remote access – Waterfall Security Solutions https://waterfall-security.com Unbreachable OT security, unlimited OT connectivity Wed, 22 Jul 2026 08:59:51 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.4 https://waterfall-security.com/wp-content/uploads/2023/09/cropped-favicon2-2-32x32.png remote access – Waterfall Security Solutions https://waterfall-security.com 32 32 Making OT Security Stronger Than IT https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/making-ot-security-stronger-than-it/ Tue, 21 Jul 2026 12:20:58 +0000 https://waterfall-security.com/?p=41894 OT security is “hard” – engineering change control (ECC) makes patching slow and expensive, many OT devices and systems have no real support for zero trust (ZT)...

The post Making OT Security Stronger Than IT appeared first on Waterfall Security Solutions.

]]>

Making OT Security Stronger Than IT

Making OT Security Stronger Than IT

OT security is “hard” – engineering change control (ECC) makes patching slow and expensive, many OT devices and systems have no real support for zero trust (ZT), and most OT systems have large subsystems that operate without encrypted or authenticated communications. But imagine – imagine we could “wave a magic wand” and solve all of this, instantly. With one gesture, we patch everything, encrypt everything and ZT everything. Would we be “done?”


No. IT networks have near-universal security updates, ZT and encryption. If with a “magic wand” we could make our OT networks exactly as strong as our IT networks, then for most OT networks this would be a material improvement over the present-day, but would not be enough. From first principles, most OT networks must be materially better protected than most IT networks. The severity of worst credible consequences of cyber compromise drives the strength of security program that any network or system needs.

How Can We Make OT Stronger?

One way to make OT stronger than IT is to make OT security programs reflect OT rather than IT priorities. In most IT systems, information is the asset we protect and preventing espionage is the priority – encrypt the information and otherwise control the ability of adversaries to read the information. In most OT systems, on the other hand, physical operations are the asset, preventing sabotage is the priority, and information is the threat – the only way an OT system can change from a normal to a compromised state is if attack information enters the system, somehow. In OT it is therefore vital to control the movement of information, because all information flows can contain attacks.

How do we do that? Some examples:

  • The humble “deny by default” rule – do not allow connections through the IT/OT firewall to email servers, Google, nor the Internet at large. We cannot afford to pull attack information into OT,
  • More powerful unidirectional gateways at the IT/OT interface are hardware components that enable real-time server synchronization outbound from OT to IT, and allows no attack information at all to flow back into OT from IT, nor from the Internet, and
  • Strict procedural, software and sometimes hardware controls over the use of removable media, such as DVD’s and USB thumb drives.


In most OT networks there are less than a dozen kinds of ways that information can enter the network. Lock them down. Lock them hard.

Cyber-Informed Engineering

More generally, the emerging Cyber-Informed Engineering (CIE) discipline, among other things, points out how to use “unhackable” engineering tools to both eliminate physical risk and to deterministically control the movement of attack information. What is “unhackable?” These are tools that behave deterministically, often without any CPU built in, or a monitor-only CPU, unable to alter the behavior of the device. These engineering-grade mitigations range from electromechanical overpressure relief valves to digital hardware such as FPGA’s and ASICs.


CIE is still under development. The most recent innovation is a database of some 62,000 records. Each record describes an “unhackable” mitigation that can be applied in a particular industry. And again, of all the engineering-grade mitigations in the database, deterministic network engineering tools such as unidirectional gateways and hardware-enforced network traffic filtering are by far the most universally applicable.

Anomaly Detection

Another way to make OT networks stronger than IT is with anomaly-based monitoring and intrusion detection systems. Most industrial networks change much less frequently than do IT networks, and are used very predictably, day after day. This means that we can tune our OT-aware anomaly-based IDS systems to be more aggressive about alerting on even small changes from “normal,” without introducing unmanageable numbers of false alarms.


That said, we must be careful not to confuse the pillars of the NIST Cybersecurity Framework (NIST CSF). For example, if a new bridge is designed with hydraulic dampers to counteract harmonic frequencies, it is not enough for the design engineer to “hope” that if a cyber attack targets the control system for the dampers, “hope” that we can detect the attack before the dampers are crippled and the bridge tears itself apart. “Hope” is not what we expect of design engineers – we expect bridges that carry a specified load, in a specified operating environment, for a specified number of decades, with a large margin for error – deterministically.
We do need the CSF detect, respond and recover pillars, and it is good that we can design our OT detection tools to be stronger than IT, but we must not confuse detection with protection.

Looking Forward

In short, how can we make OT security stronger than IT? With sabotage-focused deterministic network engineering, Cyber-Informed Engineering, and OT-aware anomaly detection. And yes, use IT tools as well – they “raise the floor” by bringing OT systems closer to the strength of IT systems, but cannot go beyond IT.
For more examples of how and why to make OT systems stronger than IT, please join our webinar on July 29, or access the recording afterwards at the same URL.

 

Register Now

About the author
Picture of Andrew Ginter

Andrew Ginter

VP Industrial Security, Waterfall Security

Andrew Ginter is the most widely-read author in the industrial security space, with over 23,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Making OT Security Stronger Than IT appeared first on Waterfall Security Solutions.

]]>
Big OT Security, Smaller Footprint – Meet DiodeCore! https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/big-ot-security-smaller-footprint-meet-diodecore/ Wed, 24 Jun 2026 07:50:40 +0000 https://waterfall-security.com/?p=41650 Two decades ago, we founded Waterfall with one purpose: to defeat nation-state attacks impacting OT environments and critical infrastructure.

The post Big OT Security, Smaller Footprint – Meet DiodeCore! appeared first on Waterfall Security Solutions.

]]>

Big OT Security, Smaller Footprint – Meet DiodeCore!

Picture of Lior Frenkel

Lior Frenkel

CEO and Co-Founder, Waterfall Security

DiodeCore Launch
Two decades ago, we founded Waterfall with one purpose: to defeat nation-state attacks impacting OT environments and critical infrastructure. We benchmarked our technology against so-called Advanced Persistent Threats (APTs) and other nation-state classes of attacks, then refined our technology, and then did it again. From our first Unidirectional Gateway to the WF-600 Performance, the Flip, and HERA Hardware-Enforced Remote Access™ - this is what we do.

And now, DiodeCore™

New, Advanced Cyber Threats

The fact that AI found hundreds of vulnerabilities in the Firefox open-source browser is really alarming. Firefox is a veteran, relatively highly secured open-source product that has been pen tested and code reviewed by governments, cyber companies and experts, multiple times. The Mythos AI found 250+ zero days in Firefox despite all this. 

What about products that are not open source, not as widely used, and not as seasoned. AI tools will find thousands of vulnerabilities, develop exploits, and chain those exploits together in ways that would have taken years for humans to figure out, code and test.

AI is taking nation-state grade tools and techniques and democratizing them, making nation-state grade attack capabilities available to a much wider audience, a much wider set of potential attackers. Within 12 or 24 months, I believe we are going to see fully automated and autonomous attacks on OT networks.

What is DiodeCore?

What can be done about this? The answer to these threats is not more software, but stronger hardware. Today we are officially launching the WF-600 DiodeCore, our newest addition to the WF-600 family. DiodeCore is a modern Unidirectional Gateway designed for simpler deployment scenarios: entry-level or simpler needs, smaller sites, and larger numbers of sites.

DiodeCore’s level of security, cybersecurity concepts, and unidirectionality are at the same hardware-enforced standard of protection Waterfall has always provided. And DiodeCore is a product that fits a different use case. I am very proud to introduce this to the market.

How DiodeCore Works

The hardware is a small, half-depth 1U rack-mount device. Open it up and there is a transmit circuit board, a receive circuit board, and a fiber between them. That fiber is the only physical connection between the two sides. The hardware is physically able to send information in only one direction. There is no laser in the receiving circuit board, and no photocell on the sending. It does not matter how clever the enemy is, and it does not matter if they are a human or an AI or a nation state. All cyber sabotage is based on information passing. The only way a control system can change from a normal state to a compromised state is if attack information enters the system. Interrupt the flow of attack information and you interrupt the attack.

