The maintenance exception becomes permanent infrastructure
Plants accumulate access paths over years: commissioning VPNs, supplier tunnels, shared support accounts and emergency connections created because production could not stop. The operational need may disappear while the trust path remains.
NIST SP 800-82 Rev. 3 treats remote access as part of the wider OT security architecture, while CISA’s exposure-reduction guidance highlights the continuing growth of Internet-accessible OT and remote-access technologies.
A VPN can authenticate a tunnel, but it does not automatically constrain every action once the user is inside. Legitimate engineering tools can make malicious or mistaken activity look like maintenance. The more useful control objective is an attributable maintenance transaction rather than a persistent network relationship.
A remote maintenance session should behave like a governed transaction with explicit identity, scope, time, evidence and closeout.
Can the organisation prove identity, purpose, actions, changed artefacts and session termination after maintenance ends?
ZTNA has to be designed around plant failure modes
The target state is strong user and device identity, exact destination and protocol scope, time limits, session recording and explicit approval for privileged actions. ISA/IEC 62443 provides the zone-and-conduit and lifecycle context needed to avoid treating remote access as an isolated IT feature.
But copying an IT access broker directly into a plant can create new availability risk. OT ZTNA has to account for vendor contracts, latency, local recovery, jump-host dependencies, offline operation and safety constraints. The break-glass path must be engineered and tested before the legacy VPN is removed.
The economic case is wider than subscription cost. One broad, unattributable supplier session can create downtime, forensic uncertainty and recovery delay that vastly exceed the cost of controlling the access path properly.
- Inventory every active and dormant supplier remote-access path.
- Map each path to the exact assets, protocols and actions it can reach.
- Replace shared accounts with attributable identity and phishing-resistant authentication.
- Record privileged sessions and retain evidence outside the managed endpoint.
- Test access-broker failure and local break-glass workflows under production constraints.
