Remote assets such as wellheads, pump stations, lift stations, and metering sites often connect to a central control room over cellular modems or radio links. These connections let a small team monitor and operate many sites without driving to each one. They also create pathways into control systems that run outside your fences and often outside your line of sight.
The same convenience that makes remote links valuable makes them a common weak point. This post covers practical steps for securing them.
The common problems
Many remote sites share the same issues.
- Modems left with factory default passwords
- Public IP addresses reachable from the internet
- Open management interfaces
- Old firmware that has never been updated
- No inventory of how many modems exist or where
- Shared SIM plans with no restrictions on where traffic can go
- Vendor remote access that stays on permanently
Internet-exposed devices can be found by anyone scanning for them, so a default password on a reachable modem is a serious problem.
Step 1: Inventory every wireless link
List every modem, radio, and gateway with:
- Location and the equipment it serves
- Make, model, and firmware version
- Carrier, SIM, and plan details
- How it is managed and by whom
- What data it carries and where that data goes
- The date it was last reviewed
Be thorough, since forgotten devices are the most dangerous.
Step 2: Keep devices off the public internet
Where possible, use a private cellular network or carrier-provided private access point name, which keeps modem traffic off the public internet and delivers it directly to your network or a secure gateway. If private service is not available, use encrypted tunnels from the modem back to a central firewall, and block unsolicited inbound connections.
Ask your carrier or integrator what options exist for restricting which destinations a SIM can reach.
Step 3: Change defaults and tighten management
- Replace default usernames and passwords with unique, strong credentials per device
- Disable management interfaces that you do not use
- Restrict administration to specific addresses
- Turn off services such as remote web access if they are not required
- Store credentials in a secured password manager, not on a spreadsheet kept on a shared drive
Step 4: Update firmware thoughtfully
Vendors do publish security fixes for modems and radios. Create a process to check for updates, test them on a spare unit, and schedule deployment in a way that does not interrupt critical operations. Where devices are hard to reach, plan updates during routine site visits and use vendor tools for remote updates only after testing.
Step 5: Protect radio links
If you use licensed or unlicensed radio links, consider encryption and authentication features if your equipment supports them. Older radios may transmit without encryption, which allows interception or spoofing. Ask the manufacturer about security options and plan upgrades for equipment that lacks them.
Step 6: Segment and filter
A remote site should only communicate with what it needs. Use firewall rules to allow the specific protocols and destinations required, and to deny everything else. The control network at the site should not be able to browse the internet, and a compromise of one site should not reach the rest of your network. Segment remote sites from each other where architecture permits.
Step 7: Monitor and alert
Watch for signs that something is wrong.
- A modem offline unexpectedly
- Unusual data usage on a SIM
- New devices appearing on the remote network
- Failed login attempts on the modem
- Configuration changes
Unexpected data usage can be an early clue that a device is being misused, so set usage alerts through your carrier.
Step 8: Control vendor access
Vendors often maintain remote systems through the same links. Require scheduled, approved, logged sessions, use individual accounts, and disable access when work is complete. Do not leave standing remote access enabled without a clear reason.
Step 9: Plan for physical access
Remote sites are often unmanned, which means anyone could reach the equipment. Use locked enclosures, tamper sensors where practical, and port blockers. Remove or lock SIM cards where possible, since a stolen SIM may allow access to your private network.
A hypothetical example
Consider a hypothetical operator with thirty small remote sites, each with a cellular modem. A review reveals that a third have default credentials and public addresses. A staged plan could address the exposed units first, move the rest to a private network, and standardize configuration for new installations, all through scheduled site visits rather than emergency trips.
Where Ironfield Cyber helps
Ironfield Cyber helps energy and utility operators assess remote connectivity, from cellular modems to radio links, and design secure, maintainable configurations. If you are not sure how many wireless links you have or how they are exposed, we can help you find out.