The DiodeCore uses the same software as is used in the WF-600 Performance series, with the DiodeCore software delivered as a closed virtual machine image. This image can run on any standard customer virtualization infrastructure, from a VM server to a workstation, running Windows, Linux, ESXi and similar platforms. There is one virtual image for the OT network side, and another for the external network side. There’s no need for any dedicated wiring any more, directly connected servers or hosts. A lot of modern automation systems use virtualization – this is the modern method of deploying this technology.

The hardware in DiodeCore is the smallest amount of hardware you can have to still get the ultimate security value of a Unidirectional Gateway. DiodeCore has a small footprint, half the depth of a standard 1U appliance. DiodeCore is easy to deploy, easy to install and manage, and easy to purchase.

Hardware-Enforced Protection Anywhere You Need It

Today, customers can use our flagship WF-600 Performance where they need high-end performance, resilience, throughput, scale, and capability, while DiodeCore is designed to support:

  • Smaller and simpler sites
  • Distributed facilities
  • Large scale rollouts across many locations


We already have customers saying: “Okay, okay, launch it already. We want these!” And so, I am pleased to say today, DiodeCore is available now!

Talk to an OT Security Expert

If you are securing a smaller site, scaling protection across distributed facilities, or modernizing a virtualized OT environment, and you are wondering where a Unidirectional Gateway can fit in your architecture, please reach out to Waterfall.

There is no cost for a consultation – let our experts surprise you with strong unidirectional designs.

About the author
Picture of Lior Frenkel

Lior Frenkel

CEO and Co-Founder, Waterfall Security

Lior Frenkel is a cybersecurity entrepreneur, author, and global expert in OT and critical infrastructure security with more than 25 years of industry experience. As the CEO and co-founder of Waterfall Security Solutions, he has led the deployment of innovative unidirectional security technologies protecting critical infrastructure worldwide. Lior is a recognized thought leader who contributes to international cybersecurity policy, regulatory initiatives, and industry strategy. He also serves in leadership roles across major Israeli technology and manufacturing organizations, helping advance the global cybersecurity industry.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Big OT Security, Smaller Footprint – Meet DiodeCore! appeared first on Waterfall Security Solutions.

]]>
Mythos, Zero Days and OT Cybersecurity https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/mythos-zero-days-and-ot-cybersecurity/ Mon, 15 Jun 2026 14:09:11 +0000 https://waterfall-security.com/?p=40467 Anthropic’s Claude Mythos is the latest example of a trend many of us in industrial cybersecurity have been warning about for years.

The post Mythos, Zero Days and OT Cybersecurity appeared first on Waterfall Security Solutions.

]]>

Mythos, Zero Days and OT Cybersecurity

Picture of Lior Frenkel

Lior Frenkel

CEO and Co-Founder, Waterfall Security

Mythos, Zero Days and OT Cybersecurity
The advent of Anthropic’s Claude Mythos is the latest example of a trend many of us in industrial cybersecurity have been warning about for years. Sophisticated offensive cyber capabilities are no longer confined to elite nation-state teams with enormous budgets and years of specialized expertise. AI is “democratizing” cyber attacks, including attacks on operational technology (OT) systems.

Public reports describe Mythos as capable of discovering zero-day vulnerabilities, chaining together exploits of otherwise low-severity vulnerabilities into powerful attacks, reverse engineering proprietary systems, and automating large portions of advanced attack workflows.

Whether every public claim proves accurate is almost beside the point. The trajectory is unmistakable. Frontier AI models are reducing the cost, time, and expertise needed to conduct sophisticated cyber operations.

Watch our webinar on-demand
as we explore the impact of AI-driven cyber threats on OT security
and introduce Waterfall’s newest Unidirectional Gateway.

OT Targets

For OT environments, this matters enormously.

OT systems are intrinsically vulnerable. Rapid patching of OT systems is extraordinarily expensive and difficult. In safety-critical and reliability-critical environments, patches cannot simply be deployed overnight. Engineering change control processes that minimize safety and reliability risks require testing, validation, outage coordination, safety review, and operational acceptance. 

In many facilities, those processes take months or years. Worse, patching (hopefully) remediates only known defects, and again, AI’s have proven adept at finding previously unknown vulnerabilities. Even with a patching “magic wand,” IT and OT systems would still be intrinsically vulnerable.

Remember Fuzzing?

That said, the discovery of large numbers of zero-day vulnerabilities is not entirely new. A decade+ ago, fuzzing technologies dramatically increased the rate of discovering vulnerabilities in both IT and OT systems. Automated fuzzing campaigns uncovered large numbers of latent defects in industrial protocols, embedded devices, operating systems, and applications.

What is different today is the scale, exploitability and sophistication of zero-day attacks. Again:

  • The volume of vulnerabilities being discovered is increasing dramatically,
  • Systems like Mythos are able to chain together low-severity vulnerabilities into much more dangerous attacks, and
  • Perhaps most important, AI systems are increasingly capable of automating sophisticated offensive workflows.


Today those workflows still involve human oversight. Tomorrow they will not!

The Perimeter Is Dead? No…

All this means OT perimeter protection becomes increasingly important – hardening the interior to zero-day attacks was and is simply not achievable – not for IT systems and not for OT systems. This problem is precisely why Waterfall’s Unidirectional Gateways were invented almost 20 years ago. Waterfall’s gateways were designed from the beginning to withstand nation-state-grade attacks against OT targets, including sophisticated attacks exploiting zero-day vulnerabilities.

In contrast, conventional firewalls depend on software correctness. Even “next generation” firewalls ultimately rely on operating systems, protocol stacks, parsing engines, authentication systems, and millions of lines of software behaving perfectly correctly under hostile conditions. Zero-day vulnerabilities undermine all of these assumptions – exploit a zero-day, or a sequence of zero-days, and completely take over the CPU / software in an ultra-sophisticated next-gen firewall, and the device does the attackers’ bidding, not the defenders’.

Waterfall’s Unidirectional Gateways – “Immune” to Zero-Days

Waterfall’s gateways are a combination of hardware and software. The hardware is physically able to send information in only one direction – usually from the OT network out to the IT network, so that the business can profit from access to OT information. The hardware, however, is not physically able to send any information nor cyber-sabotage attack information back into OT networks. There is no return path, physically.

This is why Waterfall’s Gateways are fundamentally immune to network-based zero-day exploits aimed at crossing the protection boundary. Even if the gateways’ IT-exposed software is compromised, there is physically no way for that software to send attack information back into the OT network.

As a side note, yes, comprehensive OT security programs are still important in unidirectionally-protected networks. Intrusion detection, security monitoring, asset inventory, vulnerability management, and capable incident response are all needed to address residual risks. But detection and response take time. Human investigation takes time. Escalation takes time. Remediation takes time. In a future of highly automated AI-driven attacks, we will not have that time – we urgently need to block AI’s from simply reaching across networks and into critical OT systems.

Looking Forward

Over the next 2-3 years, we are entering one of the most dangerous periods OT security has faced. In that environment, deterministic protection is essential. Unidirectional gateways are not the only control we need, but they are one of the few technologies specifically engineered from the beginning to remain effective, even when sophisticated attackers possess zero-days, advanced malware, and increasingly powerful AI assistance.

Waterfall’s The gateways are exactly the kind of deterministic, engineering-grade protections we need for the difficult years ahead.

About the author
Picture of Lior Frenkel

Lior Frenkel

CEO and Co-Founder, Waterfall Security

Lior Frenkel is a cybersecurity entrepreneur, author, and global expert in OT and critical infrastructure security with more than 25 years of industry experience. As the CEO and co-founder of Waterfall Security Solutions, he has led the deployment of innovative unidirectional security technologies protecting critical infrastructure worldwide. Lior is a recognized thought leader who contributes to international cybersecurity policy, regulatory initiatives, and industry strategy. He also serves in leadership roles across major Israeli technology and manufacturing organizations, helping advance the global cybersecurity industry.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Mythos, Zero Days and OT Cybersecurity appeared first on Waterfall Security Solutions.

]]>
3 OT Security Myths https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/3-ot-security-myths/ Sun, 10 May 2026 06:50:46 +0000 https://waterfall-security.com/?p=39498 If only we could wave a magic wand and patch everything and zero-trust everything, just like with our IT networks, then our OT networks would be “secure”

The post 3 OT Security Myths appeared first on Waterfall Security Solutions.

