Access
Secure Remote Access
Make every remote session into OT identified, approved, mediated, time-bounded and logged.
Defensive guide
Why should I care?
Remote access is one of the most consistently documented initial access paths into OT.
How to implement it
- Single controlled entry: identity provider with MFA → remote access broker in the DMZ → monitored jump host → approved destination
- Named accounts only; vendor access disabled by default and enabled per work order
- Restrict each identity to the destinations it needs
- Record sessions where appropriate and retain logs
What good looks like
- Vendor access is off until requested
- Every session maps to a person and a ticket
- No path bypasses the jump host
Common failure modes
- Shared vendor accounts
- Permanent standing access
- Direct RDP/VNC exposure
- MFA exceptions
How to verify it
- Attempt a direct connection bypassing the broker — it must fail
- Audit accounts against active contracts