Data as of Aug 25, 2026 · Based on 347 AI responses from ChatGPT Search and Google AI Mode · See how Parse measures this
For secure remote access to OT and industrial networks, select a tool based on your specific requirements: Beyondtrust is best for privileged user and vendor access management;
Claroty and
Dispel lead in OT-specific security and compliance; and companies like and provide specialized connectivity for legacy or field-based maintenance.
Brands AI recommends here
Best for controlling third-party and privileged user access. It offers fine-grained permission setting, full session recording, and time-bound access, making it ideal for strict operational security requirements.
Best for industrial maintenance teams needing easy-to-deploy access for field engineers. Its industrial-grade gateway is designed specifically for remote equipment support and maintenance workflows.
Best for secure OT remote access that avoids the risks of traditional VPNs. Its architecture is built specifically for OT environments, focusing on reducing attack surface and improving visibility.
The gold-standard approach for securing industrial control systems (ICS) and operational technology (OT) networks is a Zero Trust Network Access (ZTNA) architecture combined with a DMZ-hosted jump server (or bastion host) and strict multi-factor authentication (MFA).
Legacy methods like direct Virtual Private Networks (VPNs) flatly connect an external user straight to the internal network, creating lateral movement risks if credentials are compromised. Modern OT security shifts away from this perimeter-only defense.
Key Components of a Secure OT Remote Access Solution
Comparison of Remote Access Strategies
| Strategy | Security Level | Implementation Complexity | Best Use Case |
|---|---|---|---|
| ZTNA + Jump Host | Highest | Moderate to High | Modernizing high-risk or critical infrastructure OT networks |
| DMZ Jump Server + VPN | High | Moderate | Standard industrial plants with legacy vendor support needs |
| Direct VPN to OT | Low / High Risk | Low | Not recommended due to lateral movement vulnerabilities |
For official guidelines and risk evaluations tailored to critical infrastructure, consult the CISA Industrial Control Systems Cybersecurity Guidance.
If you'd like to narrow this down, please let me know:
For most industrial environments, the best approach is not a traditional “VPN straight into the OT network.” I’d recommend a brokered, least-privilege remote-access architecture with a hardened OT jump host, MFA, strong segmentation, and just-in-time access.
Remote user/vendor → MFA + access broker → IT/OT DMZ → hardened jump server → specific OT asset
Key controls:
CISA's OT remote-access guidance recommends VPN technology for standardized external access and specifically describes using a secured administrative “jump” server. CISA NIST SP 800-82 Rev. 3 likewise emphasizes designing OT security around the unique reliability, performance, and safety requirements of the environment.
| Approach | Recommendation | Why |
|---|---|---|
| Direct RDP/SSH to OT | ❌ Avoid | Excessive exposure |
| Port-forwarding/NAT to PLC/HMI | ❌ Avoid | Poor segmentation and accountability |
| Traditional VPN into entire OT subnet | ⚠️ Better than direct access | Can provide too much network reach |
| VPN → OT DMZ → jump server | ✅ Good | Stronger segmentation and control |
| ZTNA/access broker → OT DMZ → jump server → specific asset | 🏆 Best overall | Fine-grained, identity-based access |
| Physically isolated/no remote access | 🏆 Strongest isolation | Best for exceptionally safety-critical environments, but operationally restrictive |
There is an important nuance: Zero Trust Network Access (ZTNA) isn't automatically safer just because it's called Zero Trust. The implementation needs to preserve OT segmentation and account for legacy equipment that cannot support modern authentication. CISA's recent guidance notes the risks associated with vulnerable/misconfigured VPN deployments and recommends moving toward more granular, least-privilege access where appropriate.
My default recommendation:
Identity-aware ZTNA/broker + MFA + OT DMZ + hardened jump host + per-asset authorization + just-in-time vendor access + session monitoring/recording. For a real deployment, I'd design it around NIST SP 800-82r3 and your Purdue/ISA-95 network zones rather than selecting a product first. NIST's OT guidance remains the key reference, with a Rev. 4 draft also now in development.
If you tell me whether this is manufacturing, power, water, oil & gas, etc., and whether remote users are employees, vendors, or both, I can give you a concrete reference architecture and shortlist the best commercial solutions.
If you mean “what architecture should we choose for secure remote access into an ICS/OT environment?”, my recommendation is:
For most industrial environments, the strongest design is not simply “put a VPN on the OT firewall.” I would use a layered architecture:
Remote user/vendor → MFA + device verification → Zero Trust/secure access gateway → OT DMZ → hardened jump/bastion host → tightly allow-listed OT assets
The key is that the remote user doesn't receive broad network-level access to the OT network. Access is granted to specific systems/applications for a limited period and is logged/controlled.