]]>

3 OT Security Myths

There are many misconceptions and myths in operational technology (OT) security. This is a problem, because when we start with the wrong premises, then we most often draw incorrect conclusions – this is how logic works. Let's look at some OT security myths and misconceptions and see how they lead us astray.
Picture of Andrew Ginter

Andrew Ginter

Everything you Know About OT Security is wrong

1) Information is the asset we protect – protect the confidentiality, integrity and availability (CIA) of the information, in that order, or maybe in AIC order, or IAC, or something.

Information is the asset we protect in most IT networks. In OT networks, in contrast, we most often protect safe, reliable and efficient physical operations. Take a metro for example: safety is first – nobody wants to die on the way to work. Reliability next – the metro needs to get hundreds of thousands of people to work every day, and passengers want their trains to be on time. And then efficiency – it does no good to have the world’s safest, most reliable metro, if the population cannot afford to use it.

So what? Can we not stand on our heads and say there must be information somewhere in the metro’s automation system that we can protect? Well, we can stand on our heads, yes, a lot of people do, but why bother? 50-year-old cybersecurity theory (Bell / La Padula) teaches us how to prevent theft or leakage of important information. Many of us learned this theory in school. What we did not learn is that 2 years after Bell & La Padula came out with their theory, Biba came out with a complementary theory.

Bell / La Padula teach us how to prevent espionage – theft or leakage of important information (eg: how to make a Nuclear Bomb – these researchers were funded by the US DoD in their day). Biba teaches us how to prevent sabotage (eg: changing the targeting coordinates for the missiles delivering The Bomb).

Biba’s theory used exactly the same concepts and terminology as Bell / La Padula but applied the concepts differently. In Biba’s theory, information is not the asset we protect, but the threat. All cyber-sabotage is defined (mathematically) as information. The only way a targeting system or an OT control system can change from a normal state to a compromised state is if attack information enters the system – somehow. The goal with OT systems is not to “protect the information” – the CIA, or IAC, or AIC of the information. The goal is to protect control systems from information – to keep attack information from affecting critical functions, such as safe, reliable and efficient physical operations.

Get this wrong and we fixate on information as the asset, when attack information entering the system is in fact the threat we must defeat.

2) Asset inventory is one of the first steps towards OT security – we cannot protect what we don’t know we have.

Here is an example of how misinterpreting the asset bites us. If we are to prevent theft or leakage of that information, it is vital that we know what and where that information is. We cannot prevent theft or leakage of information if (a) we do not know it exists or (b) we do not know where it is. An asset / information inventory is therefore one of the very first steps we must carry out if we are to design mechanisms to protect our information assets.

Biba, however, teaches us that information is the threat. This means that one of the very first things we must do is not inventory where our information lives, but rather inventory all of the ways attack information can reach our vulnerable OT systems. We need an inventory of data flows, most importantly those data flows that enter our OT systems from the “outside” – from potentially compromised sources. Understanding our perimeter and data flows that cross the perimeter is much more important than enumerating all of the countless “information assets” inside that perimeter.

Technical note: these perimeter-crossing data flows can be online or offline. Offline means the attack information lives in physical media, like USB thumb drives, laptops, or new computers arriving from our suppliers. We physically carry offline information into contact with our OT systems. Online information is more ephemeral – it is communicated into our systems with the movement of electrons, photons, electric or magnetic fields, or event sound waves – vibrations and quantum “things” rather than the movement of macroscopic physical objects.

Yes, eventually we will probably also benefit from an inventory of computer & information assets, but for most of us, our first priority is to prevent or control the movement of attack information into our systems – not protect that information, for example by encrypting that attack information.

 

3) If only we could wave a magic wand and patch everything and zero-trust everything, just like we do our IT networks, then our OT networks would be “secure.”

In most OT networks, the worst credible consequences of compromise are completely unacceptable: things blow up and people die. Or long-lead-time physical equipment is destroyed, and production / infrastructure is down for months or years, not hours or days. In most IT networks, the worst credible consequences are undesirable, and sometimes material, but will not put us out of business. This is the essential difference between most IT and OT networks: we cannot “restore” human lives nor damaged equipment from backups.

This means that even if we could wave our magic wand and secure OT networks exactly as we secure our IT networks, then our OT security program would still be woefully inadequate. The worst credible consequences (credible = reasonable to expect) define the required strength of our security program. When consequences are unacceptable, we need to protect our OT networks much more thoroughly than we protect our IT networks. Our postulated “magic wand” is not nearly enough.

Summing Up

Don’t get me wrong – I’m not saying information is never an asset (robotic programs in discrete manufacturing can be very valuable), nor that asset inventory is useless, nor that IT-style security mechanisms, where we can manage to apply them in OT, are pointless. What we’re talking about here is priorities. If we apply the world’s very best “protect the information assets” IT security program to OT systems, we might, accidentally, prevent material sabotage of physical operations. And we’ll probably spend an enormous amount of money doing that.

Moreover, no security program is complete until it has all the pillars of the NIST CSF: govern, identify, protect, detect, respond and recover. I’m not saying to ignore any of those pillars. To one extent or another, we most often need to “do it all,” but in which order, and where should the funding / implementation priorities lie?

What I am saying is that if we understand our priorities and constraints more accurately, then we can do a much more effective job of all of the above, for far less money.

About the author
Picture of Andrew Ginter

Andrew Ginter

Andrew Ginter is the most widely-read author in the industrial security space, with over 35,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.
Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post 3 OT Security Myths appeared first on Waterfall Security Solutions.

]]>
8 (and a Half) Questions for Your OT “Secure” Remote Access Vendors https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/8-and-a-half-questions-for-your-ot-secure-remote-access-vendors/ Wed, 01 Apr 2026 05:26:23 +0000 https://waterfall-security.com/?p=39051 Ask different questions, get different answers. What should you be asking your OT “secure” remote access (SRA) vendor?

The post 8 (and a Half) Questions for Your OT “Secure” Remote Access Vendors appeared first on Waterfall Security Solutions.

]]>

8 (and a Half) Questions for Your OT “Secure” Remote Access Vendors

Ask different questions, get different answers: What should you be asking your OT “secure” remote access (SRA) vendor?
Picture of Waterfall team

Waterfall team

Terminology first. The word “secure” is in quotes, because cybersecurity (like safety) is a continuum, not a pair of discrete yes/no states. We can always be safer, or less safe. We can always be more secure, or less. The question “Are we secure?” is meaningless. The question “How secure are we?” has an answer. The question “How secure should we be?” is even more important. Anyone who uses “secure” as an adjective is selling something – “secure” communications (really: encrypted and/or authenticated), “secure” boot (really: cryptographically authenticated firmware), “secure” by design (really: better security by designing security in), and so on.

There is no such thing as “secure” remote access.

Want to learn more about OT remote access? Watch our webinar: “13 Ways To Break “Secure” OT Remote Access Systems”

Question 1: For SRA into OT systems, does your vendor provide IT-grade protection we HOPE can detect attacks in time, or do they provide hardware-enforced, engineering-grade protection?

What is IT-grade protection? Imagine a long suspension bridge has dangerous harmonic frequencies – people simply walking over the bridge risk setting up oscillations that build up, eventually to the point of tearing the bridge apart. See the 1940 Tacoma Narrows disaster for an example. Imagine that a bridge you cross every day on the way to work has this problem, and so is stabilized by hydraulic dampers – multiply redundant dampers, redundant power supplies and “secure” control systems. How happy would you be driving across that bridge every day if you knew the design engineer HOPED that, if there was a cyber attack on the control system, HOPED we could detect the attack before the bridge tore itself apart. How happy would you be knowing the design engineer HOPED that, if we detected the attack in time, HOPED we could scramble an incident response team fast enough to prevent disaster?

Hope is not what we expect of design engineers. we expect bridges to carry a specified load, in a specified operating environment, for a specified number of decades, with a large margin for error. Engineering-grade solutions, like over-pressure relief valves and unidirectional gateways, behave deterministically, no matter how sophisticated a cyber attack is launched at them.

Question 2: If someone phishes an SRA credential, can they exploit a vulnerability in the Multi-Factor Authentication (MFA) to get into the protected OT systems?

