A production line stops responding, a utility operator loses visibility of a remote site, and maintenance teams start making decisions from partial information. The consequences spread quickly: output schedules move, service commitments come under pressure, and leaders need to establish whether a device, application, or remote connection contributed to the interruption.
Industrial automation security protects industrial control systems, connected devices, remote connections, and operational data from unauthorized activity and system disruption. It brings asset visibility, network segmentation, identity controls, monitored access, managed changes, and tested recovery procedures into one operating model, so connected plants retain the oversight they need without leaving unmanaged routes into critical processes.
Remote monitoring and supplier support give operations teams faster insight into equipment conditions and specialist help when it is needed. They connect operational technology (OT), including programmable logic controllers, sensors, and remote terminal units, with Ethernet networks, cloud services, and corporate systems. That connection improves oversight, but it means assumed isolation no longer provides a dependable control boundary.
This article sets out how leaders can govern that exposure through critical asset records, zone-and-conduit segmentation, demilitarized zones, controlled remote access, and risk-based patch decisions. It covers response exercises, recovery order, third-party dependencies, and the ownership evidence needed to keep legacy modernization aligned with production stability.
Why do connected plants change the risk model?
Connected plants need a risk model that treats control-system availability, process integrity, and recovery order as business concerns. Engineering workstations, cloud monitoring, supplier support, and corporate identity services create useful operating links, but each link needs an owner, an approved purpose, and evidence that access remains controlled.
The scale of convergence is evident: 73% of surveyed organizations reported an intrusion affecting OT systems alone or both IT and OT systems, up from 49% in the prior year (Fortinet, 2024). The financial impact reaches beyond technical recovery. Cybersecurity Dive reported in 2024 that Johnson Controls recorded a $27 million impact from its September 2023 ransomware incident, including response costs and lost or deferred revenue.
Which pressures make OT exposure harder to govern?
These conditions compound. A visibility gap makes it harder to assign ownership. Unclear ownership leaves changes and exceptions outside a reliable review process.
- Asset heterogeneity: PLCs, remote terminal units, sensors, interfaces, and engineering devices often have different lifecycles and communications needs. Inventory must show which assets support each production process.
- Legacy lifecycle constraints: Older equipment may not tolerate routine changes. Leaders need documented compensating controls and a replacement decision rather than an open-ended exception.
- Third-party dependencies: Original equipment manufacturers, integrators, and service providers need access during maintenance or disruption. Their access requires the same approval and evidence standards as internal access.
- Shared IT/OT accountability: IT, engineering, operations, and security teams each own part of the decision. One accountable executive must resolve trade-offs when safety, uptime, and cyber risk conflict.
| Legacy assumption | Connected-operations reality | Executive implication |
|---|---|---|
| Asset lists are maintained locally | Devices and data flows cross operational and enterprise boundaries | Require a shared inventory and named owner |
| Plant access is physically contained | Remote support and cloud services create additional paths | Approve access pathways as controlled services |
| An outage is an IT event | A disruption can affect production quality and restoration order | Set process-based recovery priorities |
| Security owns cyber decisions | Operations and suppliers influence access and change | Define decision rights across functions |
What framework aligns IACS risk and business priorities?
A workable IACS program connects four dimensions: Governance, Architecture, Operations, and Resilience. IEC 62443 gives leaders an industrial automation and control system reference for program requirements. NIST Cybersecurity Framework (CSF) 2.0 provides a common structure for enterprise oversight, investment choices, and reporting.
The distinction matters in practice. IEC 62443-2-1:2024 states that it “specifies asset owner security program policy and procedure requirements for an industrial automation and control system (IACS) in operation.” That directs attention to accountable operating practices, not a one-time technology purchase.
How do IEC 62443 and NIST CSF 2.0 fit together?
