Data as of Sep 16, 2026 · Based on 365 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
For secure remote access to OT and industrial networks, select a tool based on your specific requirements: Beyondtrust is best for privileged user and vendor access management;
Claroty and
Dispel lead in OT-specific security and compliance; and companies like and provide specialized connectivity for legacy or field-based maintenance.
Brands AI recommends here
Named in 47% of answers
Named in 36% of answers
Named in 35% of answers
Best for industrial maintenance teams needing easy-to-deploy access for field engineers. Its industrial-grade gateway is designed specifically for remote equipment support and maintenance workflows.
Named in 27% of answers
When providing secure remote access to Industrial Control Systems (ICS) and Operational Technology (OT) networks, there is no single silver-bullet product, but rather a **gold-standard architectural approach**: **Zero Trust Network Access (ZTNA) combined with a hardened, outbound-only Jump Host/Bastion architecture.**…
When providing secure remote access to Industrial Control Systems (ICS) and Operational Technology (OT) networks, there is no single silver-bullet product, but rather a gold-standard architectural approach: Zero Trust Network Access (ZTNA) combined with a hardened, outbound-only Jump Host/Bastion architecture.
Traditional Virtual Private Networks (VPNs) are increasingly discouraged for OT. Standard VPNs grant broad, perimeter-based network access—if an attacker compromises a vendor's laptop or credentials, they gain a direct tunnel straight into the flat internal OT network.
To align with modern industrial cybersecurity frameworks (such as the joint CISA and UK NCSC Secure Connectivity Principles for OT ), the best solution relies on a structured implementation:
To help narrow down the ideal architecture for your facility, could you share:
For most industrial environments, the **best approach is not simply a VPN**. I’d recommend a **brokered, zero-trust remote-access architecture with a hardened jump server/bastion host in an OT DMZ**, combined with MFA, least privilege, session controls, and strong monitoring. ### Recommended architecture ```
For most industrial environments, the best approach is not simply a VPN. I’d recommend a brokered, zero-trust remote-access architecture with a hardened jump server/bastion host in an OT DMZ, combined with MFA, least privilege, session controls, and strong monitoring.
Remote Engineer / Vendor
│
MFA + SSO
│
▼
┌─────────────────────┐
│ Remote Access │
│ Gateway / Broker │
│ • JIT access │
│ • RBAC │
│ • Device checks │
│ • Session logging │
└──────────┬──────────┘
│
IT/OT Firewall
│
▼
┌─────────────────────┐
│ OT DMZ │
│ Hardened Jump Host │
│ / Bastion / Proxy │
└──────────┬──────────┘
│
OT Firewall
│
▼
┌─────────────────────┐
│ OT Network │
│ HMI / SCADA / DCS │
│ PLCs / Engineering │
│ Stations │
└─────────────────────┘
This aligns well with NIST SP 800-82 Rev. 3, which specifically addresses OT's safety, reliability, and performance requirements.
CISA specifically warns that traditional remote-access/VPN deployments can create significant risk when misconfigured and recommends moving toward more granular, least-privilege access models.
A VPN can still be part of the solution, but I would not make "give the engineer a VPN into the OT subnet" the architecture.
A conventional VPN can effectively put a remote device inside the network. For OT, that's often too much trust. NIST's ICS guidance recommends strong authentication and describes using a remote-access server plus additional authentication at the control-network boundary.
So I'd rank the approaches roughly:
| Approach | OT suitability |
|---|---|
| Direct RDP/VNC to OT systems | 🔴 Poor |
| Port forwarding/NAT to SCADA/PLC | 🔴 Avoid |
| VPN directly into OT network | 🟠 Better, but broad trust |
| VPN + OT DMZ + jump server + MFA | 🟢 Good |
| Brokered zero-trust access + OT DMZ/jump host + MFA + JIT + monitoring | 🟢 Best overall |
One important caveat: there isn't a single universally best product or architecture for every ICS environment. CISA explicitly notes that no single remote-access solution is adequate without defense in depth.
If you tell me whether this is manufacturing, energy, water, oil & gas, building automation, etc., and whether you need vendor access, employee access, or both, I can give you a concrete recommended architecture and compare solutions such as PAM, ZTNA, secure remote-access gateways, and traditional VPNs.
## Best approach For most industrial environments, the **best solution is a purpose-built, brokered remote-access gateway for OT**, deployed in an **OT DMZ**, rather than giving users or vendors direct VPN/RDP access into the control network. A strong architecture looks like:
For most industrial environments, the best solution is a purpose-built, brokered remote-access gateway for OT, deployed in an OT DMZ, rather than giving users or vendors direct VPN/RDP access into the control network.