“Secure” Remote Access vendors boast about their MFA, but MFA is software. Yes, the little dongle on our keychain looks like hardware, but the “secure” SRA system we are logging into with the dongle is software. All software has defects, and some defects are security vulnerabilities. Some of those vulnerabilities are known to the SRA product developers, who are madly trying to develop patches / security updates for the vulnerabilities. Others are known only to our enemies, who are using these zero-day vulnerabilities against us without our knowledge. Our attackers phish our “secure” password, ignore our RSA dongle or cell phone authentication app, and exploit a zero-day in the “secure” system to break in with our credentials and work their will upon our OT networks. Is this possible in the “secure” system we are using or considering using?

Question 3: Is that SRA a H2M solution, or an M2M solution?

Terminology:

  • H2M = human-to-machine = sends keystroke & mouse movements in / receives screen images back out.
  • M2M = machine-to-machine = software talking to software – for example: an HMI running on our remote laptop, talking through a VPN to PLCs or OPC servers in the OT network, or a PLC programming tool on our remote laptop, talking through a VPN to update firmware in our safety-instrumented systems (SIS).


When “secure” remote access supports M2M, then any malware that might be present on our laptops can reach across the M2M/VPN and connecting to any vulnerable, out-of-date (eg: XP) OT systems in our OT network. Such systems are a bonanza to common malware that relies on exploiting known vulnerabilities.

Question 4: Can users override SRA encryption / certificate warnings?

Many “secure” OT solutions use industry standard Transport Layer Security (TLS) to protect their connections across the Internet. This is the same technology used by web browsers, M2M applications, and the vast majority of Internet and IT applications. TLS uses certificates. If an attacker intercepts our communications, they can substitute their certificates. Our software – eg: our web browsers – are supposed to diagnose the substitution. A lot of these applications, like many web browsers, caution their users when they see an unexpected certificate and ask if the user really wants to proceed. Most users answer, “yes of course – override the warning / force the connection to complete / finally I’m connected through this nonsense!” And they successfully use their MFA and other credentials to log into the “secure” remote access system in a way that lets the bad guys take over their session.

Question 5: Can you paste or file-transfer arbitrarily complex files into OT equipment remotely?

A lot of OT equipment is sensitive – it malfunctions if anti-virus is running on it, so we do not run AV on it. It costs a lot of money to re-certify for safety if anything changes, so we have not applied any security updates, nor upgrade the operating system. These systems are often found still running obsolete versions of Windows XP. What risk is there in downloading a PDF file to this device? Or a software update executable? Or a clever new OT tool we just found on the Internet that claims it can “clean the hard drive” on this very old, very vulnerable, very important OT system? If people can transfer files that can contain malware, sooner or later they will do so. Does our “secure” remote access permit this very dangerous operation?

Question 6: Is there a session timeout?

Many users find session timeouts to be really annoying. Users must log in repeatedly when they get distracted by other emergencies during OT SRA sessions. But what happens if there is no session timeout? We log in and finish a job in the evening on our home computer. We go to work the next day. Our kids log into the home computer to do their homework. They find our session still open, still connected. What harm could that cause? Or – we put no password on our cell phones, because constantly entering PINs is annoying. Now open a “secure” remote access session, set the phone down and forget it. A stranger picks it up. There is no PIN. The remote session is still active into our critical infrastructure operations. What harm could be done?

Question 7: Do you require deny-by-default on firewalls protecting OT networks?

Many “secure” remote access vendors claim we can install their software on the OT computer of your choice, and the software will connect straight out to the Internet through IT/OT and IT firewalls, without needing to do anything to reconfigure the firewalls. This design assumes that OT firewalls are configured like most IT firewalls are configured – they allow any outbound connection by default, disallowing only inbound connections and outbound connections to known-dangerous destinations.

Such configuration means the “secure” remote access solution counts on a firewall configuration that any well-meaning technician on the OT network can use to install their own rogue remote access solution, among other things. For example: open a persistent SSH connection to a home Linux computer that is able to forward connections back into OT systems or download a “free” remote access / support solution, connect it out to the cloud and at home, rendezvous with this solution from a home computer. Well-meaning technicians imagine that there is no need to “bother” IT or engineering with matters like this when anyone with the most modest of computer skills can download and install whatever “secure” remote access software they wish, using their XP admin credentials.

Question 8: Does your OT SRA need a firewall?

Most SRA vendors assume there is a firewall between the IT and OT networks, and their SRA software relies on establishing connections through this firewall. Firewalls, however, are vulnerable to many attacks. For examples, see Thirteen Ways to Break a Firewall. In contrast, Hardware-Enforced Remote Access™ (HERA), for example, is compatible with, but does not require a vulnerable firewall at the IT/OT interface.

Question 8 1/2: Does your SRA support MFA?

We count this as only half a question, because all commercial-grade OT SRA supports MFA. The only SRA without MFA is the “roll your own” kind, where you are hard-pressed to find any vendor to ask these questions of in the first place. Internet-exposed, and even IT-exposed OT facilities should all support MFA and we must enable that MFA without fail.

Digging Deeper

To better understand why these questions are important, or to dig deeper into the simple attack scenarios that lie behind these questions, watch our webinar 13 Ways To Break “Secure” OT Remote Access Systems – And questions you should be asking your OT SRA vendor about these attacks.

About the author
Picture of Waterfall team

Waterfall team

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post 8 (and a Half) Questions for Your OT “Secure” Remote Access Vendors appeared first on Waterfall Security Solutions.

]]>
Secure Industrial Remote Access Solutions https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/secure-industrial-remote-access-solutions/ Thu, 28 Aug 2025 20:19:01 +0000 https://waterfall-security.com/?p=35720 Secure, efficient, and reliable industrial remote access solutions enable monitoring, maintenance, and troubleshooting of SCADA and control systems from anywhere, protecting critical operations.

The post Secure Industrial Remote Access Solutions appeared first on Waterfall Security Solutions.

]]>

Secure Industrial Remote Access Solutions

Industrial remote access enables secure, efficient connectivity to SCADA, PLCs, and other control systems, supporting maintenance, monitoring, and troubleshooting. Best practices include robust authentication, encryption, network segmentation, and compliance with standards like IEC 62443 and NIST, while solutions like Waterfall’s HERA provide zero-trust, reliable remote access for critical industrial operations.
Picture of Waterfall team

Waterfall team

Secure Industrial Remote Access Solutions

Industrial remote access is a secure method that allows technicians to connect to, monitor, and manage industrial equipment from remote locations. It uses protected networks, such as VPNs, to enable maintenance, troubleshooting, and diagnostics without on-site presence, reducing downtime, costs, and safety risks while improving efficiency.

In today’s hyperconnected industrial world, remote access has become both a necessity and a risk. Organizations across manufacturing, energy, utilities, and critical infrastructure rely on remote connectivity to monitor systems, troubleshoot equipment, and enable vendor support without dispatching teams onsite. While this brings significant efficiency and cost benefits, it also introduces new security challenges. Unsecured or poorly managed remote connections can serve as entry points for cyberattacks, threatening operational continuity and even safety.

Industrial remote access, therefore, requires a comprehensive framework, one that balances the operational need for connectivity with rigorous security controls. This framework isn’t just about VPNs or firewalls; it encompasses identity management, secure protocols, granular access policies, and continuous monitoring, all tailored to the unique demands of operational technology (OT) environments.

Definition and Scope

What is Industrial Remote Access?
Industrial remote access refers to the secure ability to connect to industrial systems, equipment, and control environments—such as SCADA, PLCs, and HMIs—from distant locations. This connectivity enables operators, engineers, and vendors to monitor performance, troubleshoot issues, deploy updates, and maintain equipment without being physically present at the facility.

How it differs from IT Access

Unlike general IT remote access solutions (think remote desktop tools or corporate VPNs), industrial remote access must account for the unique requirements of operational technology (OT). OT systems prioritize availability, safety, and reliability over typical IT concerns like data confidentiality. While IT remote access is often focused on office productivity, industrial remote access deals with real-time processes, critical infrastructure, and potentially life-safety functions—making its risk profile significantly higher.

A Brief Historical Evolution

Remote access in industry began with direct connections—dial-up modems or leased lines that allowed engineers to reach specific machines. Over time, this evolved into VPN-based approaches and, more recently, cloud-enabled remote access platforms. Each step has increased flexibility and ease of use, but also expanded the attack surface. Today, modern solutions integrate identity and access management, encrypted communications, and continuous monitoring to strike a balance between connectivity and security.

