Who this is for: IT, maintenance and production managers organising remote support for industrial equipment.
An industrial remote-access project should define the permitted activity before selecting a tool. Reading a log, observing a machine state and modifying a program are different operations. They should not be treated as a single permanent permission granted to a supplier.
Connectivity is only one part of the service. Establish who authorises work, who is present on site, which assets are reachable and how access can be interrupted. Production, maintenance and IT need to agree these decisions, involving the security specialists appropriate to the environment.
Inventory existing people, tools and connections
Establish how suppliers currently connect. The inventory should cover installed tools, accounts, reachable devices, permission owners and support arrangements. Even an infrequently used connection needs an accountable owner and an identifiable purpose.
Remote access requires active management and control: CISA guidance highlights the risks of misuse of these tools. For project planning, compare authorised arrangements with access that is actually available and record differences requiring clarification.
References: CISA — Guide to Securing Remote Access Software
Separate observation from changes
Describe permitted activities in language understandable to the person authorising support. For each one, identify the recipient, asset and level of intervention. This distinguishes routine assistance from changes needing preparation, a backup or an on-site presence.
Scroll horizontally to see every column.
| Activity | Question to resolve | Useful evidence |
|---|---|---|
| Read logs | Which information does the supplier need? | Data list and permitted access period |
| Diagnostics | Who authorises and follows the session? | Support request and on-site contact |
| Software changes | Which revision changes and how can it be recovered? | Starting/final versions and approved procedure |
| Contract ends | Who removes or revokes access? | Named owner and revocation check |
Assess architecture against plant constraints
OT security design must also consider availability, performance and the safety of the physical process, as NIST explains. A measure suitable for an ordinary office computer should not automatically be transferred to every control device.
Ask how environments are separated, identities managed, sessions approved and records retained. Identify dependencies on external services and behaviour when connectivity is unavailable. The objective is a solution that can be checked in its actual setting, rather than a product label treated as sufficient assurance.
References: NIST SP 800-82 Rev. 3 — OT Security
Create a support procedure people can use
Define a straightforward flow: request, approval, session opening, agreed activity, final checks and closure. Address urgent exceptions without allowing them to become the normal operating method. An excessively complicated procedure invites workarounds; an overly general one makes the intervention hard to reconstruct.
A practical record might include the machine, reason for support, company contact, external technician, time window and permitted operations. At closure, record changes, checks completed and outstanding questions. Adapt this project worksheet with the responsible teams; it is not a security or compliance attestation.
Questions for the technical discussion
- Which connections and accounts already exist, and who owns them?
- Which activities require reading, diagnosis or modification?
- Who authorises, follows and closes each session?
- How are versions, recovery and service interruption managed?
- How is access revoked when work or a contract ends?
Common questions
Does installing a VPN complete the project?
No. Identities, permissions, reachable assets, session management, responsibilities and operating procedures still need definition. Evaluate the selected technology against these requirements and the plant environment.
Does the supplier need permanent access?
That decision needs justification based on the activity and its constraints. Specify when access is required, who controls it and how it is revoked. Continuous availability should not be assumed necessary for every support arrangement.
Sources and further reading
Apply this to your project.
If remote support is part of your automation project, describe the assistance required and the teams involved. We can help frame the technical scope to coordinate with your IT and security specialists.
Discuss your automation project