A strong architecture looks like:
Remote user/vendor → MFA + identity/zero-trust access → OT remote-access gateway/jump host → OT firewall/DMZ → specific ICS assets
This aligns well with current NIST and CISA guidance: remote access should be explicitly authorized, limited to the business need, monitored, and prevented from bypassing OT safety/security controls.
| Approach | My assessment for ICS/OT |
|---|---|
| Direct RDP/SSH/port forwarding | ❌ Avoid |
| Traditional VPN directly into OT | ⚠️ Better than direct exposure, but often too broad |
| VPN → OT jump server | ✅ Good |
| Dedicated OT remote-access gateway + MFA + JIT + monitoring | 🏆 Best general choice |
| Zero Trust/brokered access + OT gateway | 🏆 Excellent for mature environments |
Zero Trust is increasingly applicable to OT: CISA's 2026 guidance recommends adapting zero-trust principles to OT rather than assuming that being "inside" the network makes a user trustworthy.
Importantly, Zero Trust doesn't mean putting an ordinary IT ZTNA product directly in front of PLCs. OT protocols, legacy systems, safety requirements, deterministic communications, and availability constraints need to be accounted for. NIST emphasizes that OT security must preserve performance, reliability, and safety requirements.
If you're selecting a solution today, I'd specify:
A dedicated OT remote-access platform/gateway with an OT DMZ, phishing-resistant MFA, centralized identity, just-in-time access, granular asset-level authorization, session recording, strong auditing, and the ability for plant operations to immediately terminate remote sessions. For vendor access, make it even more restrictive: the vendor gets access only to the required asset, for the approved maintenance window, with the session monitored/recorded and access automatically revoked afterward.
Also, don't treat the remote-access product as the security boundary by itself. CISA explicitly notes that no single remote-access solution is adequate for every ICS architecture and recommends a defense-in-depth approach.
If you tell me your environment (e.g. Rockwell/Allen-Bradley, Siemens, Schneider, ABB, Honeywell, Emerson; number of plants; vendor remote access; cloud/on-prem), I can narrow this down to the best architecture and specific product options.
When securing remote access to Industrial Control Systems (ICS) or Operational Technology (OT) networks, **there is no single "silver bullet" product, but rather a gold-standard architectural approach:** a **Zero Trust Network Access (ZTNA) tailored for OT** , combined with **industrial-grade hardware gateways** and…
When securing remote access to Industrial Control Systems (ICS) or Operational Technology (OT) networks, there is no single "silver bullet" product, but rather a gold-standard architectural approach: a Zero Trust Network Access (ZTNA) tailored for OT , combined with industrial-grade hardware gateways and strict micro-segmentation.
Traditional IT remote solutions (like standard enterprise VPNs or flat-network remote desktop tools) are dangerous in OT because if an attacker compromises a vendor's laptop or a remote engineer's credentials, they get a flat, unhindered tunnel straight into the plant floor.
The industry consensus guided by frameworks like NIST SP 800-82 points to a specific modern blueprint for secure OT remote access.
Organizations typically build their stacks utilizing specialized OT security and remote access platforms:
To help narrow down what fits your plant or facility best, tell me:
There is no single "silver bullet," but cybersecurity consensus strongly dictates that the best solution for OT/ICS remote access is **Zero Trust Network Access (ZTNA) purpose-built for OT** , replacing legacy, overly permissive Virtual Private Networks (VPNs). Legacy VPNs drop a user (or vendor) directly onto the…
There is no single "silver bullet," but cybersecurity consensus strongly dictates that the best solution for OT/ICS remote access is Zero Trust Network Access (ZTNA) purpose-built for OT , replacing legacy, overly permissive Virtual Private Networks (VPNs).
Legacy VPNs drop a user (or vendor) directly onto the network layer, letting them move laterally if their credentials are compromised. An OT-specific ZTNA solution grants least-privilege, ephemeral access strictly to specific authorized assets or applications, rather than the network itself.
Leading enterprise and industrial-grade options fall into a few specialized categories depending on your architecture:
Core Architectural Best Practices
Whichever vendor platform you evaluate, a secure remote access deployment must include:
If you share:
I can help narrow down which specific platform aligns best with your environment.
