October 11, 2026

Secure Remote Access for OT Systems: 9 Requirements

Secure Remote Access for OT Systems: 9 Requirements

Setting the Foundation for OT Cybersecurity Part 3: Secure Remote Access for OT Systems

One of the biggest cyber risks for an organization with OT is the risk posed by third parties. Third parties include service providers, integrators, vendors, original equipment manufacturers (OEMs), telecommunications providers and anyone else outside the organization who operates or supports your OT systems. The 2025 Verizon Data Breach Investigations Report found that third-party involvement in breaches doubled in one year, from 15% to 30%. Third-party risk management is a large topic that we will cover in a later post. Here we focus on the part of it that affects real estate and critical infrastructure organizations most directly: secure remote access for OT systems.

Why vendor remote access is a path into your environment

Every facility's operations team depends on vendors and service providers. That dependency ranges from annual service visits to daily support. In some buildings the service provider is the de facto operations team, and facility managers go through them for any change to the OT systems. A single facility can have a dozen vendors. A real estate portfolio with hundreds of buildings can have hundreds, and the number of individual technicians who need remote access is higher still. Each one is a path into your environment, and your operations team needs to know when a system is being accessed and what is being changed.

Nine requirements for secure remote access for OT

Remote access solutions include virtual private networks (VPNs), remote desktop applications, remote service ports and cloud-based platforms, each with advantages and disadvantages. Whichever you choose, apply the following:

  1. Never expose OT systems to the internet. It remains common to find a BMS with a public IP address that leads straight to its login page. In October 2025, the Canadian Centre for Cyber Security warned that hacktivists had tampered with internet-exposed controls at a water facility, an oil and gas company and a farm. Water pressure values were changed, a tank gauge triggered false alarms and a grain drying silo was pushed toward unsafe conditions. The Cyber Centre's guidance is direct: the most effective defence is removing OT systems from direct internet exposure.
  2. Assess your corporate solution first. IT teams usually have a preferred remote access method that is part of a wider identity and access management (IAM) platform. Check whether it suits OT. If it does not, consider a dedicated OT remote access solution.
  3. Avoid weak and unpatched solutions. Do not use VPNs or remote tools that rely on protocols with known vulnerabilities, and keep the appliances patched. Attackers target edge devices because one compromised gateway opens many sites.
  4. Require multi-factor authentication (MFA) for every remote session.
  5. Issue named accounts. Every technician gets an individual account. Shared vendor logins make it impossible to know who did what.
  6. Log and record sessions. The solution should log user activity and, ideally, record sessions. Recordings help you troubleshoot an issue or investigate an incident.
  7. Use strong encryption, then test with your own systems. Older OT thick clients and slow site links often behave badly over remote access tools. Run a time-limited proof of concept (PoC) with your actual applications before deployment.
  8. Make access time-bound. Schedule vendor sessions in advance and close them when the work is done. Access should not be continuous.
  9. Check legacy compatibility. Confirm the solution can reach your legacy OT applications. If it cannot, decide on a compensating control, which may require changes to the network architecture covered in Part 2.

How to measure progress

Measure progress with one number: how many OT systems a vendor can reach without passing through your controlled gateway. Count them today, and set the target at zero.

Frequently asked questions

What is secure remote access for OT?

It is a controlled way for vendors and staff to reach control and building systems from outside the site. It uses individual accounts, multi-factor authentication, logged sessions and scheduled access, and it never exposes OT systems directly to the internet.

Why is vendor remote access a risk for building management systems?

Each vendor and technician with access is a path into your environment. A building management system with a public IP address, or a shared vendor login, makes it hard to know who is connected and what they are changing.

How do I know how exposed my OT systems are?

Count how many OT systems a vendor can reach without passing through your controlled gateway. The target is zero.

Other articles in this series

Next in this series, we look at tactical remedies you can apply while the larger program takes shape.

Actimeta is an OT cybersecurity company focused on smart buildings and critical infrastructure.

References

‍

Author:
Team Actimeta