IEC 62443 defines IACS-oriented expectations for asset-owner policies, procedures, and technical controls. NIST CSF 2.0 gives executives a shared risk-management vocabulary across Govern, Identify, Protect, Detect, Respond, and Recover (National Institute of Standards and Technology, 2024).
Use IEC 62443 to ask whether control environments have appropriate program discipline. Use NIST CSF 2.0 to connect that discipline to enterprise risk reporting and budget decisions. The two references work together when the same asset owner, risk decision, and recovery evidence appear in both governance conversations.
Where does the Purdue model inform control boundaries?
The Purdue Reference Model and zone-conduit modeling help leaders decide which communications are necessary between areas with different operational roles. Think of the network as a facility with controlled passageways: movement between areas requires an approved route, a defined purpose, and records that show who entered.
NIST describes security segmentation as grouping cyber assets by their communications and security needs. CISA advises organizations to “Use DMZs to segregate business and control architectures” (CISA, 2023). Before approving a cross-zone connection, leaders need to know its operational purpose, approving owner, monitoring method, and recovery path.
- Governance: Assign decision rights for risk tolerance, exceptions, and investment sequencing.
- Architecture: Define zones, conduits, and demilitarized zones (DMZs) that constrain communications.
- Operations: Maintain asset records, access reviews, change controls, and detection workflows.
- Resilience: Test restoration priorities, manual procedures, escalation routes, and supplier dependencies.
| Framework dimension | Leadership question | Evidence source | Decision enabled | Common misread |
|---|---|---|---|---|
| Governance | Who accepts an exception? | Risk register and approvals | Risk tolerance | Policy alone proves maturity |
| Architecture | Which flows are necessary? | Zone and conduit records | Connection approval | Segmentation is only a network task |
| Operations | Who reviews control performance? | Access and change evidence | Operating ownership | Tool deployment equals control |
| Resilience | What restores first? | Exercise results | Recovery investment | Backups prove recovery readiness |
Which controls reduce industrial automation risk first?
Industrial automation security investment should follow process consequence, production criticality, reachability, and recoverability. A severity score is useful input, but it cannot decide whether a vulnerable asset supports a safety function, a constrained production step, or a process with no practical fallback.
That prioritization prevents teams from treating every finding alike. Ember OT reported in 2026 that 29 of 2,203 tracked ICS/OT CVEs appeared in CISA’s Known Exploited Vulnerabilities catalog. Boundary review deserves equal attention: TechTarget reported in 2025 that 22% of 606 OT/ICS-relevant advisories analyzed were network-exploitable and perimeter-facing.
- Critical asset and communication inventory: Record assets, their process role, dependencies, and approved communications. Leaders need a view that connects technical ownership to service criticality. The common error is treating an inventory as a static spreadsheet rather than an operating record.
- Zone-conduit segmentation and DMZ controls: Separate business and control functions, then approve only necessary pathways between them. This supports connection decisions and limits the effect of an exception. The common error is adding a boundary device without validating the permitted flows.
- Identity-based, least-privilege remote access: Tie access to an accountable individual, a stated purpose, and only the actions required. This creates reviewable decision evidence. The common error is retaining standing supplier access after the original work ends.
- Risk-based patch and compensating-control program: Assess change safety alongside exposure and process consequence. Where immediate updates are unsuitable, document containment, monitoring, and a replacement plan. The common error is allowing temporary exceptions to become permanent.
- Contextual detection and recovery validation: Connect alerts to process context and test the restoration sequence. Leaders need evidence that teams can make informed decisions during disruption. The common error is measuring alert volume instead of recovery readiness.
| Control domain | Leadership signal | Decision supported | Interpretation error |
|---|---|---|---|
| Asset inventory | Process owner and dependency recorded | Prioritize remediation | Counting devices alone |
| Segmentation | Approved flows reviewed | Approve cross-zone pathways | Assuming a DMZ solves ownership |
| Remote access | Identity and purpose attributable | Grant or revoke access | Accepting shared accounts |
| Patch governance | Exception has end date | Fund compensating controls | Ranking only by severity |
| Detection and recovery | Exercise validates restoration order | Improve resilience plan | Equating backups with recovery |
How should leaders govern remote OT access?