Importance in Modern Manufacturing

Role in Industry 4.0 and Smart Manufacturing

Industrial remote access is a cornerstone of Industry 4.0, where interconnected devices, automation, and data-driven insights define the future of manufacturing. Smart factories depend on continuous access to machine data, predictive maintenance, and real-time monitoring—all of which require reliable and secure remote connectivity. Without industrial remote access, the promise of fully digitalized and adaptive manufacturing environments would remain out of reach.

Benefits for Modern Operations

The practical advantages of industrial remote access are compelling. Manufacturers can dramatically reduce downtime by enabling engineers to diagnose and resolve problems without waiting for travel or onsite presence. Remote updates and configuration changes cut costs while ensuring systems stay current with minimal disruption. Most importantly, operational efficiency improves when plants can be monitored and optimized from anywhere, allowing scarce engineering talent to support multiple sites simultaneously.

Adoption Rates Across Sectors

Adoption of industrial remote access has accelerated rapidly. According to industry surveys, more than 60% of manufacturers now use some form of remote access for equipment maintenance, with adoption highest in sectors like energy, automotive, and pharmaceuticals. The pandemic further accelerated this trend, as facilities sought safe ways to maintain continuity without sending large teams onsite. These adoption rates underscore that remote access is no longer a “nice-to-have,” but an operational necessity in competitive, modern manufacturing.

Key Stakeholders and Use Cases

Machine Builders and OEMs Providing Remote Support

Original Equipment Manufacturers (OEMs) and machine builders increasingly rely on remote access to deliver timely support for their equipment deployed at customer sites. Instead of dispatching technicians worldwide, OEMs can diagnose faults, apply software patches, and guide operators in real time. This not only enhances customer satisfaction but also opens opportunities for new service-based business models.

System Integrators and Remote Commissioning
System integrators play a critical role in setting up and maintaining industrial systems. With secure remote access, they can perform commissioning tasks, configure programmable logic controllers (PLCs), and troubleshoot integration issues without physically being onsite. This accelerates project timelines, lowers costs, and ensures quicker adaptation to client needs.

Plant Operators Monitoring Production Lines
For plant operators, remote access provides continuous visibility into production processes. Operators can track performance metrics, spot deviations, and intervene as necessary from any location. This level of oversight ensures not only higher productivity but also quicker response to emerging issues, which can prevent costly downtime and safety incidents.

Maintenance Teams and Preventive Care
Maintenance engineers benefit enormously from industrial remote access. With real-time monitoring, they can detect anomalies before failures occur, plan preventive maintenance, and conduct corrective interventions remotely when possible. This proactive approach extends equipment life, reduces unplanned outages, and optimizes spare parts management.

Technical Architecture and Components

Connection Methods

VPN Tunnels and Secure Connection Protocols

Virtual Private Networks (VPNs) are one of the most common methods for establishing secure remote connections to industrial environments. They create encrypted tunnels that shield data traffic between external users and internal control systems, helping to prevent unauthorized interception. When paired with industrial-grade firewalls and authentication controls, VPNs provide a strong security foundation for remote access.

Cellular Connectivity Options (4G/5G)

Cellular connections have become increasingly attractive for remote industrial sites where wired infrastructure is limited or unavailable. With the advent of 4G and especially 5G, industrial facilities can achieve low-latency, high-bandwidth connectivity suitable for real-time monitoring and even control tasks. However, security hardening and proper device management are critical to prevent exploitation of cellular endpoints.

Ethernet Solutions for Local and Wide Area Networks

Ethernet-based connections remain a cornerstone of industrial networking. Whether through local area networks (LANs) within a plant or wide area networks (WANs) linking multiple facilities, Ethernet provides reliable, high-speed data transfer for SCADA, PLCs, and other control devices. Segmenting industrial Ethernet networks into security zones and managing traffic with firewalls ensures safe integration of remote access capabilities.

Internet-Based Access Mechanisms

As Industry 4.0 pushes systems toward cloud integration, internet-based access has become more widespread. Technologies such as secure web gateways, remote desktop protocols (RDP), and vendor-provided cloud platforms enable access through standard internet connections. While highly flexible, these methods also broaden the attack surface, making robust encryption, authentication, and monitoring essential components of secure deployment.

Hardware Infrastructure

Edge Gateways

Industrial-Grade Remote Access Gateways

Edge gateways are specialized devices that serve as secure bridges between external networks and industrial control systems. Unlike generic IT routers, industrial-grade remote access gateways are built with features tailored for OT, such as deep protocol inspection, built-in encryption, and role-based access control. They form a critical first line of defense, ensuring that only authorized and authenticated connections reach sensitive equipment.

Ruggedized Design for Harsh Environments

Industrial environments often involve extreme temperatures, dust, vibration, or electrical noise—conditions that typical IT hardware cannot withstand. Ruggedized edge gateways are designed to operate reliably in these harsh settings, providing uninterrupted remote access even in mission-critical facilities such as oil rigs, power plants, or manufacturing floors. This resilience is essential to maintaining secure connectivity without compromising system uptime.

Integration Capabilities with Existing Infrastructure

One of the strengths of modern edge gateways is their ability to integrate seamlessly with existing industrial infrastructure. They support a wide range of industrial protocols (e.g., Modbus, OPC UA, PROFINET) and can connect legacy equipment to modern remote access frameworks. This makes them invaluable for organizations seeking to modernize their systems incrementally while maintaining backward compatibility with their operational technology.

Control Systems Integration

PLC Connectivity Options

Programmable Logic Controllers (PLCs) are at the heart of industrial automation, and enabling secure remote access to them is essential for monitoring, programming, and troubleshooting. Modern solutions offer connectivity through encrypted VPN tunnels, protocol-specific gateways, or cloud-based interfaces, ensuring engineers can manage PLCs without exposing them directly to the internet. This secure connectivity reduces the risk of unauthorized manipulation while allowing timely interventions.

HMI Remote Visualization Techniques

Human-Machine Interfaces (HMIs) provide operators with a window into industrial processes, and remote visualization extends this capability beyond the plant floor. Techniques such as web-based dashboards, thin-client applications, or secure remote desktop sessions allow engineers to view and interact with HMI screens from afar. When properly secured, this enables faster response times and decision-making without compromising the integrity of the control system.

Control Panel Access Methodologies

Traditional control panels house critical switches, indicators, and manual overrides. With remote access, these panels can be virtually replicated, giving authorized users the ability to monitor or control key functions securely. Methods range from digital twins to secure remote terminal access, which balance the need for operator flexibility with strict safeguards that prevent unsafe operations or accidental activations.

Remote Access Client Applications

Client applications are the user-facing software that enable engineers, operators, and saervice providers to establish secure connections to industrial assets. These lightweight tools often include multi-factor authentication, encryption, and role-based access to ensure that only authorized users can reach sensitive systems. A well-designed client simplifies the user experience while embedding strong security by default.

Server-Side Management Platforms

Behind every secure remote access solution lies a management platform that enforces policies, provisions users, and controls connectivity. These platforms often reside on-premises, in the cloud, or as hybrid solutions, and provide administrators with centralized visibility and governance. By managing sessions, configurations, and permissions from a single interface, they reduce complexity while strengthening compliance and security.

Authentication and Authorization Systems

Robust authentication and fine-grained authorization are the backbone of secure remote access. Beyond simple usernames and passwords, modern solutions employ multi-factor authentication (MFA), certificate-based access, and role-based control to ensure that users can only perform actions aligned with their responsibilities. In SCADA and industrial contexts, this limits the potential impact of compromised accounts or insider misuse.

Monitoring and Logging Tools

Visibility is essential in remote access environments, and monitoring and logging tools provide the audit trail needed for both security and operational oversight. These systems capture session details, command histories, and user activity, which can be analyzed for anomalies or compliance reporting. Real-time monitoring also enables rapid detection of unauthorized actions, helping to contain potential threats before they escalate.

Security Framework for Industrial Remote Access

Threat Landscape

Common Attack Vectors Targeting Industrial Systems

Industrial systems face attack vectors ranging from stolen credentials and phishing to compromised remote access tools and exploitation of unpatched software. Attackers frequently exploit weak authentication, exposed VPNs, and misconfigured firewalls to gain an initial foothold. Once inside, they may move laterally across the network to target control systems, disrupt operations, or exfiltrate sensitive data.

