Remote Work in OT: Secure Access without VPN Sprawl
Since 2020, remote access to industrial systems has skyrocketed — but so have breaches linked to overextended VPNs. In the Zero Trust era, the goal isn’t connecting everything — it’s connecting only what’s needed, when it’s needed.
The VPN Problem
- Flat network tunnels expose entire OT subnets.
- Credential reuse between vendors and engineers.
- Minimal audit or session visibility.
Zero Trust Remote Access (ZTRA)
- Per-session authorization: Validate identity, device posture, and purpose for each session.
- Granular policy enforcement: Allow access to one PLC or HMI — not the whole subnet.
- Brokered connections: Use jump servers or software-defined perimeters (SDP).
Implementation Tips
- Replace VPNs with identity-aware proxies (e.g., Cloudflare Access, Tailscale, ZScaler Private Access).
- Log all actions for session replay and compliance.
- Integrate MFA and just-in-time approvals for contractors.
Example
A machinery OEM replaced 12 site VPNs with a centralized SDP solution. Access now requires MFA and session approval, cutting external exposure by 90% while reducing IT overhead.
Related Articles
- Least Privilege for HMIs and SCADA: Design Patterns
- Zero Trust in OT: Micro-Segmentation That Engineers Can Maintain
- Measuring Zero Trust Maturity in Factories
Conclusion
VPNs were built for connectivity — not security. With Zero Trust Remote Access, OT teams can enable safe remote work that protects both uptime and data integrity.

































Interested? Submit your enquiry using the form below:
Only available for registered users. Sign In to your account or register here.