Glossary · OT cybersecurity
Secure remote access
Also known as: Secure remote maintenance
German: Sicherer Fernzugriff
In OT cybersecurity, secure remote access is remote access to industrial systems that is controlled by design: authenticated with strong credentials, authorized per person and task, routed through defined conduits such as a jump server or remote access gateway, time-limited, logged and, where needed, approved by the operator on site.
- OT security
In one sentence
Secure remote access routes remote connections to industrial systems through controlled gateways with strong authentication, approval, time limits and logging.
Example
A service engineer requests access through the vendor portal; the plant's shift lead approves the session, which runs through a jump server for two hours and is recorded.
How it applies
- Engineering: Typical building blocks are a gateway or Jump server in the DMZ, Multifactor authentication (MFA), individual accounts for each technician, access limited to the specific machine, and session recording. Permanent, always-on VPN tunnels from vendors into the plant network should be avoided.
- Operation: The operator stays in control: sessions are requested, approved and ended on site. For actions that can move machinery, on-site coordination is needed, because the remote user cannot see the danger zone.
- Maintenance: Accounts of former service staff and unused access paths must be removed; remote access paths are frequent entry points in incidents.
- Documentation: Service documentation should describe the remote access architecture, the approval process and which tasks may be done remotely. Safety instructions must state which functions are blocked or require a person on site.
Secure remote access vs. remote access
Remote access is any access from outside the local trust boundary. Secure remote access describes the controlled way of providing it.