Documented Incidents and Case Studies

Real-world incidents highlight the risks of insecure remote access. For example, the 2021 Oldsmar water treatment facility breach involved an attacker remotely accessing operational systems and attempting to manipulate chemical levels in the water supply. Similarly, ransomware campaigns have locked out operators from remote monitoring systems, forcing costly shutdowns. These cases underscore the dangers of inadequate security controls.

Emerging Threats Specific to Remote Industrial Environments

As industrial environments increasingly rely on cloud-based connectivity, IoT devices, and mobile access, new threats emerge. Attackers are developing malware tailored to industrial protocols, exploiting insecure edge devices, and leveraging supply chain compromises to infiltrate trusted systems. The rise of ransomware-as-a-service and nation-state actors targeting critical infrastructure further amplifies the risk, making proactive defense measures essential.

Compliance and Standards

IEC 62443 Requirements for Remote Access

IEC 62443, the leading standard for industrial automation security, establishes strict requirements for secure remote access. It outlines measures such as strong authentication, session encryption, access control policies, and audit logging. Compliance ensures that remote connectivity to control systems is governed by the principle of least privilege and monitored to detect anomalies.

NIST Cybersecurity Framework Application

The NIST Cybersecurity Framework (CSF) provides a flexible model for managing risk in industrial environments, including remote access. By applying its five core functions—Identify, Protect, Detect, Respond, and Recover—organizations can align remote access strategies with broader cybersecurity goals. For example, the “Protect” function stresses identity management and access controls, while “Detect” highlights continuous monitoring of remote sessions.

Industry-Specific Regulations and Guidelines

Different industrial sectors have their own compliance mandates for remote access security. Energy companies must follow NERC CIP standards, while pharmaceutical manufacturers often adhere to FDA regulations for electronic records integrity. The oil and gas sector may face additional regional requirements. Aligning remote access practices with these sector-specific guidelines not only reduces risk but also ensures legal and regulatory compliance.

Certification Processes for Secure Remote Access Solutions

Vendors offering remote access technologies are increasingly seeking certifications to demonstrate compliance and trustworthiness. Certifications such as IEC 62443-4-2 for components or third-party security audits validate that solutions meet stringent cybersecurity requirements. For end-users, choosing certified solutions helps reduce vendor risk and provides assurance that the tools enabling remote access won’t become the weakest link in the control environment.

Securing industrial remote access is no longer optional—it’s essential for protecting operations, maintaining uptime, and safeguarding critical infrastructure. By implementing best practices across authentication, encryption, network segmentation, and monitoring, organizations can reduce risk while reaping the benefits of modern connectivity. 

To see how these principles are applied in practice, explore Waterfall’s HERA remote access solution, a purpose-built platform that provides secure, reliable, and zero-trust remote connectivity for industrial systems. 

Learn more about HERA and how it can safeguard your operations today.

About the author
Picture of Waterfall team

Waterfall team

FAQs About Industrial Remote Access Solutions

Industrial Remote Access Solutions are specialized technologies that allow authorized personnel to securely connect to industrial control systems—such as SCADA, PLCs, and HMIs—from remote locations. These solutions enable monitoring, troubleshooting, maintenance, and updates without requiring on-site presence, all while addressing the unique requirements of operational technology (OT) environments where availability, reliability, and safety are critical. They typically combine secure connectivity methods, robust authentication and access controls, monitoring and logging, and seamless integration with both modern and legacy industrial systems, ensuring that remote access enhances efficiency without compromising security.

 
 
Ask ChatGPT

We need industrial remote access solutions because modern industrial operations demand real-time monitoring, rapid troubleshooting, and efficient maintenance across geographically dispersed facilities. Remote access enables engineers, operators, and vendors to respond quickly to issues, reduce downtime, and optimize production without the delays and costs of traveling on-site. Additionally, with the rise of Industry 4.0, cloud integration, and smart manufacturing, secure remote connectivity is essential for leveraging data-driven insights, predictive maintenance, and continuous process optimization—all while maintaining strict security controls to protect critical infrastructure from cyber threats.

The main use cases for industrial remote access solutions include equipment monitoring, troubleshooting, and maintenance, allowing engineers and operators to diagnose issues and apply fixes without being physically on-site. They also support system commissioning, configuration updates, and software patching for PLCs, SCADA, and HMIs. Additionally, remote access enables vendor and contractor support, real-time production monitoring, and data collection for analytics and predictive maintenance. These use cases improve operational efficiency, reduce downtime, lower costs, and ensure that industrial facilities can respond rapidly to both routine and emergency situations while maintaining security and compliance.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Secure Industrial Remote Access Solutions appeared first on Waterfall Security Solutions.

]]>
Rethinking Secure Remote Access for Industrial and OT Networks https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/rethinking-secure-remote-access-to-industrial-and-ot-networks/ Wed, 06 Aug 2025 09:38:01 +0000 https://waterfall-security.com/?p=35035 Discover which remote access technologies truly secure industrial and OT networks—and which leave critical operations exposed.

The post Rethinking Secure Remote Access for Industrial and OT Networks appeared first on Waterfall Security Solutions.

]]>

Rethinking Secure Remote Access for Industrial and OT Networks

Rethinking Secure Remote Access for Industrial and OT Networks

Remote access is essential—but traditional solutions like VPNs and jump hosts are increasingly under fire from both attackers and regulators. With guidance from CISA and CCCS urging organizations to move beyond legacy remote access tools, the stakes for industrial and OT networks have never been higher.

This ebook demystifies secure remote access technologies, from classic firewalls and 2FA to hardware-enforced solutions and unidirectional gateways. Discover which approaches truly protect against today’s threat landscape—and which leave critical operations exposed.

Download the book now to:

arrow red right Gain a deep understanding of modern and legacy remote access technologies – including VPNs, firewalls, 2FA, jump hosts, cloud systems, and hardware-enforced solutions.

arrow red right Explore common attack scenarios and assess how different combinations of security technologies perform against actual threats

arrow red right Learn which security measures are most effective for specific attack types, helping you make informed decisions about protecting remote access in your organization

About the author
Picture of Waterfall team

Waterfall team

FAQs About Remote Access

Remote access for OT (Operational Technology) networks is the ability to connect to and control industrial systems from outside the facility—often over the internet or corporate IT networks.

This allows engineers, vendors, or operators to:

  • Monitor and manage ICS, SCADA, and other OT systems remotely

  • Perform maintenance, updates, or troubleshooting without being on-site

  • Enable emergency intervention from anywhere

✅ Common technologies for remote access:

  • VPNs – Secure encrypted tunnels into OT networks

  • Jump servers / Bastion hosts – Controlled gateways between IT and OT

  • Remote Desktop (RDP/VNC) – Access to HMI or control workstations

  • OT-specific platforms – Purpose-built tools for safe industrial remote access

  • MFA / 2FA – Authentication to ensure only authorized users connect

⚠ Remote access increases convenience, but also creates potential entry points for attackers if not properly secured.

Organizations use remote access to:

1. Improve Efficiency

  • Engineers can diagnose and configure systems without traveling

  • Reduces downtime for routine maintenance

2. Support Vendor Access

  • Equipment vendors can update or troubleshoot systems remotely

  • Faster support without waiting for on-site technicians

3. Handle Emergencies

  • Teams can respond to incidents outside working hours

  • Quick intervention minimizes production impact

4. Lower Costs

  • Saves money on travel, labor, and incident response

  • Enables small OT teams to manage multiple sites

5. Enable Remote Operations

  • Operators can control or monitor sites across large geographic areas

  • Ideal for distributed infrastructure like pipelines, wind farms, or utilities

While powerful, remote access brings serious cybersecurity risks to industrial environments:

⚠ Top Risks Include:

  1. Unauthorized Access

    • Stolen or reused credentials can give attackers access

    • Weak or shared authentication increases exposure

  2. Vulnerable Technologies

    • VPNs, RDP, and web tools may have unpatched flaws

    • Attackers exploit them to gain a foothold in OT

  3. Lateral Movement

    • Once inside, attackers move from one device to another

    • Can lead to control over critical operations

  4. Human Error

    • Remote staff may misconfigure systems

    • Vendors might introduce malware accidentally

  5. Malware and Ransomware

    • Remote sessions can be used to inject malicious code

    • Poor segmentation allows malware to cross into OT from IT

  6. Regulatory and Safety Violations

    • Unauthorized changes can impact safety and compliance

    • Could trigger penalties, outages, or safety incidents


✅ Conclusion: Remote access brings flexibility, but also risk. Implementing strong authentication, network segmentation, monitoring, and vendor controls is essential to stay secure.

