Why VPNs Are A Major Risk for OT — And What to Use Instead

In industrial environments, remote access has long crossed the line from occasional exception to essential daily operation. OEM vendors, system integrators, and off-site engineers all need entry into operational technology (OT) systems for maintenance, monitoring, and disaster response. But the way many plants still grant access — via traditional VPNs and standing tunnels — is creating gaping security holes. What was once a convenience is now considered one of the largest threat vectors.

Why Standard VPNs Don’t Cut It for OT

OT systems, including industrial control systems (ICS), supervisory control and data acquisition (SCADA) servers, programmable logic controllers (PLCs), and human-machine interfaces (HMIs), were originally built to operate in isolation. When OT and IT networks converged, it opened those formerly protected systems to remote access — a change driven by needs like analytics, remote maintenance, and efficiency.

VPNs were designed to create secure tunnels for trusted employees — not to manage fine-grained, temporary access to industrial assets. But when applied to OT, VPNs often grant overly broad network access that lasts indefinitely. Contractors may use shared accounts, uncontrolled sessions remain open 24/7, and unmanaged devices can tunnel directly into critical systems without supervision. VPN concentrators are exposed to the internet and represent a growing target for attackers. In short, VPNs offer network location trust rather than identity or task-level control.

What a Modern, Secure Remote Access Framework Looks Like

The safer alternative is a brokered, VPN-less access model built on zero trust principles. Instead of creating inbound firewall rules or exposing ports, this model relies on lightweight connectors inside each OT zone to initiate outbound connections to a central access gateway. Remote users then log into that gateway via a browser. Under this setup:

  • Every session is scoped to specific tasks or assets — no broad network access.
  • Protocols like RDP, SSH, VNC, or web console interfaces are rendered through the gateway rather than exposing raw packet-level traffic.
  • Access is granted per asset, for limited time windows, under approved policies rather than standing permissions.
  • Credentials reside in secure vaults and are only injected during sessions, without being exposed to external users.
  • All sessions are recorded, monitored live, and can be terminated instantly.

This architecture transforms vendor or engineer access from a constant tunnel into discrete, auditable sessions — the leap many compliance frameworks now demand.

How This Maps to OT Compliance Standards

Frameworks like IEC 62443, NERC CIP, and the European Union’s NIS2 directive have all been increasingly emphasizing strong remote access controls, accountability, vendor access oversight, and rigorous logging. A brokered session model fulfills many of these obligations: it enforces zone boundaries between OT segments, demands identity verification with multi-factor authentication, mandates credential vaulting and audit logging, and adheres to least-privilege and just-in-time access practices. Shared VPN accounts and long-standing tunnels rarely produce the evidence or control these regulations require.

Criteria for Evaluating OT Remote-Access Platforms

Before adopting any tool or service for remote access in industrial settings, it should meet a checklist of requirements:

  • An outbound-only architecture with no inbound ports or exposed firewall rules.
  • Per-asset least-privilege access, bounded by time and tasks rather than standing entitlements.
  • Identity-first authentication, integrating MFA and consistent identity provider or directory support.
  • Credential vaulting so that third parties never see or store internal OT credentials.
  • Live monitoring, recording of sessions, and instant termination capabilities.
  • Reporting aligned with standards like IEC 62443, NERC CIP, and NIS2 to satisfy audits and regulatory reviews.

Any platform that claims to secure OT remote access but fails one or more of these controls is likely just a VPN variant with better marketing.

Industrial organizations that transition to brokered, zero-trust remote access models replace standing network trust with identity-based controls. Rather than constant tunnels, they adopt just-in-time sessions; instead of invisible vendor activity, they produce recorded evidence. The tools for this shift are already mature and in use today; the question is whether facilities will prioritize replacing outdated access methods before the next breach occurs.