For most industrial control systems (ICS) and operational technology (OT) environments, the **best solution is not a traditional VPN alone**. The strongest approach is a **Zero Trust remote access architecture designed specifically for OT**, typically combining: 1. **OT DMZ / Industrial DMZ (IDMZ)** 2. **Hardened jump…
For most industrial control systems (ICS) and operational technology (OT) environments, the best solution is not a traditional VPN alone. The strongest approach is a Zero Trust remote access architecture designed specifically for OT, typically combining:
This approach limits users and vendors to only the specific systems they need, only when they need them. CISA guidance recommends using controlled jump hosts, MFA, monitoring, and time-limited access controls for OT remote access.
Remote Engineer / Vendor
|
| MFA + identity verification
|
Remote Access Gateway
|
OT DMZ / IDMZ
|
Hardened Jump Host
|
Firewall Rules / Segmentation
|
PLCs | HMIs | SCADA | DCS
| Solution | Security level | Best use case | Main weakness |
|---|---|---|---|
| Traditional VPN | Medium | Small environments, temporary access | Often gives broad network access after login |
| VPN + jump server | High | Many existing ICS environments | Requires operational discipline and maintenance |
| OT-focused remote access gateway | Very high | Vendor access, critical infrastructure | Higher cost, requires deployment planning |
| ZTNA for OT | Very high | Modern environments moving toward Zero Trust | May require identity and architecture changes |
Traditional VPNs encrypt traffic but usually do not provide enough control over which OT assets a user can reach after authentication. Zero Trust approaches add identity-based, context-aware, least-privilege access controls.
Depending on your environment, organizations often evaluate:
For a new design, I would avoid deploying a standalone VPN as the primary ICS access mechanism and instead build around an OT remote access broker/gateway with Zero Trust principles.
If you share your environment (manufacturing, energy, water, oil & gas, etc.), number of sites, PLC/SCADA vendors, and whether access is mainly for employees or third-party vendors, I can narrow this down to a more specific architecture.
There is no single "silver bullet" vendor product, but cybersecurity authorities (like [CISA](https://www.cisa.gov/resources-tools/resources/secure-connectivity-principles-operational-technology-ot) ) and industry frameworks universally agree that the gold-standard architectural solution is an **Industrial Zero Trust…
There is no single "silver bullet" vendor product, but cybersecurity authorities (like CISA ) and industry frameworks universally agree that the gold-standard architectural solution is an Industrial Zero Trust Network Access (ZTNA) model tailored specifically for OT.
Traditional remote access methods—like legacy corporate VPNs—are dangerous in industrial environments because they typically grant broad, flat network-level access once a user is authenticated. If a vendor’s laptop is compromised, the attacker has a runway straight into your PLCs and SCADA systems.
An industrial-grade secure remote access solution relies on several core components and best practices:
Key Architectural Pillars
Leading Solution Approaches
To help narrow down which specific architecture fits your plant floor, tell me:
For most industrial environments, the **best approach is not a conventional VPN directly into the OT network**. I’d recommend a **zero-trust, brokered remote-access architecture with an OT jump host/gateway**, protected by MFA, strict segmentation, and comprehensive session monitoring. CISA specifically recommends…
For most industrial environments, the best approach is not a conventional VPN directly into the OT network. I’d recommend a zero-trust, brokered remote-access architecture with an OT jump host/gateway, protected by MFA, strict segmentation, and comprehensive session monitoring.
CISA specifically recommends using a jump host for secure, monitored access to internet-exposed systems and applying MFA, while its 2026 OT guidance recommends MFA for privileged remote access into OT.
Remote Engineer / Vendor
│
MFA + SSO
│
▼
Remote Access Broker
/ Zero-Trust Gateway
│
Firewall / DMZ
│
▼
OT Jump Host
(hardened, monitored)
│
┌─────┴─────┐
▼ ▼
SCADA/HMI Engineering
│ Workstation
└─────┬─────┘
▼
PLC / DCS
The key controls should be:
NIST's OT security guidance likewise identifies MFA as a best practice for remote OT access and emphasizes tailoring security controls to OT's reliability, availability, and safety requirements.
| Approach | Recommendation | Why |
|---|---|---|
| Direct RDP/VNC to OT | ❌ Avoid | Excessive exposure and weak segmentation |
| Traditional VPN into OT | ⚠️ Better than direct access | Can provide network-level access that's broader than necessary |
| VPN → jump server | ✅ Good | Stronger segmentation and control |
| Zero-trust/broker → OT jump host → specific asset | 🏆 Best | Least privilege, MFA, granular authorization, auditing |
| Vendor remote-access appliance/service | ✅ Excellent for vendor access | Purpose-built access control, session monitoring, temporary access |
There isn't one universally "best" product: CISA notes that no single remote-access solution is appropriate for every ICS architecture, and recommends defense-in-depth.
