Running Safe Remote Maintenance Windows for Control Systems

Remote maintenance is where OT security and uptime collide. Use approved windows, supervised sessions, and rollback plans to keep vendors productive and safe.

3 min readBy Ironfield Cyber Team

Control systems need maintenance, and increasingly that maintenance happens remotely. A vendor engineer logs in to update controller logic, a technician troubleshoots an HMI from another state, or an integrator pushes a patch after hours. Remote work saves travel time and speeds repairs. It also opens one of the most significant paths into an operational network.

A maintenance window process lets you keep the benefit and control the risk. It does not need to be heavy. It needs to be consistent.

Why a Window, Not an Open Door

Many sites leave remote access permanently available because it is convenient. The downside is that the door is always open, and nobody is watching when someone walks through it. A maintenance window flips the model: access is closed by default and opened on purpose, for a specific person, task, and time.

Before the Window

Request and Approve

Every remote session starts with a request that states:

  • Who needs access, from which company
  • What system and what task
  • Planned start and end time
  • Expected impact on operations
  • Rollback plan if something goes wrong

An operations lead approves from a safety and production standpoint. An IT or security contact approves from a cyber standpoint. Record the approval, even if it is a simple ticket.

Prepare the Environment

  • Confirm a current backup of the affected controllers, configurations, and project files
  • Verify that the system is in a state where maintenance is safe, and coordinate with operators
  • Confirm patches or files are from the legitimate source and have been checked, ideally on a test system first
  • Make sure a local person is available to observe or intervene

During the Window

Enable Access Only for the Task

Open access to only the systems required, for the agreed period. Use individual named accounts with multifactor authentication, not shared vendor logins. Route access through a controlled entry point, such as a jump host in a secured zone, rather than direct connections to controllers.

Supervise the Session

Where possible, have a site representative watch the session or use session recording. Make sure the vendor knows they are expected to describe what they are changing. Keep communication open over a separate channel, such as a phone call, so the operator can stop the work if the process looks wrong.

Control Changes

  • Make only the approved changes
  • Document each change, with before and after states
  • Avoid bringing in unapproved tools or removable media
  • Stop if anything unexpected occurs, and escalate

After the Window

  1. Close the access path and disable or expire the vendor account
  2. Verify that systems are operating normally
  3. Take a fresh backup of the changed configuration
  4. Review logs from the session for anything beyond the approved scope
  5. Close the ticket with notes on what was done and the outcome
  6. Update asset records and documentation

Do not skip closure. The most common failure is a window that is opened and never properly shut.

Emergency Maintenance

Real breakdowns do not wait for paperwork. Define an emergency path that is faster but still controlled: verbal approval from a named person, the same technical safeguards, and a ticket completed within a day. Review emergency uses afterward to confirm they were truly emergencies.

Vendor Expectations

Put requirements into contracts and purchase terms:

  • Named individuals with unique credentials
  • Multifactor authentication
  • Notification when their staff leave or change roles
  • Compliance with your remote access procedure
  • Prompt notice if their own systems are compromised
  • Right to review their access logs

Ask equipment vendors how they secure their own remote support tools. A vendor who cannot answer clearly is a risk to your plant.

Measure and Improve

Track how many sessions happen, how many were scheduled versus emergency, how long accounts stayed active, and whether any windows ran over. Review quarterly with operations and IT. Patterns often reveal systems that need better local tools or vendors that need coaching.

Start Simple

If you currently have no process, begin by requiring a phone call or ticket before any remote session, and by disabling vendor accounts when work is complete. You can add recording and jump hosts as you mature.

Ironfield Cyber helps energy services companies and small utilities design remote access and maintenance procedures that respect uptime and safety. If you want to tighten vendor access without slowing your crews, we can help.