← Home

Secure Remote Access

Remote connectivity to Industrial Automation and Control Systems (IACS) can run over LANs, WANs and the internet, dial-up or serial paths to controllers, and many remote-support tools. It brings clear operational benefits — central management, vendor support, remote maintenance — and equally clear risk: if a legitimate person or device can reach the system remotely, an unauthorised one may be able to do the same.

Teaching note: Paraphrased for learning from IACS cybersecurity course material and industry practice. Not a substitute for ISA/IEC 62443 normative requirements (especially Part 2-1 NET 3) or organisation-specific remote-access policy.

Related: IEC 62443-3-1 Clause 5 Authentication | IEC 62443-3-1 Clause 7.3 VPN | Jump Host | Multi-Factor Authentication (MFA) | IEC 62443-2-1 NET 3 – Secure Remote Access | Network Segmentation | IEC 62443-3-1 Clause 8.3 IDS | Unified Threat Management (UTM) | Zone and Conduit Security Strategy | Network Security Devices


Design challenges

Secure remote-access design is hard because organisations must reconcile:

Larger organisations typically face more complexity — more user types, more entry points and more systems to monitor.


Typical remote users


Remote access technologies

Common options include:

Choose technology for the business need and risk posture — not familiarity alone. For VPN appliances, protocols (IPSec, TLS/SSL, and related), site-to-site vs remote-access architectures, and industrial deployment tips, see the VPN page. Terminate remote-access VPN gateways in an industrial DMZ where practical.


Design factors

When designing remote access, consider at least:

Part 2-1 expects interactive remote sessions to be authorised, authenticated, encrypted, documented, logged and monitored (NET 3.2), with automatic termination after inactivity (NET 3.3).


Jump host

A jump host concentrates interactive remote work on a controlled workstation (KVM-style access) instead of granting broad IACS network membership. Place it in the DMZ, limit reachability and file transfer, and harden it as a high-value endpoint.

See Jump Host for architecture, benefits and placement guidance.


Remote access best practices


Preferred access patterns

Additional sector guidance is available from bodies such as national infrastructure protection organisations, NERC (for applicable electric entities), and national public-safety cybersecurity programs — always start with the vendor and with ISA/IEC 62443 requirements for your role.


Key takeaways