Securing Remote Access to SCADA and Control Systems

Vendors and engineers need remote access to control equipment, but it is a top entry point for attackers. Here is how to set it up and manage it safely.

3 min readBy Ironfield Cyber Team

Remote access is the feature that makes operational technology convenient and, if done carelessly, dangerous. Oilfield service companies, small utilities, water systems, and industrial plants all rely on engineers and vendors who connect remotely to troubleshoot controllers, update logic, or check on a remote site. Convenience often arrives before security, and many sites still run on a remote tool installed years ago that nobody has reviewed since.

CISA and other agencies have repeatedly warned about internet-exposed control system devices and weak remote access. The fixes are practical, and most do not require replacing equipment.

Start by finding every path in

You cannot manage what you do not know about. List every way someone can reach control equipment from outside:

  • VPN connections to the plant or field site.
  • Remote desktop or screen sharing tools on HMI or engineering workstations.
  • Cellular modems and routers at remote sites.
  • Vendor-installed tools or cloud portals.
  • Wireless links between sites.

Ask operations, the controls engineer, and each equipment vendor. Then verify with a scan or network review, because informal remote access often exists that nobody remembers.

Never expose control devices directly to the internet

Controllers and HMIs should not be reachable from the open internet. If a device appears on public scanning services, anyone can find it and try default passwords or known weaknesses. If you find an exposed device, treat it as urgent: move it behind a firewall and a secure remote access method.

Use a single, managed entry point

Instead of many one-off tools, set up one controlled path:

  1. A remote access gateway or VPN terminating in a separate zone between the business network and the control network, often called a demilitarized zone or DMZ.
  2. Multi-factor authentication for every user.
  3. Individual accounts for each person, with no shared logins.
  4. Session logging, and where practical, recording of sessions.
  5. Access limited to the specific systems each user needs.

Jump hosts

A hardened jump host in the DMZ lets users reach control systems through one monitored point instead of connecting directly from their own computers. It also keeps the vendor's laptop off your control network.

Manage vendor access as a process

Vendors often need access, and that is fine. Manage it deliberately:

  • Require a request and approval for each access window, ideally with an operator aware that a session is occurring.
  • Disable accounts between sessions when practical.
  • Define access in the contract: who, what, from where, and under what security conditions.
  • Review vendor accounts every quarter and remove those no longer needed.
  • Require vendors to notify you if their own staff or systems are compromised.

Protect the endpoints used for access

A strong gateway does not help if the engineer's laptop carries malware. Set minimum standards for devices that connect: current patches, endpoint protection, disk encryption, and no personal use during sessions.

Segment remote sites

Remote well sites, pump stations, and lift stations often use cellular routers with default settings. Change default passwords, disable unused services, use private APNs or VPN tunnels where available, and limit what each site can reach. A compromise of one small site should not give access to the whole network.

Monitor and log

Record who connected, when, from where, and to which device. Review the logs for access outside normal hours or from unexpected locations. Alert on repeated failed logins. If monitoring is not practical in-house, a managed security provider can watch the logs.

Have a way to cut access fast

Document how to disable all remote access immediately during a suspected incident. Make sure operations knows the procedure and that manual operation is possible when remote links are shut off.

A quick checklist

  • Inventory of all remote paths.
  • No direct internet exposure for controllers or HMIs.
  • MFA and individual accounts everywhere.
  • A DMZ or jump host for vendor sessions.
  • Approval and logging for each session.
  • Quarterly review of accounts.
  • A tested emergency shutoff of remote access.

Working with Ironfield Cyber

Ironfield Cyber helps energy and industrial companies review remote access, segment networks, and set up managed access for vendors, in coordination with your operations team. A short review of your current remote paths is a good first step.