This aligns particularly well with the latest joint U.S. government OT guidance. In April 2026, CISA, FBI, DOE and other agencies recommended applying Zero Trust principles to OT; their guidance specifically recommends hardened jump hosts in the OT DMZ as the sole entry point, with MFA, continuous monitoring, auditing and time-based access controls.
| Approach | OT security | Best use |
|---|---|---|
| OT-specific ZTNA + jump host | ⭐⭐⭐⭐⭐ | Preferred architecture |
| Hardened VPN + jump host | ⭐⭐⭐⭐½ | Excellent, especially for existing infrastructure |
| VPN directly into OT network | ⭐⭐⭐ | Transitional/legacy environments |
| RDP/SSH exposed to Internet | ⭐ | Avoid |
| Vendor remote-access software directly to PLC/HMI | ⭐ | Avoid unless tightly controlled |
A jump/bastion host creates a controlled choke point between remote users and the control environment. CISA's current OT guidance explicitly recommends placing hardened jump hosts in the OT DMZ and using them as the sole remote-access entry point.
Ideally, the jump solution provides:
I wouldn't automatically eliminate VPNs. NIST's OT guidance recognizes VPNs as an appropriate mechanism for secure remote access when properly implemented, and CISA has recommended modern VPNs with strong authentication and encryption.
The important distinction is:
Good:
User → MFA VPN/ZTNA → OT DMZ → Jump Host → Specific OT asset
Riskier:
User → VPN → entire OT network
CISA/NSA specifically recommend segmentation, DMZs, firewalls and jump servers, along with VPN encryption and MFA when remote access is necessary.
If you're starting from scratch, I'd evaluate OT-focused remote-access platforms that combine ZTNA/PAM capabilities with a hardened jump host, rather than buying a generic enterprise VPN and putting it in front of the control network.
For an existing plant where you already have a mature VPN infrastructure, a hardened VPN → OT DMZ → jump server architecture can be an excellent and potentially simpler solution.
One important caveat: OT safety and availability take precedence over blindly applying IT Zero Trust controls. NIST emphasizes that OT security needs to account for performance, reliability and safety requirements.
Bottom line:
Use Zero Trust principles for identity and authorization, a hardened OT DMZ/jump host as the access choke point, MFA, least privilege, just-in-time access, strong segmentation, and comprehensive session logging. Use VPN as the secure transport where appropriate—not as the authorization boundary itself.
If you're evaluating specific products/vendors (e.g., Claroty, OPSWAT, Nozomi, Tenable, BeyondTrust, CyberArk, Zscaler, Palo Alto, Fortinet, etc.), I can do a current 2026 comparison specifically for ICS/OT remote vendor access and rank them by security, architecture, ease of deployment, and cost.
There is no single "silver bullet" product that fits every industrial environment, but the undisputed industry consensus—reflected in frameworks like the Purdue Model and analyst guidance from Gartner’s Market Guide for Cyber-Physical Systems (CPS) Secure Remote Access —is a move away from legacy, flat-network VPNs toward Zero Trust, protocol-aware, and privileged-access platforms.
Traditional VPNs grant too much lateral network access once a user is authenticated. For an ICS/OT network, the "best" solution is a Dedicated OT/CPS Secure Remote Access (SRA) or Privileged Remote Access (PRA) platform that enforces strict least-privilege boundaries.
Top-Tier Solutions by Category
Industry leaders and representative vendors in the OT/ICS secure remote access space are typically categorized by their core strengths:
Core Requirements for a "Best-in-Class" OT Remote Access Setup
No matter which vendor you evaluate, a true industrial-grade remote access solution must meet these non-negotiable criteria:
To help narrow down the best specific fit, tell me a bit more about your environment:
The "best" solution for secure remote access to an industrial control system (ICS) or operational technology (OT) network isn't a single commercial product, but rather an architectural approach: Zero Trust Network Access (ZTNA) combined with a hardened, brokered gateway or jump host model.
Traditional legacy Virtual Private Networks (VPNs) grant broad, network-level access once authenticated, allowing a compromised vendor laptop to move laterally across the plant floor. Modern industrial frameworks reject this "castle-and-moat" design.
The Gold-Standard Architecture: ZTNA + Brokered Access
Instead of extending the corporate network or the internet directly to a PLC, RTU, or HMI, the connection follows a strict protocol:
Leading Solutions by Operational Focus
To help narrow down which specific vendor or deployment model fits your plant, tell me:
For most industrial environments, I would not make a traditional VPN directly into the ICS/OT network the primary solution. The strongest architecture is a hardened OT jump host / bastion gateway in an OT DMZ, combined with MFA, least-privilege access, device/user verification, time-limited authorization, session monitoring/recording, and strict network segmentation.
