RealVNC logomark

RealVNC Viewer

Productivity

icon close circle

Securing Industrial Control Systems Remotely: Key Risks

Contents

A pump station stops responding, a production line shows an unexpected reading, and the engineer who knows the controller is hours away. Operations feels the pressure first, but an improvised support connection can leave plant teams carrying a new operational risk long after service resumes.

Securing industrial control systems remotely means granting approved people time-limited, task-specific access to operational technology assets through controlled network routes, verified identities, and reviewable sessions. Each connection needs a defined purpose, a named owner, and boundaries that preserve process safety, availability, and engineering authority.

Industrial control systems (ICS) include programmable logic controllers (PLCs), supervisory control and data acquisition (SCADA) systems, and distributed control systems (DCS) that monitor physical processes. These systems often remain in service for long lifecycles. Remote engineering, vendor support, and connected operations introduce access needs their original designs did not anticipate. A route that suits corporate IT may bypass the process context required in an operational technology (OT) environment.

This article sets out a governance model for remote ICS access, from the first engineering review through session oversight. It explains how ISA/IEC 62443 zones and conduits, NIST SP 800-82 guidance, and applicable NERC CIP obligations shape access decisions. It describes why an OT demilitarized zone (DMZ) and dedicated jump host matter. It shows how IT, OT, vendors, and maintenance teams can keep every session justified, constrained, and ready for review.

Why is remote ICS access now a resilience issue?

Remote access to industrial control systems is a resilience issue: each connection reaches equipment that governs a physical process. Leaders need every route to be explicit, approved for a defined purpose, segmented from core control assets, and owned by a named decision-maker.

Older industrial networks were built around reliability and limited connectivity. Remote engineering, specialist vendors, and connected operations have changed that operating model. A 2025 IEEE EuroS&P study, “Uncovering Exposed Industrial Control Systems and Honeypots on the Internet” identified 139,876 internet-reachable ICS hosts across 175 countries, including 119,534 potentially real devices. That figure signals an asset-discovery and exposure-management problem; it does not mean each device has been compromised.

The wider risk reaches beyond direct internet discovery. Kaspersky ICS CERT’s 2024 threat landscape reported that 38.6% of ICS computers were targeted globally in 2023, with internet-originated threats affecting 22.8% of targeted ICS computers. A remote pathway must be treated as part of the plant’s operating design.

The four pressures changing OT access

  • Remote expertise: Specialist knowledge sits away from the site, especially for legacy controllers and vendor-supported equipment.
  • Connected operations: IT/OT convergence brings production data, support tools, and enterprise services closer to control networks.
  • Identity ownership: Vendors, integrators, and maintenance teams require distinct approval paths rather than shared credentials.
  • Process consequences: A change to a controller or human-machine interface (HMI) can affect uptime, quality, and safe operation.

Think of an industrial demilitarized zone (DMZ) and controlled conduit as a staffed, logged gate to a plant control room. It gives approved visitors a defined route and a record of entry; it does not create an open corridor from the internet.

Legacy Assumption Modern Operating Reality Executive Consequence
Perimeter isolation Remote support reaches distributed sites Review each remote pathway as an engineering decision
Local expertise Vendors and specialists support systems remotely Define approved tasks and maintenance windows
Shared administration Multiple organizations require access Assign identity and approval ownership
Contained incident impact A control change can affect a physical process Tie cyber response to plant operations

Which control model secures remote ICS access?

A defensible model makes access necessary, bounded, and reviewable before a session begins. The five-part Justify, Segment, Verify, Constrain, Evidence model gives leaders a common way to assess remote-support architecture without separating cyber controls from process safety.

Zero trust means authorization is evaluated continuously and close to the protected resource, rather than assumed after one network entry point. It complements Purdue Reference Model zoning, industrial DMZs, and safety-preserving engineering controls; it does not replace them. NIST SP 800-82 Rev. 3 includes multi-factor authentication (MFA) for remote OT access alongside segmentation and perimeter protections.

