Skip to main content

Access

Remote Access Gateway

The controlled service through which remote engineers and vendors reach OT systems.

Critical criticalityLevel 3.5

What it does

Authenticates users, brokers sessions to approved destinations and records activity.

Typically locatedIndustrial DMZ.

At a glance

PurdueLevel 3.5
CategoryAccess
Protocolsopc-ua
Talks toIdentity provider, Jump hosts, Approved OT destinations, Log collectors
Common vendorsSiemens (SINEMA Remote Connect), Rockwell Automation (FactoryTalk Remote Access), Schneider Electric (EcoStruxure Secure Connect), Multiple

Why should I care?

Remote Access Gateway sits at Level 3.5. Compromise here is not just a data problem — it changes what the physical process does or what operators can see and control.

Common security problems

  • Shared vendor accounts
  • Permanent standing access
  • MFA exceptions
  • Direct-to-device tunnels bypassing jump hosts

If it is compromised

  • A supported, authenticated path straight into OT for an attacker

What to monitor

  • Session start/stop with named identity
  • Destination reached
  • Out-of-hours access
  • Failed authentication patterns

How to defend it

  • MFA, named accounts, time-bounded approval, session recording where appropriate, default-off vendor access

Related

Protocols this component speaks