The term Secure Remote Access has been overused in today’s Operational Technology world. It is impossible to read any blog, attend any industry conference, or listen to a podcast where it is not mentioned. With so many vendors in the space and each one putting their own spin on what it is, why it is matters, and why you need it, the noise is deafening. Adding to this confusion is the influx of IT-focused staff and technology entering the space with their own thoughts and visions on the topic. Analysis paralysis has set in, causing companies to hold off on making a decision on how to properly implement it within their organization. With the attacks on critical infrastructure increasing every day, companies must start taking charge of their Secure Remote Access direction before it’s too late.

 

Defining Secure Remote Access

Before we discuss what Secure Remote Access (SRA) is and why we need it in Operational Technology (OT), we need to define it.

 

Secure Remote Access (SRA) is defined by NIST as authorized, protected, and monitored access to an organization’s information systems by users or devices communicating through external, non-organization-controlled networks.

 

And while this definition helps define SRA overall, it leaves out a few key points that we need to understand. OT is not IT, and both areas do some things differently when it comes to people, process, and technology. While IT embraces the use of Virtual Private Networks (VPN) for Secure Remote Access within their environments, OT regulatory guidance and security best practices deeply discourages their implementation and use for many reasons. Additionally, IT networks are considered to be external and untrusted, even if they are controlled by the IT organization. While there are many reasons for this, the core security risk reason is that 75% of the cyber-attacks that occur within OT originate from IT network connectivity.

 

Why do we need Secure Remote Access in OT?

 

Now that we have defined the concept of Secure Remote Access, we now need to understand why we need it in Operational Technology. While there has been some form of outside access into Industrial Control Systems (ICS) within OT for many years, Covid played a significant role in increasing the need for access as contractors, vendors, and operational staff were not able to travel on-site to perform their roles or tasks. Much of this access was put in place ad-hoc and quickly to ensure system uptime and availability and without much forethought about operational safety or cybersecurity risks. This led to many organizations taking IT driven access methods such as VPN, 5G phone home cellular, and even unsecured cable modems and putting them in place. Unfortunately, many of these methods were never removed or redone with OT Safety and Security best practices put in place.

 

Today with the growth of Smart Factories (Industry 4.0), the large scale retiring of OT staff (Peak 65), the AI driven demand to access critical operational data within ICS resources (all of which will be covered in more detail in future blogs) the need to gain remote access to legacy and modern computing systems safely and securely has grown even bigger.

 

This reach has expanded as well. There is a growing need to reach legacy and modern computing resources at challenging locations such as oil drilling platforms miles off the coast, quarries, mines, rail, wastewater, and water systems. Modern infrastructure locations are driving the need for Secure Remote Access as well. These include Distributed Energy Resources such as solar, wind, hydroelectric, geothermal, Battery Energy Storage Systems (BESS), smart city/grid infrastructure, EV charging systems, and lights out data centers and factories to name just a few.

 

Who needs Secure Remote Access?

 

Secure Remote Access today is not only for remote contractors, vendors and IT/OT staff. The need is a growing need for its use for contractors, vendors and OT staff who walk the grated floor as well.

 

While there is also an equally expanding need for getting access to data for analytics, monitoring, reducing Mean Time To Detect (MTTD), improving Operational Efficiency (OE), reducing Mean Time Between Failure (MTTB) and more, those will be covered in a future dedicated blog.

 

Contractors and vendors, both remote and on-site, in many cases require direct connectivity between their laptops, locally installed applications and internal OT devices such as PLCs and RTUs. This Bring Your Own Device / Application (BYOD/BYOA) approach gives them direct device and network level access to the OT environment. This level of access brings safety and security risks, including introducing malware, uncontrolled network access and movement, access to sensitive data and resources, to name just a few. By implementing a modern Secure Remote Access application-level approach to access, contractors can now safely and securely perform their required job tasks without network-level, access and organizations can mitigate, the threats and risks discussed above.

 

For on-site staff and operators, use cases such as having Mobile HMI Access can now allow them to not be tethered to a fixed production line, work area, or line-of-sight status indicator. They can securely and safely respond to a notification or alert through a browser anywhere in the facility. Maintenance and inspection staff can now walk the plant floor performing break/fix, asset inventory collection, safety inspections, remote augmented reality support, and more.

 

Internal staff, contractors, and vendors also encounter situations where physically accessing a resource or location in a facility could put their safety or the lives of others at risk. Risk areas that include chemical, nuclear, heat, cold, oxygen deprivation, toxins, hazardous operations, and more. While they could use an Engineering Workstation (EWS) in some situations, most of these legacy systems lack oversight and safety tools such as recording, multi-factor authentication, just-in-time access, and remote monitoring to ensure that highly dangerous operations are not done improperly, insecurely, or unsafely.

 

With all of the growing needs above becoming commonplace, the long-standing concept of isolated or what is also commonly referred to as “air-gapped” environments is rapidly going away. While isolation had its safety and security benefits, we no longer live in a world that supports complete isolation for many of our critical infrastructure systems and resources.

 

Why not just use existing IT Access

 

While IT organizations have been providing Secure Remote Access for employees and third parties to systems and resources for decades, there are positives and negatives to this approach that must be weighed heavily.

 

Many IT organizations have a wealth of knowledge and expertise, and have an existing preferred solution to provide Secure Remote Access, which is controlled and managed by the IT network and cybersecurity teams most of the time. Being able to leverage this existing infrastructure, with features like identity and access management, provide several benefits for OT environments from a security, compliance, and management perspective.