  • Justify: Confirm the system, task, operator, and approved maintenance purpose before access is granted.
  • Segment: Route connections through controlled zones and conduits that limit direct reach to PLCs, SCADA systems, and engineering workstations.
  • Verify: Authenticate the user and evaluate authorization near the requested resource.
  • Constrain: Limit time, permissions, actions, and session scope to the approved work.
  • Evidence: Retain records that show who connected, what was authorized, and what occurred during the session.
Framework Dimension Control Objective Evidence Source Leadership Decision Common Misread
Justify Establish a valid maintenance purpose Approved work order Who authorizes the session? Any support request is sufficient
Segment Separate enterprise and control networks Zone and conduit design Which path reaches the asset? A VPN alone provides separation
Verify Confirm identity and resource authorization Identity records Which identities are accepted? MFA proves task authorization
Constrain Limit what a session can do Role and session controls Which actions are permitted? Authenticated users need broad access
Evidence Support review and response Session and access records Who reviews activity? Logs without ownership provide assurance

How do zones and conduits protect the process?

Zones group systems with similar trust and process requirements. Conduits are the controlled communications paths between them. ISA Global Cybersecurity Alliance guidance on zero-trust outcomes using ISA/IEC 62443 standards aligns this approach with defining security zones and managed conduits between enterprise, DMZ, and industrial-control networks.

An industrial DMZ gives remote users a controlled stopping point before they reach HMIs, engineering workstations, programmable logic controllers (PLCs), or supervisory control and data acquisition (SCADA) assets. NIST SP 1800-35 describes an approach in which resource groups sit on unique segments protected by gateway security components. The exact zone design must reflect plant safety, service criticality, and engineering approval.

Why is identity insufficient without session control?

MFA verifies that a user has passed an identity check. It does not establish whether that user needs a particular controller, whether the work is approved, or whether file transfer and remote programming are appropriate for the task.

Adoption alone does not show governance maturity. SANS Institute’s 2024 State of ICS/OT Cybersecurity survey found that 75% of respondents had implemented MFA for remote access to industrial sites. Leaders still need task-based authorization, approved time windows, session oversight, and evidence that access ended when the maintenance work ended.

How should leaders evaluate ICS remote safeguards?

Leaders should evaluate safeguards as a connected control system: known pathways, constrained sessions, approved changes, and evidence that supports review. A remote-access product or a single authentication control does not establish that the pathway is appropriate for a particular industrial process.

Recent advisories show why the review must extend to the operational action itself. CISA AA23-335A documented IRGC-affiliated actors using remotely programmable PLCs in multiple critical-infrastructure sectors and advised operators to disable remote programming or require a strong password. The right response depends on plant design and engineering authority, yet the principle is clear: remote programming needs explicit control.

  1. Asset and pathway visibility: Maintain a current record of remote-capable assets, entry routes, identities, and approved communications.
  2. Segmentation and jump-host integrity: Confirm that remote users reach control assets through the intended DMZ and dedicated jump host.
  3. Identity, privilege, and session constraints: Review who has access, what actions they can take, and when their approval ends.
  4. Change-control and remote-programming safeguards: Link sensitive changes to work orders, engineering approval, and safe operating conditions.
  5. Monitoring, recording, and incident evidence: Review activity with asset, user, and process context rather than treating raw logs as sufficient.
Evaluation Criterion Leadership Signal Evidence to Review Common Error
Asset and pathway visibility Every route has an owner Asset inventory and access map Unknown vendor connection remains active
Segmentation and jump-host integrity Control assets have defined entry points Network design and gateway rules Direct connection to an HMI
Identity, privilege, and session constraints Access reflects a task Role assignments and approvals Broad standing vendor access
Change-control safeguards Sensitive actions follow plant rules Work orders and approvals Remote programming outside a window
Monitoring and incident evidence Sessions are reviewable Session records and review process Logs exist but nobody examines them

The operational detail matters. WaterISAC’s Quarterly Water Sector Incident Summary: Q1 2024 reported CARR actors using VNC remote-access software and default credentials on internet-facing OT devices at water utilities, then accessing HMIs, changing settings, disabling alarms, and changing administrator passwords. This is not evidence that every remote-access product is unsafe; it shows why direct reachability, default credentials, and unreviewed privilege create a dangerous combination.

