Direct answer
Do not expose a machine PLC or HMI directly to the internet. Use the site’s approved OT remote-access architecture with strong authentication, individual accounts, least privilege, session logging, controlled vendor access and a method for the site to enable and revoke connections.
Why this matters
Remote support can reduce diagnostic time, but unmanaged modems, shared passwords or persistent vendor tunnels create operational technology risk and unclear responsibility.
Decision table
| Control | Purpose | Project question |
|---|---|---|
| Approved gateway | Avoid direct device exposure | Who owns and patches it? |
| MFA and named users | Protect human access | How are accounts approved and removed? |
| Least privilege | Limit reachable assets and actions | What must the supplier access? |
| Session control | Time limit, approval and logging | Who enables each session? |
| Recovery | Backups and tested restore | What if a change fails? |
Information to collect
- Identify every remote connection and support device.
- Confirm the site OT policy before quotation.
- Remove default and shared credentials.
- Define supplier identity and authorisation.
- Record software, firmware and configuration backups.
- Test access removal and communication-loss behaviour.
Practical method
- 1
Use a site-managed secure gateway.
- 2
Require MFA for human remote access.
- 3
Restrict routes and permissions to the support need.
- 4
Approve and log sessions.
- 5
Review access after personnel, supplier or equipment changes.
Common mistakes to avoid
- Using port forwarding to a PLC or HMI.
- Leaving permanent supplier credentials active.
- Sharing one account between technicians.
- Allowing remote changes without backup or approval.
- Assuming a cellular router is secure by default.
Questions people also ask
Should a supplier have permanent access?
Use the site risk and support model; many sites require access to be disabled until a named support session is approved.
Is a VPN enough?
A VPN is only one control; identity, least privilege, logging, patching and network segmentation still matter.
Should remote sessions be recorded?
Retain appropriate connection and change records according to the site policy and risk.
Can remote access be added after installation?
Yes, but architecture, ownership, support and cyber-risk requirements should be assessed before connecting it.
Official and primary sources
These references support the regulated, standards-led or security points in this guide. Check the current source before making a project decision.
Continue from the requirement to the equipment
Use the specialist route that matches the product, pack and process. Final suitability requires representative samples, output targets and site information.