote access for OT/ICS is now an identity problem