Where do vendor connections create ICS governance gaps?

External specialists are often important to continuous industrial operations, particularly where equipment knowledge is held by an original equipment manufacturer or system integrator. The governance gap appears when a vendor relationship supplies technical expertise but leaves access approval, session scope, and offboarding unclear.

That exposure has a measurable access-path dimension. SANS Institute’s 2023 ICS/OT Cybersecurity Survey found that 23.3% of respondents identified external remote services as a principal initial-access vector. The answer is not to remove specialist support. It is to make the access relationship accountable across plant operations, OT security, enterprise identity teams, procurement, and incident response.

  1. Define system and task ownership: Name the plant owner, technical approver, and vendor contact for each supported asset.
  2. Use time-bounded access approvals: Grant access for a defined maintenance purpose and end it when work closes.
  3. Separate emergency access from standing privilege: Emergency sessions need a documented authority path and later review.
  4. Review evidence and revoke stale access: Reconcile accounts, permissions, and session records against active contracts and support needs.
Governance Choice Operational Benefit Risk if Absent
Vendor identity Clear accountability for each user Shared credentials obscure responsibility
Approval workflow Plant context informs access decisions Support begins without task validation
Session scope Access matches maintenance work Vendor reaches unrelated systems
Offboarding and review Stale access is removed Former partners retain a route inward

The scale of discoverable services reinforces the need for disciplined ownership. Censys Research’s 2024 analysis observed more than 148,000 internet-reachable ICS services across 175 countries. Treat that as a prompt to verify what is reachable and why, then assign a decision-maker to every approved route.

Industrial remote access: Which failures matter most?

The failures that matter most are governance conditions that let a routine support route bypass process-aware decisions. They are correctable, but they require IT and OT teams to work from the same asset, approval, and safe-state assumptions.

Availability sets the pace. The Carnegie Mellon Software Engineering Institute’s 2024 Zero Trust Industry Day takeaways identifies uptime as the leading focus in OT environments and advises evaluating controls against that requirement. For applicable power utilities, NERC CIP adds sector-specific obligations, yet every organization still needs system-specific engineering analysis.

  • Direct exposure: Internet-reachable HMIs, engineering stations, or PLC management interfaces remove the control point where access can be assessed.
  • Shared accountability: No named owner for a pathway leaves approvals, reviews, and emergency decisions unresolved.
  • Persistent privilege: Contractor access that remains after maintenance expands the number of active routes without a current purpose.
  • Blind monitoring: Records without asset, user, and process context do not show whether activity matched an approved task.
  • Unsafe response: Cyber procedures that omit plant operators and safe-state decisions risk worsening a process event.

The monitoring expectation is explicit. The ISA Global Cybersecurity Alliance states in its 2023 guidance: “Continuously monitor OT/ICS networks to log and inspect all traffic, assets, users and access.” Monitoring must feed a process-aware review path, where engineering teams can distinguish a legitimate maintenance action from unexpected controller behavior.

How RealVNC Closes the Industrial Remote Access Gap

A remote-access policy only becomes defensible when the organization can show how a session was authenticated, authorized, limited, and reviewed. In industrial support work, that evidence needs to connect a vendor or engineer to an approved task, a defined asset group, and a known maintenance window. OT architecture, zoning, and plant-safety authority remain with the customer.

RealVNC Connect Security documents multi-factor authentication and single sign-on (SSO) with Microsoft Entra ID and Okta, supporting centrally governed identity assurance. Role-based access controls (RBAC) and granular action-based permissions let organizations align keyboard, mouse, and file-transfer access with a user’s assigned task. Session monitoring, recording, and detailed audit logs provide reviewable records for vendor support and incident investigation. RealVNC Connect Product Documentation describes Cloud and Direct deployment options, allowing teams to assess connectivity placement against their industrial DMZ and segmentation design.

