Remote Access to Plant Controls: Safer Options Than a Shared VPN

Vendors and operators need remote access to controls, but a shared VPN login is risky. Compare safer approaches that keep technicians connected and sites safe.

3 min readBy Ironfield Cyber Team

Remote access is one of the most useful and most dangerous features in an industrial environment. A technician can diagnose a compressor from three hours away instead of driving out at midnight. An integrator can adjust a program without flying in. But every remote path into a control network is also a potential path for an attacker.

CISA and other agencies have repeatedly highlighted remote access and exposed control devices as common entry points for attacks on industrial environments. For construction and energy companies with remote sites and many vendors, the problem is amplified because access tends to accumulate: one VPN account here, a vendor's modem there, a remote desktop tool someone installed years ago.

What goes wrong with a shared VPN

A single VPN login shared by multiple vendors or employees often seems simple. In practice, it creates serious issues.

  • No accountability. If something changes, you cannot tell who did it.
  • Passwords that never change because too many people would need to be told.
  • No easy way to revoke one person's access when they leave.
  • Broad network access. Once connected, the user can often reach everything, not only the one device they need.
  • No multi-factor authentication, because the account is not tied to a person.

Principles for safer remote access

One person, one identity

Every remote user should have their own named account. Vendors should provide the names of the individuals who need access, and those accounts should be disabled when the work ends.

Multi-factor authentication

Require MFA for all remote access, including vendors. If a vendor cannot support it, treat that as a risk to be reduced by other means, such as enabling access only on request.

Least privilege

Limit each account to the specific systems it needs. A pump vendor should reach the pump controller, not the entire site network.

Access on demand

Rather than leaving connections open permanently, enable them only when a task is scheduled. Many solutions allow an operator to approve a session, which also creates a natural record.

Log and review

Keep logs of who connected, when, and to what. Review them periodically, and watch for connections at odd hours.

Architecture options

A jump host in a protected zone

Remote users connect first to a hardened intermediate system, then from there to the control device. The jump host enforces authentication, logging and restrictions. Control devices are never directly reachable from the internet.

Industrial remote access platforms

Several vendors offer products designed for operational environments, with per-user accounts, session recording and approval workflows. Evaluate them for how they authenticate users, where data is stored, and whether they work with the equipment you actually have.

Vendor-managed cellular gateways

These are convenient but should be treated cautiously. Ask who manages the gateway, who can reach it, and whether you can disable it. Document every one.

What to avoid

Port forwarding a control device to the internet, consumer remote desktop tools installed without review, and shared passwords written on a whiteboard.

A short action plan

  1. List every remote access method into every site, including vendor modems and software installed years ago.
  2. Identify which devices each method can reach.
  3. Replace shared accounts with named accounts and MFA.
  4. Limit access to specific systems and enable it on demand where possible.
  5. Add remote access requirements to vendor contracts, including notification of personnel changes.
  6. Review logs on a regular schedule.

Working with your vendors

Vendors generally respond well to clear requirements stated up front. Put them in contracts and purchase orders: named users, MFA, no shared credentials, and notification when staff change.

How Ironfield Cyber helps

Ironfield Cyber helps construction and energy companies inventory remote access paths, design safer architectures, and write vendor access requirements. If you are not sure how many ways into your sites exist today, that inventory is the right first step.