 

Unfortunately, this quickly becomes a double-edged sword for many reasons. Two of the primary reasons stated prior are most attacks into OT originate from within IT, and IT may times embraces the tried-and-true use of VPNs for access. While this is may have positives, requiring OT third-party contractors and vendors to install yet another endpoint agent or security plugin onto their laptop or phone is, in many cases a difficult ask. Even if they are able to overcome these challenges and gain access, the technologies used within IT are not granular enough and feature rich enough to provide things such as Just-In-Time (JIT), Just-Enough-Access (JEA), session recording, supervision, keystroke logging, and time limit control.

 

Even if IT is able to provide features such as session recording or supervision through a jump-box, as an example, the recordings, session audit logging and collaboration are done within DMZ and cloud-based platforms which now expose that data and recordings to areas outside of OT Electronic Security Perimeter (ESP). While OT data while not deemed sensitive, is definitely critical and contains many process and formulation secrets that must be kept within OT.

 

Additionally, when an incident occurs within an organization, one of the first things I hear people within OT and IT say is that they are going disconnect connectivity between them and isolate. While this may seem like a good practice from a cybersecurity and safety perspective, access to critical systems within each realm is becoming so intertwined that it has the real potential to make the situation much worse.

 

Lastly, having OT staff be able to access the Secure Remote Access management platform within the bounds of their environment and enable, disable, or modify access based on the situation gives them direct control during an incident. Having this control when IT staff priorities and resources are focused elsewhere can have a huge impact when human and critical infrastructure safety are on the line and seconds truly matter.

 

Regulatory and Compliance Drivers of Secure Remote Access

 

The cyberattacks that have happened already including the Bowman Avenue dam in NYC (2013) over an insecure cellular modem, Colonial Pipeline (2021) through an IT controlled VPN, wastewater treatment facility in Oldsmar, FL (2021) through insecure desktop sharing software and most recently the attack on Poland’s Energy Sector (2026) over internet facing devices using default credentials and lacking multi-factor authentication, should alone be enough of a wakeup call to adopt Secure Remote Access methods in OT but they are not.

 

To help mitigate and reduce cyberattacks within OT, there have been many directives, frameworks, guidance and best practices published on the proper ways to implement Secure Remote Access in OT. These include NERC CIP-005, IEC 62443-3-3, NIST SP 800-53, 800-46, 800-171, 800-207, TSA SD02E, NIS2, CMMC, CISA and more.

 

Additionally, Secure Remote Access is Control No 4 in SANS in the Five Critical Controls for ICS/OT Security which acts as a simple yet effective prioritized roadmap to secure OT environments, prioritizing safety, uptime, security and reliability.

 

What are the core foundations and features of Secure Remote Access for OT

 

While there is a myriad of additional features that vendors provide in their Secure Remote Access products, including AI the core features are:

 

  • Just In Time (JIT) and Just Enough Access (JEA)
  • Session Recording, Supervision and Intervention
  • Multi-Factor Authentication
  • Identity, Role and Policy-Based Access Control
  • Asset and Protocol Isolation
  • Logging and Auditability
  • Identity Access Management
  • Legacy Protocol Support
  • Outbound Connectivity
  • Flexible Deployment Architecture Model
  • Continuous Monitoring and Access Evaluation
  • Browser-Based UI
  • Agentless

 

These features align to the growing trend in a push towards a Zero Trust Architecture Security Framework (NIST SP 800-207) and the CISA model of 5 pillars and 3 platforms. This provides a "never trust, always verify" model across these areas to ensure a comprehensive, defense in depth approach to protect against modern, sophisticated cyber threats while moving away from the perimeter-based data-centric security approach.

 

The Five Pillars

 

  • Identity: Verifies user, service, or application identity using strong authentication (MFA) to ensure only authorized users access resources.
  • Devices: Monitors and secures all devices (endpoints, IoT) connecting to the network, verifying their security posture before granting access.
  • Networks: Uses micro-segmentation to break the network into small, secure zones, limiting the lateral movement of threats.
  • Applications and Workloads: Protects applications, including those in the cloud and on-premise, by securing access and verifying workloads, such as containers or virtual machines.
  • Data: Identifies, classifies, and encrypts data at rest and in transit, placing security controls as close to the data as possible.

 

The Three Platforms

 

  • Visibility and Analytics: Continuous monitoring to analyze user activity, device posture, and network traffic to detect anomalies.
  • Automation and Orchestration: Enables rapid response to threats and automatic, dynamic policy enforcement.
  • Governance: Enable policies that enable tailored local controls with continuous enforcement and dynamic updates.

 

In Conclusion

As with any technology within OT the core pillars of safety, security, and operational availability must always be drivers when planning, architecting and implementing any solution. We need to acknowledge that any external or internal connectivity to any resource always comes with risk. Due to the high level of specialization within OT environments, many of the tools that an organization chooses will likely differ from those used in IT.

 

Technology is only one piece of the puzzle when it comes to success for any solution or project. To be successful, you must ensure that you have trained, competent people and structured battle tested processes in place to ensure that your Secure Remote Access solution meets not only your business challenges and needs, but more importantly, that it keeps your staff and facilities safe and secure.

 

Secure Remote Access with Kasm Workspaces

 

To support modern Secure Remote Access strategies in Operational Technology environments, Kasm Workspaces delivers a browser-based, Zero Trust intermediary platform that acts as a secure gateway between internal systems and external networks. By removing direct network access and rendering workspaces through the browser, Kasm Workspaces significantly reduces the attack surface and prevents malware from infiltrating internal systems, eliminating the need for risky VPN-based approaches. With built-in logging, auditing, multi-factor authentication, and seamless integration with existing identity providers, it enables secure, compliant access to applications and data from any device, while keeping sensitive resources and regulatory controls within your infrastructure. This makes Kasm Workspaces an effective solution for enforcing JIT and JEA controls, protecting critical infrastructure, and aligning remote access with Zero Trust security principles.

 

Get Started with Kasm Workspaces