These capabilities support an operational access layer rather than complete ICS protection. Customers still need to define zones and conduits, approve maintenance activity, assess process consequences, and monitor the OT environment. Used within that governance model, RealVNC Connect helps turn third-party access from an informal connection into reviewable evidence of who entered, what they were permitted to do, and how the session was governed.

Final Words

Securing industrial control systems remotely starts with treating every connection as a process decision. A resilient program justifies each route and places it behind controlled zones and conduits. It then verifies identity, constrains access to an approved task and maintenance window, and retains evidence for review. That approach keeps remote expertise available and preserves the engineering authority, safety decisions, and availability requirements that govern plant operations. NIST’s Guide to Operational Technology Security (2024) reinforces this model by pairing multi-factor authentication (MFA) with segmentation and authorization close to the protected resource.

RealVNC Connect provides an operational access layer for that governance model. Multi-factor authentication and single sign-on (SSO) help teams govern identity centrally. Role-based access controls and granular action permissions align a session with the work an engineer or vendor has been approved to perform. Session monitoring, recording, and detailed audit logs provide a reviewable account of access without replacing your industrial demilitarized zone (DMZ), OT monitoring, plant approvals, or process-safety controls. When every session has a purpose, owner, boundary, and record, vendor access becomes accountable rather than informal. Arrange a meeting to assess how RealVNC Connect can support governed, audit-ready remote access to your industrial systems.

FAQs

What framework governs remote access to OT systems?

Securing industrial control systems remotely requires a five-part governance model: Justify, Segment, Verify, Constrain, and Evidence. This model links each connection to an approved purpose, a defined pathway, verified identity, limited permissions, and reviewable records. It complements NIST SP 800-82 Rev. 3 and ISA/IEC 62443-aligned guidance rather than replacing plant-specific engineering analysis.

How do OT segmentation and zero trust differ?

OT segmentation creates protected network boundaries and controlled conduits. Zero trust evaluates authorization continuously near the requested resource. NIST SP 800-82 Rev. 3 presents these approaches as complementary, with multi-factor authentication (MFA) supporting remote access governance. A plant needs both architectural separation and resource-level access decisions, sequenced around safety and availability.

Which standards guide industrial remote-access governance?

ISA/IEC 62443 guides the definition of security zones and conduits for operational technology environments. NIST SP 800-82 provides broader OT security guidance. NIST SP 1800-35 describes resource groups placed on network segments protected by gateway security components. NERC CIP adds sector-specific requirements for applicable electricity organizations; none of these references removes the need for engineering risk analysis.

What are examples of industrial control systems?

Industrial control systems include programmable logic controllers (PLCs), supervisory control and data acquisition (SCADA) systems, and distributed control systems (DCS). A PLC may control equipment directly. SCADA gathers operational data and supervises processes across sites. These systems require access decisions that account for physical operations, safe states, and service availability.

What are the 5 C’s in security?

The five C’s are often presented as a general security lens covering change, compliance, cost, continuity, and coverage. The model is not a universal OT security standard. For remote industrial access, the Justify, Segment, Verify, Constrain, and Evidence model offers a more direct way to assess pathways and decision ownership. Use any mnemonic as a discussion aid, then anchor control choices in NIST guidance, ISA/IEC 62443 concepts, and plant engineering requirements.

How does RealVNC support governed OT workflows?

RealVNC Connect supports governed OT workflows through MFA, single sign-on (SSO) with Microsoft Entra ID and Okta, role-based access controls (RBAC), and granular action-based permissions. Session monitoring, recording, and detailed audit logs provide reviewable evidence for remote support and vendor activity. Cloud and Direct deployment options support different connectivity designs. These controls complement industrial DMZs, OT monitoring, plant approval, and process-safety decisions; they do not replace them.

Learn more on this topic

This release is one of those "something for everyone" ones. There's a redesigned home screen that makes finding and connecting...
A data and analytics strategy turns conflicting reports into trusted decisions - but when governance slows access to sensitive insight,...
A hybrid cloud strategy can stall services, blur accountability, and inflate costs. See the governance model that keeps workloads controlled...

Try RealVNC® Connect today for free

No credit card required for 14 days of free, secure and fast access to your devices. Upgrade or cancel anytime