Remote OT access needs an operating policy that preserves urgent support without normalizing standing connectivity. Plant operations, engineering, IT, security teams, and suppliers need agreed decision rights before a support event; access choices made under pressure are difficult to reconstruct later.
CISA’s direction is direct: “Eliminate all direct connections to critical operational assets” (CISA, 2023). The practical question is how each approved pathway is mediated, authenticated, constrained, monitored, and revoked. Dragos found secure-remote-access issues in 20% of its 2025 service engagements, a useful indicator that remote-access governance needs regular review.
- Define approved purposes and owners: Classify support, engineering, vendor maintenance, and emergency access. Each category needs an accountable owner who can approve, review, and retire the pathway.
- Require strong identity assurance and least privilege: Individual identity must replace shared credentials. Permission sets need to reflect the work being performed and expire when that work ends.
- Mediate external paths through controlled zones: Route external connectivity through the architecture approved for operational access. Do not permit convenience connections that bypass segmentation decisions.
- Retain session evidence and test revocation: Keep records that support review after an exception, then test whether access can be removed promptly. Evidence is only useful when it supports an actual investigation or audit question.
| Access-governance choice | Operational trade-off | Implication |
|---|---|---|
| Standing versus time-bound access | Faster repeat support versus tighter control | Default to time-bound approval |
| Shared versus individual identity | Convenience versus accountability | Use attributable identities |
| Direct versus mediated path | Fewer steps versus controlled routing | Protect operational assets through approved zones |
| Logs versus replayable session evidence | Basic history versus fuller review | Match evidence depth to process criticality |
Where do OT programs fail during disruption?
Programs often fail at the handoff between documented controls and real operating decisions. A patch plan does not settle whether a production system can tolerate change, and a backup does not prove that a team can restore systems in the right order and communicate with operations and suppliers.
The business case for exercises is tangible. Sophos reported a mean ransomware recovery cost of $1.67 million for manufacturing organizations in 2024, compared with $1.08 million in 2023. Kaspersky ICS-CERT recorded 107 publicly confirmed industrial cybersecurity incidents in Q4 2024; at least 50% involved ransomware and 31% involved denial of operations. Public records are incomplete, yet they reinforce the need to rehearse cross-functional response.
- Unowned exceptions: Temporary access, deferred patches, and unsupported assets need a named business owner and review date.
- Unvalidated recovery: Teams must test restoration order, manual alternatives, system dependencies, and decision thresholds.
- Unrehearsed escalation: Leaders need predefined triggers for plant operations, executive escalation, customer communication, and supplier coordination.
- Undocumented third-party dependencies: Recovery plans must identify the vendors, credentials, software, and support arrangements required during restoration.
| Failure mode | Governance evidence to require |
|---|---|
| Unowned exceptions | Approved risk acceptance and expiry date |
| Unvalidated recovery | Exercise record and restoration findings |
| Unrehearsed escalation | Tested communications and decision log |
| Undocumented third-party dependencies | Current supplier-access and dependency register |
A documented plan becomes credible when a drill reveals what must change before the next disruption.
How RealVNC Closes the Industrial Automation Security Gap
The gap in secure remote operations often appears after a policy has already been approved. A team may define segmentation rules and supplier-access requirements, yet still lack documented evidence of who connected to an HMI, engineering workstation, or SCADA endpoint, what permissions applied, and whether the session remained appropriate. CISA recommends least-privilege configurations for remote-access software, including identity- or endpoint-based approaches (CISA, FBI, NSA, MS-ISAC, and Israel National Cyber Directorate, 2023).
RealVNC Connect supports the controlled-access layer around authorized support and remediation workflows. It does not replace segmentation, detection, patch governance, or incident response. Instead, it provides controls that help teams apply remote-access decisions consistently and retain evidence for later review.
