
One of the biggest cyber risks for an organization with OT is the risk posed by third parties. Third parties include service providers, integrators, vendors, original equipment manufacturers (OEMs), telecommunications providers and anyone else outside the organization who operates or supports your OT systems. The 2025 Verizon Data Breach Investigations Report found that third-party involvement in breaches doubled in one year, from 15% to 30%. Third-party risk management is a large topic that we will cover in a later post. Here we focus on the part of it that affects real estate and critical infrastructure organizations most directly: secure remote access for OT systems.
Every facility's operations team depends on vendors and service providers. That dependency ranges from annual service visits to daily support. In some buildings the service provider is the de facto operations team, and facility managers go through them for any change to the OT systems. A single facility can have a dozen vendors. A real estate portfolio with hundreds of buildings can have hundreds, and the number of individual technicians who need remote access is higher still. Each one is a path into your environment, and your operations team needs to know when a system is being accessed and what is being changed.
Remote access solutions include virtual private networks (VPNs), remote desktop applications, remote service ports and cloud-based platforms, each with advantages and disadvantages. Whichever you choose, apply the following:
Measure progress with one number: how many OT systems a vendor can reach without passing through your controlled gateway. Count them today, and set the target at zero.
It is a controlled way for vendors and staff to reach control and building systems from outside the site. It uses individual accounts, multi-factor authentication, logged sessions and scheduled access, and it never exposes OT systems directly to the internet.
Each vendor and technician with access is a path into your environment. A building management system with a public IP address, or a shared vendor login, makes it hard to know who is connected and what they are changing.
Count how many OT systems a vendor can reach without passing through your controlled gateway. The target is zero.
Next in this series, we look at tactical remedies you can apply while the larger program takes shape.
Actimeta is an OT cybersecurity company focused on smart buildings and critical infrastructure.