Controls, data and cyber security

Secure Remote Access for Packaging Machinery

Plan supplier remote support using approved connectivity, strong authentication, named accounts, least privilege, logging, time limits and site-controlled enablement.

Updated 1 September 2026Evidence-led production guidance7–10 minute read

Direct answer

Do not expose a machine PLC or HMI directly to the internet. Use the site’s approved OT remote-access architecture with strong authentication, individual accounts, least privilege, session logging, controlled vendor access and a method for the site to enable and revoke connections.

Why this matters

Remote support can reduce diagnostic time, but unmanaged modems, shared passwords or persistent vendor tunnels create operational technology risk and unclear responsibility.

Decision table

ControlPurposeProject question
Approved gatewayAvoid direct device exposureWho owns and patches it?
MFA and named usersProtect human accessHow are accounts approved and removed?
Least privilegeLimit reachable assets and actionsWhat must the supplier access?
Session controlTime limit, approval and loggingWho enables each session?
RecoveryBackups and tested restoreWhat if a change fails?

Information to collect

  • Identify every remote connection and support device.
  • Confirm the site OT policy before quotation.
  • Remove default and shared credentials.
  • Define supplier identity and authorisation.
  • Record software, firmware and configuration backups.
  • Test access removal and communication-loss behaviour.

Practical method

  1. 1

    Use a site-managed secure gateway.

  2. 2

    Require MFA for human remote access.

  3. 3

    Restrict routes and permissions to the support need.

  4. 4

    Approve and log sessions.

  5. 5

    Review access after personnel, supplier or equipment changes.

Common mistakes to avoid

  • Using port forwarding to a PLC or HMI.
  • Leaving permanent supplier credentials active.
  • Sharing one account between technicians.
  • Allowing remote changes without backup or approval.
  • Assuming a cellular router is secure by default.

Questions people also ask

Should a supplier have permanent access?

Use the site risk and support model; many sites require access to be disabled until a named support session is approved.

Is a VPN enough?

A VPN is only one control; identity, least privilege, logging, patching and network segmentation still matter.

Should remote sessions be recorded?

Retain appropriate connection and change records according to the site policy and risk.

Can remote access be added after installation?

Yes, but architecture, ownership, support and cyber-risk requirements should be assessed before connecting it.

Official and primary sources

These references support the regulated, standards-led or security points in this guide. Check the current source before making a project decision.

Relevant machinery routes

Continue from the requirement to the equipment

Use the specialist route that matches the product, pack and process. Final suitability requires representative samples, output targets and site information.

Ask a production question