If you're selecting a commercial solution, I can also compare the leading OT remote-access platforms (e.g., Claroty, Nozomi Networks, OPSWAT, Zscaler, Palo Alto Networks, Fortinet, and BeyondTrust) specifically for security, architecture, vendor access, MFA, session recording, and cost.
The gold-standard approach for securing industrial control systems (ICS) and operational technology (OT) networks is a **Zero Trust Network Access (ZTNA) architecture combined with a DMZ-hosted jump server (or bastion host) and strict multi-factor authentication…
The gold-standard approach for securing industrial control systems (ICS) and operational technology (OT) networks is a Zero Trust Network Access (ZTNA) architecture combined with a DMZ-hosted jump server (or bastion host) and strict multi-factor authentication (MFA).
Legacy methods like direct Virtual Private Networks (VPNs) flatly connect an external user straight to the internal network, creating lateral movement risks if credentials are compromised. Modern OT security shifts away from this perimeter-only defense.
Key Components of a Secure OT Remote Access Solution
Comparison of Remote Access Strategies
| Strategy | Security Level | Implementation Complexity | Best Use Case |
|---|---|---|---|
| ZTNA + Jump Host | Highest | Moderate to High | Modernizing high-risk or critical infrastructure OT networks |
| DMZ Jump Server + VPN | High | Moderate | Standard industrial plants with legacy vendor support needs |
| Direct VPN to OT | Low / High Risk | Low | Not recommended due to lateral movement vulnerabilities |
For official guidelines and risk evaluations tailored to critical infrastructure, consult the CISA Industrial Control Systems Cybersecurity Guidance.
If you'd like to narrow this down, please let me know:
For most industrial environments, the **best approach is not a traditional “VPN straight into the OT network.”** I’d recommend a **brokered, least-privilege remote-access architecture** with a hardened OT jump host, MFA, strong segmentation, and just-in-time access. ### Recommended architecture **Remote user/vendor →…
For most industrial environments, the best approach is not a traditional “VPN straight into the OT network.” I’d recommend a brokered, least-privilege remote-access architecture with a hardened OT jump host, MFA, strong segmentation, and just-in-time access.
Remote user/vendor → MFA + access broker → IT/OT DMZ → hardened jump server → specific OT asset
Key controls:
CISA's OT remote-access guidance recommends VPN technology for standardized external access and specifically describes using a secured administrative “jump” server. CISA NIST SP 800-82 Rev. 3 likewise emphasizes designing OT security around the unique reliability, performance, and safety requirements of the environment.
| Approach | Recommendation | Why |
|---|---|---|
| Direct RDP/SSH to OT | ❌ Avoid | Excessive exposure |
| Port-forwarding/NAT to PLC/HMI | ❌ Avoid | Poor segmentation and accountability |
| Traditional VPN into entire OT subnet | ⚠️ Better than direct access | Can provide too much network reach |
| VPN → OT DMZ → jump server | ✅ Good | Stronger segmentation and control |
| ZTNA/access broker → OT DMZ → jump server → specific asset | 🏆 Best overall | Fine-grained, identity-based access |
| Physically isolated/no remote access | 🏆 Strongest isolation | Best for exceptionally safety-critical environments, but operationally restrictive |
There is an important nuance: Zero Trust Network Access (ZTNA) isn't automatically safer just because it's called Zero Trust. The implementation needs to preserve OT segmentation and account for legacy equipment that cannot support modern authentication. CISA's recent guidance notes the risks associated with vulnerable/misconfigured VPN deployments and recommends moving toward more granular, least-privilege access where appropriate.
My default recommendation:
Identity-aware ZTNA/broker + MFA + OT DMZ + hardened jump host + per-asset authorization + just-in-time vendor access + session monitoring/recording. For a real deployment, I'd design it around NIST SP 800-82r3 and your Purdue/ISA-95 network zones rather than selecting a product first. NIST's OT guidance remains the key reference, with a Rev. 4 draft also now in development.
If you tell me whether this is manufacturing, power, water, oil & gas, etc., and whether remote users are employees, vendors, or both, I can give you a concrete reference architecture and shortlist the best commercial solutions.