Remote Access: The Number One Way Into OT
Remote access is one of the most useful things that has happened to industrial operations. Vendors can troubleshoot a compressor from another continent, and on-call staff can check an alarm without driving to site at 2 a.m. It is also, time and again, the door attackers walk through, because remote access paths tend to grow quietly, one urgent request at a time, until nobody has the full picture.
Why remote access is such a common entry point
Very few OT environments set out to have weak remote access. It usually accumulates. Common patterns include:
Vendor VPNs: a supplier is given a VPN account during commissioning, and it is never removed when the project ends.
Always-on connections: site-to-site tunnels or vendor connections that stay up permanently, even though they are only needed a few times a year.
Shared accounts: one login used by a whole vendor team or by every shift, so nobody can tell who connected or when.
Ad hoc remote desktop tools: TeamViewer, AnyDesk and similar products installed directly on an HMI or operator workstation to solve an immediate problem, often bypassing the firewall entirely.
Cellular modems and routers: dropped into a panel at a remote site for convenience, creating a path to the control network that does not appear on any drawing.
Unhardened jump hosts: a "secure" intermediate server that is unpatched, shares credentials with the corporate domain or allows anyone who reaches it to go anywhere.
Each of these is understandable on its own. Together, they can give an attacker with one stolen password a direct route into the systems that run the process.
A well-known example
The 2021 ransomware attack on Colonial Pipeline is often cited here. The company's chief executive told the US Senate that attackers gained access through a legacy VPN account that was no longer in active use and was not protected by multi-factor authentication. The ransomware affected business systems, and the company shut down pipeline operations as a precaution while it assessed the situation. The FBI attributed the attack to the DarkSide ransomware group.
The lesson is not that VPNs are bad. It is that a single forgotten account, with only a password standing in the way, can lead to a major operational decision. Industrial security advisories from government agencies have repeatedly highlighted exposed and poorly protected remote access as a leading concern for OT owners.
Start with a full inventory of access paths
You cannot secure a path you do not know about. The first step is to find every way someone can reach the OT environment from outside it:
VPN concentrators and the accounts configured on them
Remote desktop and screen-sharing tools installed on OT hosts
Vendor-supplied remote support appliances and cloud connectors
Cellular, satellite and radio links, especially at remote sites
Dial-up modems that may still exist on older equipment
Firewall rules that allow inbound connections to the control network
Passive network monitoring, firewall configuration review and site walkdowns all help. Interviews with vendors and controls staff often reveal paths that no tool would find.
What good remote access looks like

Once you know what exists, the goal is to funnel all remote access through a small number of controlled, monitored routes. Good practice includes:
Brokered access through the DMZ: remote users land in an industrial demilitarized zone (DMZ) between corporate IT and OT, and only reach control systems through a hardened jump host or remote access gateway.
No direct internet-to-Level 2 connections: nothing from the internet, or even from the corporate network, should connect straight to supervisory systems or controllers at Level 2 and below of the Purdue model.
Multi-factor authentication (MFA): required for every remote session, including vendors and administrators.
Unique, named accounts: every person has their own account, so actions can be traced and access removed when someone leaves.
Just-in-time, time-boxed access: vendor accounts are disabled by default and enabled for a specific window when there is an approved reason, then switched off again.
Session recording and supervision: high-risk sessions are recorded, and in some cases watched live by site staff who can end them.
Least privilege: each user reaches only the systems they need for the job at hand, not the whole network.
A kill switch: a simple, well-understood way to cut all remote access quickly during an incident, which operations staff know how to use.
Keep reviewing it
Remote access is not a one-time fix. New vendors arrive, projects end and urgent workarounds creep back in. Build in regular checks:
Review remote access logs for unusual times, locations or volumes
Reconcile active accounts against current contracts and staff lists at least quarterly
Re-check OT hosts for newly installed remote desktop tools
Confirm that cellular modems and other out-of-band links are still approved and still needed
Test the kill switch, so you know it works before you need it
Make remote access part of vendor contracts, too. Suppliers should agree to use your approved method, protect their own credentials and notify you of staff changes.
How QBits Networks can help
Our secure remote access reviews map every path into your OT environment, from VPN accounts to forgotten modems, and compare them against practical good practice. We then help you prioritize changes that tighten control without getting in the way of the vendors and staff who depend on that access. Tell us what you need through our contact page and we'll scope it with you.