Share

Fill out the form and get it by email

The post Rethinking Secure Remote Access for Industrial and OT Networks appeared first on Waterfall Security Solutions.

]]>
Selecting OT “Secure” Remote Access Solutions – Options, Criteria & Examples https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/selecting-ot-secure-remote-access-solutions-options-criteria-examples/ Mon, 14 Apr 2025 08:36:27 +0000 https://waterfall-security.com/?p=32424 Which OT remote access solution is right for you? It depends on the sensitivity of your OT/physical process, on your risk tolerance, and on your assessment of credible threats.

The post Selecting OT “Secure” Remote Access Solutions – Options, Criteria & Examples appeared first on Waterfall Security Solutions.

]]>

Selecting OT “Secure” Remote Access Solutions – Options, Criteria & Examples

Which OT remote access solution is right for you?
Picture of Andrew Ginter

Andrew Ginter

secure remote access

Which OT remote access solution is right for you? It depends on the sensitivity of your OT/physical process, on your risk tolerance, and on your assessment of credible threats. In Waterfall’s upcoming webinar, we look at the landscape of available OT remote access solutions, how they compare risk-wise, and what a decision tree for choosing between the alternatives looks like.

One core assumption: we are trying to prevent cyber attacks pivoting from the Internet (possibly via intervening IT and other networks) into sensitive OT networks and sabotaging physical operations

remote access solutions comparison table

In our webinar on April 21st, we look at different types of systems:

  • 2FA, DMZ, VPN, Jhost, NGFW – this is a conventional IT/OT remote access system, such as the system described as the minimum acceptable for NERC CIP Medium Impact sites, including (more or less) two-factor authentication, a demilitarized zone “network between networks,” a virtual private network, a jump host, and a next-gen firewall.

  • OT SRA – is a typical OT “secure” remote access solution that works roughly like Microsoft Teams – there is a client in the OT network and it reaches out through an IT/OT firewall to connect to remote laptops and other clients, either by contacting those clients directly or by reaching into a cloud service or other server to rendezvous with clients.
  • Timed switch – a timed hardware switch that temporarily connects / disconnects a conventional type (1) or (2) software-based remote access solution to an IT network or the Internet. The timed switch is normally in a disconnected state and enables temporary remote connectivity infrequently.

  • Hardware-Enforced Remote Access – Waterfall’s HERA, which consists of cooperating inbound and outbound gateways designed to prevent attacks pivoting from the Internet into OT systems.

  • Unidirectional remote screen view technology – tech that lets the remote user “look but not touch” and requires an engineer or other human operator in the protected OT network to cooperate with the remote expert providing remote support.

Features & Characteristics of Remote Access Solutions

To compare risks in these solutions, we look at a number of features & characteristics:

  • High connectivity – CISA and other authorities recently requested that high-consequence sites stop using VPNs for remote access, in large part because VPNs very often provide more connectivity into IT and OT networks than is needed and is wise.

  • Dangerous features – many “secure” remote access solutions have a myriad of features including dangerous ones such as file transfers (of potentially malicious files) and clipboard cut-and-paste operations (of potentially large attack scripts).
  • Firewalled – most “secure” remote access solutions demand a firewall at the IT/OT interface. Firewalls have a role inside OT networks and inside IT networks but are often not strong enough to defend a consequence boundary – when OT and IT networks have dramatically different worst-case consequences of compromise.

  • Server pivot – most “secure” remote access solutions have fairly constant IP addresses. They are in a sense “sitting ducks” for any adversary who cares to test them, any time that adversary cares to test them – for zero days, for unpatched known vulnerabilities, for misconfigurations and so on. And once these remote access servers are compromised, the attacker can pivot through the compromised remote access equipment, using the compromised equipment to attack more valuable assets deeper into the OT network.
  • Client pivot – most remote access solutions can be mis-used by attackers if he remote workstation or laptop is taken over. Two-factor authentication makes this harder, but not impossible, since 2FA is also software with vulnerabilities, both known and zero-day. Attackers thus are able to pivot through a compromised remote endpoint into the protected OT network.

  • Constant exposure – most remote access solutions are “always on” – constantly exposed to attacks from compromised external networks, such as IT networks and the Internet.
  • Personnel – most remote access solutions are designed for unattended operation, meaning that no OT personnel need be present at or internally connected to remote sites, such as substations, pump stations, lift stations, compressor stations or other remote installations. Attended operation systems that work only if there are local personnel present to help them along tend to be more secure, but those personnel are not always available.

How do we use these characteristics to choose between the options?

Well, we need to understand our needs and especially the criticality of our physical operations. A key question: what is the worst consequence possible due to a credible attack scenario? The question has three key parts:

  • Worst possible consequence – what is the worst that can happen if compromised computers either fail to function correctly, or more often are deliberately made to function maliciously. And beware – many risk programs have blind spots, such as bricked control equipment. What happens if the bad guys get in and load dummy firmware into most of our 10-year-old PLCs, damaging them so thoroughly that it is now impossible to reload them with correct firmware? Where do we get spares to replace these components when the manufacturer no longer produces this equipment?
  • Credible attacks – in the spectrum of possible attacks (see Waterfall’s report on the Top 20 Cyber Attacks on Industrial Control Systems), which attack scenarios and consequences do we deem credible threats, given the defenses we have already deployed and the remote access systems we are considering, and which consequences and attacks do we not believe will be realized in our network or in any similar networks, any time soon?
  • Acceptable consequences – which credible consequences, due to credible attacks on our systems, do we deem acceptable vs. unacceptable?

All this and more, in greater detail, with industry-specific examples, is coming up in our Apr 21 webinar ‘Building a Game Plan for OT Remote Access‘. 

I hope you can join us.

About the author
Picture of Andrew Ginter

Andrew Ginter

Andrew Ginter is the most widely-read author in the industrial security space, with over 35,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.

FAQs About Remote Access Solutions

2FA, DMZ, VPN, Jhost, NGFW – this is a conventional IT/OT remote access system, such as the system described as the minimum acceptable for NERC CIP Medium Impact sites.
Another type is OT SRA, which is a typical OT “secure” remote access solution that works roughly like Microsoft Teams.
Timed switch – a timed hardware switch that temporarily connects / disconnects a conventional type (1) or (2) software-based remote access solution to an IT network or the Internet. 
Hardware-Enforced Remote Access, like Waterfall’s HERA, which consists of cooperating inbound and outbound gateways designed to prevent attacks pivoting from the Internet into OT systems.
And finally, unidirectional remote screen view technology which lets the remote user “look but not touch” and requires an engineer or other human operator in the protected OT network to cooperate with the remote expert providing remote support.

The main features and characteristics of a remote access solution are the degree of connectivity, the location of firewalls, server & client pivots, exposure time to potential attacks, and the personnel required to operate them.

To know which remote access solution to choose, we first need to understand our needs and especially the criticality of our physical operations. A key question to answer is: what is the worst consequence possible due to a credible attack scenario? Once we understand what is at stake, we will have a better understanding of how to choose the solution that prevents this scenario from occuring.

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Selecting OT “Secure” Remote Access Solutions – Options, Criteria & Examples appeared first on Waterfall Security Solutions.

]]>
Building a Game Plan for OT Remote Access https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/building-a-game-plan-for-ot-remote-access/ Mon, 17 Mar 2025 09:39:41 +0000 https://waterfall-security.com/?p=31658 OT remote access is seen as essential for many industries, but there are a variety of OT solutions out there. Watch the webinar as we help you make the right decision for your OT network.

The post Building a Game Plan for OT Remote Access appeared first on Waterfall Security Solutions.

]]>

Building a Game Plan for OT Remote Access

Watch the webinar where we’ll provide an overview of the current landscape of OT remote access solutions and help you make the right decision for your OT network.

OT remote access is seen as essential for many industries – partly to save costs, and partly because physical travel to very distant substations, compressor stations, mine sites, and other physical assets is difficult, time-consuming, and sometimes even dangerous. 

The problem is that there is a bewildering variety of OT remote access solutions out there, with different kinds of needs in different kinds of industries and use cases.