- Role-based access controls (RBAC) and granular action-based permissions: Assign access by role and separately control keyboard, mouse, and file-transfer actions.
- Multi-factor authentication and single sign-on (SSO): Strengthen identity assurance through MFA and SSO with Microsoft Entra ID or Okta.
- Session monitoring, recording, and detailed audit logs: Give authorized administrators reviewable records of remote-control activity and granted permissions.
- Code Connect: Use single-use, time-bound session codes for attended third-party access without issuing standing credentials.
These capabilities give operations and security teams a stronger basis for approving exceptions, reviewing remote work, and revoking access when the task is complete. In a segmented control environment, that evidence supports production continuity confidence and makes access governance a repeatable operating practice rather than a promise recorded in policy.
Final Words
Industrial automation security becomes dependable when governance decisions show up in the daily control of assets, connections, and recovery. IEC 62443-2-1:2024 sets expectations for an asset-owner security program. NIST CSF 2.0 gives leaders a common structure from governing risk through recovery. Put those references to work by tying critical asset records to zone-conduit decisions, assigning an owner to every remote pathway, and testing the restoration order that production depends on.
RealVNC Connect reinforces the controlled-access portion of that operating model. Role-based access controls (RBAC) and granular action-based permissions keep remote work aligned to the task, and multi-factor authentication (MFA) and single sign-on (SSO) with Microsoft Entra ID or Okta strengthen identity assurance. Session recording and detailed audit logs then give operations and security teams evidence to review when access exceptions or production incidents demand answers. This does not replace segmentation, patch governance, detection, or rehearsed response; it makes remote support more accountable within those controls. Arrange a meeting to discuss how RealVNC Connect can support controlled, auditable remote access for your operational environments.
FAQs
What is an IACS security framework?
Industrial automation security is the governance and protection of connected control environments to preserve safe, reliable operations. IEC 62443-2-1:2024 focuses on security policies and procedures for IACS asset owners. NIST Cybersecurity Framework (CSF) 2.0 organizes risk management through Govern, Identify, Protect, Detect, Respond, and Recover. Together, they give executives a way to connect control requirements with business oversight.
How do Purdue and IEC 62443 differ?
The Purdue Reference Model is an architectural model for organizing industrial systems and their communications. IEC 62443 provides broader security-program and control expectations for IACS environments. Purdue-informed segmentation helps define where communications should occur; IEC 62443 helps govern why they exist, who approves them, and what evidence supports the decision. CISA advises using demilitarized zones (DMZs) to separate business and control architectures.
How should leaders prioritize legacy control assets?
Leaders should prioritize legacy assets by process consequence, network exposure, exploitability, compensating controls, and recovery options rather than severity scores alone. An asset supporting a safety-related or production-critical process may require stronger containment and monitoring when immediate patching is unsafe. The exception record must name the owner, the reason for delay, the interim controls, and the review date.
What’s the difference between ICS and SCADA?
Industrial control systems (ICS) is the broad category covering technologies that monitor or control industrial processes, including programmable logic controllers, remote terminal units, and distributed control systems. Supervisory control and data acquisition (SCADA) is one type of ICS that gathers data from remote sites and provides supervisory control through operator interfaces. The distinction matters: SCADA protection sits within the wider governance of industrial control environments.
How does RealVNC Connect support controlled OT access?
RealVNC Connect supports controlled remote-support workflows through role-based access controls (RBAC), granular action-based permissions, multi-factor authentication (MFA), and single sign-on (SSO) with Microsoft Entra ID or Okta. Session monitoring, session recording, and detailed audit logs provide reviewable evidence of remote activity and granted permissions. Code Connect adds time-bound, single-use 9-digit session codes for attended third-party access. These capabilities support access governance and evidence; they do not replace segmentation, monitoring, patch governance, or incident response.


)
)