In this webinar Andrew Ginter takes us through:

  • Provide an overview of the current landscape of solutions and needs.

  • Recommend a decision process – how to gather critical information, the steps required to make informed decisions in a specific order.

  • Provide examples of the decision process across various industries and contexts – from municipal utilities to backbone / heavy infrastructure to manufacturing and building automation.

Watch the webinar as we "fly low and fast" - in 60 minutes see all the options in one place, and where and why each one makes sense, with concrete examples.

Picture of Andrew Ginter

Andrew Ginter

Andrew Ginter is the most widely-read author in the industrial security space, with over 35,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.
Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Building a Game Plan for OT Remote Access appeared first on Waterfall Security Solutions.

]]>
Secure Remote Access for Critical Infrastructure: What’s at Stake? https://waterfall-security.com/ot-insights-center/ot-cybersecurity-insights-center/secure-remote-access-for-critical-infrastructure-whats-at-stake/ Tue, 31 Dec 2024 07:34:04 +0000 https://waterfall-security.com/?p=30134 One of the most significant vulnerabilities when it comes to OT security for critical infrastructure are the risks posed by the use of remote access into OT.

The post Secure Remote Access for Critical Infrastructure: What’s at Stake? appeared first on Waterfall Security Solutions.

]]>

Secure Remote Access for Critical Infrastructure: What’s at Stake?

OT Remote Access needs to be far more secure than IT remote access. There is a good reason why.
Picture of Waterfall team

Waterfall team

OT Remote Access with OT security in mind

In our hyper-connected world, critical infrastructure—power plants, water systems, transportation networks, airports, seaports, and anything else that can’t simply be “turned off”—is the backbone of modern society. These systems provide essential services that underpin daily life and economic stability. However, as these infrastructures become increasingly digitized and interconnected, the challenge of securing them from cyber threats becomes ever more important. 

One of the most significant vulnerabilities when it comes to OT security for critical infrastructure are the risks posed by the use of remote access into OT. While remote access is essential for operational efficiency and emergency response, it also opens doors for potential cyberattacks. Understanding what’s at stake and how to address these challenges is vital for understanding what is required when it comes to securing critical infrastructure. 

Critical infrastructure is a juicy target for cybercriminals [and] nation-state actors…

The High Stakes of Critical Infrastructure

Industrial secure remote access for OT such as this industrial operation.Critical infrastructure is a juicy target for cybercriminals, nation-state actors, and hacktivists. A successful breach can lead to: 

Widespread Disruption: An attack on the power grid could result in prolonged blackouts, affecting millions. Similarly, a breach in water systems could disrupt supply or even compromise water safety. 

Economic Impact: Downtime in transportation networks or energy systems can cost billions in lost productivity and revenue. 

Public Safety Risks: Malicious actors could manipulate transportation systems, potentially causing accidents, or disrupt healthcare facilities reliant on stable power. 

National Security Threats: Infiltration of critical systems can serve as a precursor to broader attacks during geopolitical conflicts. 

You get the picture. Critical infrastructures are heavily cyber-targeted. And at the same time the option of “turning it off” is not a good option, and if it does go off, it must come back on as a top priority.

Challenges in Securing Remote Access

Securing remote access to critical infrastructure is uniquely challenging due to several factors: 

So much legacy still operationalSo Many Legacy Systems: Many critical infrastructure systems run on legacy technology designed decades ago. Back then they didn’t build with cybersecurity in mind. Retrofitting or replacing these systems with modern security measures is overly complex and not cheap. 

The OT vs IT Standoff: OT environments prioritize availability and safety, while IT focuses on data confidentiality and integrity. Bridging this cultural and technological gap is a persistent challenge across many critical industries. Large strides have been made on this issue with Cyber-informed Engineering (CIE). One interesting facet about CIE, which was originally championed by the Idaho National Laboratory, is that it presents new solutions to cyber security problems that don’t need to exist in the first place.
Get a complimentary copy of Andrew Ginter’s new book on this topic >>

Far and Away: Critical infrastructure often spans vast and distant areas, requiring remote access for maintenance and monitoring. This reliance on remote connectivity increases the attack surface if not done in a way that deterministically keeps away remote threats.

Cloudy with a chance of Third-Party Access: Vendors and contractors often require remote access for system updates and repairs. Sometimes that access is even required as part of warranty agreements. Many of the more recent analytical services require connecting critical machinery to the cloud. This external access poses a significant attack surface. 

Advancing Advanced Threats: Attackers targeting critical infrastructure are often highly skilled and well-funded, employing sophisticated methods such as supply chain attacks and zero-day vulnerabilities. They seem to be growing as governments are able to build-up and develop their cyber capabilities.

Hardware Enforcements for Secure Remote Access

Despite all these challenges and evolving threats, Waterfall has several solutions to all these problems:

HERA – Hardware Enforced Remote Access. HERA uses hardware to enforce the remote access. Software can be hacked from afar, but hardware can only be modified when you are standing right next to it. This is how HERA provides secure OT remote access:

OT secure remote access laptop woman's handsOne-way remote screen connection: HERA’s outbound connection that shows the remote screen is independent of the inbound connection. The remote screen is duplicated using a one-way fiber-optic cable and then that duplicate is viewed remotely. The hardware required for sending information back through this connection is physically missing, denying such a possibility to cyberattackers.

One-way connection for mouse and keyboard: HERA’s inbound connection also flows in only one direction, from a dedicated laptop using the ███████ protocol, and only transmitting mouse movements and keyboard strokes. No files or images can be uploaded over this connection. No information from this connection can flow back into the laptop, only outbound, and only mouse moves and keys.

There are no TCP/IP packets crossing the IT/OT boundary. If you’d like clarification regarding this technical point, we encourage you to speak to one of our OT remote access specialist that can fully explain how it works Contact us >>

Additional hardware measures for additional security: Additional security measures are in place on the embedded hardware of the laptop, such as Intel’s TPM, while the keystrokes and mouse moves are encrypted.

The Strictly Unidirectional Option: For certain systems and machinery, a Unidirectional Security Gateways will suffice, without the need for full remote access. The machinery’s OT data is duplicated onto a server which is then accessed remotely. The data going to the duplicate server is constantly updated in real-time using a unidirectional connection. This way it can be updated immediately, yet not a line of code can ever make it back onto the machinery’s systems. If occasional changes need to be made remotely, the remote user can phone someone physically near the machinery and have them make the required adjustments.

Waterfall Blackbox
Waterfall Tamperproof Blackbox

Tamper-proof Logs: While unidirectional technology is able to neutralize remote threats, there still persists the risk from insiders as well as embedded threats -threats that might come from foreign-made machinery that has a “backdoor” embedded into the technology, such as ship-to-shore cranes. Cyberattacks that make use of such sophisticated attacks are known for “covering their tracks” and erasing event logs of their actions. By maintaining a tamper-proof copy of the logs, if any breach is ever suspected, the logs can be compared for any discrepancies so that whatever was deleted is quickly found. This usually also helps narrow down what the attackers were after.

Let’s Not Forget Compliance and Regulations

Unidirectional technology and hardware enforced OT remote access also boast strong regulatory compliance. This includes adherence to IEC 62443, NIS2, NERC CIP, and many more, including recommended best practices such as connecting OT to AWS (Amazon Web Services).

So, in Conclusion

The stakes for securing remote access to critical infrastructure could not be higher. Disruptions to power, water, or transportation systems can ripple across societies, causing economic turmoil, public safety crises, and national security vulnerabilities. While the challenges in securing remote access for OT are complex, a deterministic approach that combines hardware enforcement with advanced software can neutralize these risks, safeguard these vital systems, and all while adhering to strict regulatory requirements.

In this digital age…the question is not if we can afford to invest in secure remote access but if we can afford not to.

In this digital age, ensuring the security of critical infrastructure is not just an operational necessity—it is a strategic imperative. The question is not if we can afford to invest in secure remote access but if we can afford not to.

 

Want more details about Waterfalls secure remote access solutions?
Speak to an ot remote access expert >>

About the author
Picture of Waterfall team

Waterfall team

Share

Stay up to date

Subscribe to our blog and receive insights straight to your inbox

The post Secure Remote Access for Critical Infrastructure: What’s at Stake? appeared first on Waterfall Security Solutions.

]]>