This aligns particularly well with recent CISA guidance: its 2026 OT zero-trust guidance specifically recommends hardened jump hosts as the sole entry point for remote access to legacy OT networks, with MFA, continuous monitoring, session recording, auditing, and time-based controls.
Remote Engineer / Vendor
|
MFA + SSO/IdP
|
Zero-Trust Access
Gateway
|
Firewall / ACL
|
OT DMZ
|
Hardened Jump Host
(session recording)
|
Firewall / ACL
|
ICS / OT Zone
┌────┴─────┐
| |
HMI Engineering
Workstation
| |
PLCs / RTUs / DCS / SCADA
| Capability | Recommendation |
|---|---|
| Network architecture | OT DMZ + dedicated jump host/bastion |
| Authentication | MFA, preferably phishing-resistant MFA |
| Authorization | RBAC + least privilege + just-in-time/time-limited access |
| Vendor access | Separate accounts, approval workflow, no shared credentials |
| Remote protocol | RDP/SSH/HTTPS through the controlled gateway, not directly to PLCs/HMIs |
| Session security | Full session recording and command/activity logging |
| Network controls | Allow-list specific destinations, ports and protocols |
| Endpoint controls | Managed/verified devices; ideally dedicated admin workstations |
| Monitoring | OT-aware IDS/NDR + centralized logging/SIEM |
| Emergency access | Break-glass account with strong controls and extensive auditing |
| Internet exposure | Never expose PLCs, HMIs, engineering stations or OT protocols directly to the Internet |
NIST's OT security guidance recognizes VPNs as a valid technology for secure remote access, but also warns that remote technologies can become an attack channel if they aren't properly managed. NIST Publications NIST Computer Security Resource Center CISA similarly recommends segmentation and jump hosts, and notes that a VPN is only as secure as the devices connected through it.
I'd rank the approaches roughly like this:
CISA's broader network-access guidance also cautions that traditional VPNs can create significant risk through vulnerabilities, misconfiguration, and excessive network access, and recommends stronger approaches incorporating zero trust and granular access controls.
I wouldn't simply buy a generic "zero-trust product" and connect it to the plant. OT has availability and safety requirements that IT environments don't, so the solution needs to be deployed around the existing Purdue/zone-and-conduit architecture, with changes tested carefully. NIST explicitly emphasizes these OT-specific reliability, performance, and safety requirements.
Bottom line: If I were designing this today, I'd choose an OT-aware privileged remote-access/bastion platform in an OT DMZ, backed by MFA + ZTNA/identity controls + just-in-time access + session recording + allow-listed conduits + continuous monitoring. A VPN can be part of that architecture, but I would not treat the VPN itself as the security boundary for the ICS network.
If you're evaluating actual products (e.g., Fortinet, Palo Alto, Zscaler, Claroty, Nozomi, Armis, OPSWAT, BeyondTrust, CyberArk, TXOne, or Siemens) I can also compare them specifically for ICS/SCADA remote vendor access, including architecture, security controls, pros/cons, and approximate deployment complexity.
Securing remote access to Industrial Control Systems (ICS) and Operational Technology (OT) networks requires a strategy that balances strict security with operational uptime. Traditional methods like legacy VPNs are increasingly seen as high-risk because they provide flat network access once authenticated, making them prime targets for lateral movement during a cyberattack.
The gold standard for ICS/OT remote access is Zero Trust Network Access (ZTNA) purpose-built or configured for OT , combined with a secure jump host / Bastion Host architecture equipped with multi-factor authentication (MFA) and session recording.
Top Solutions and Architectures
Key Features to Prioritize
If you'd like to narrow this down, tell me:
For most industrial environments, the best architecture is not a single remote-access product. It is a brokered, zero-trust-style remote-access architecture built around a hardened jump server/bastion host, MFA, least privilege, segmentation, and session monitoring.
NIST specifically recommends MFA as a best practice for remote access to OT, while CISA emphasizes controlled remote access, strong authentication, limiting access to when it is required, and logging/monitoring. CISA also notes that no single remote-access solution is sufficient by itself; defense in depth is required.
Remote Engineer / Vendor
│
▼
MFA + Device Validation
│
▼
Remote Access Gateway
/ Zero-Trust Broker
│
▼
OT DMZ / Jump Server
│
Firewall / ACL
│
▼
OT Management Zone
│
▼
HMI / Engineering Workstation
│
▼
ICS / PLCs
Key controls:
This aligns well with NIST's OT security guidance and its zero-trust model, which removes implicit trust based on network location and requires authentication/authorization before resource access.
| Approach | Recommendation | Why |
|---|---|---|
| Direct RDP/SSH from Internet | ❌ Avoid | Excessive attack surface |
| Port-forwarded VPN directly into OT | ⚠️ Better, but insufficient | Network access can become too broad |
| Traditional VPN → OT jump server | Good | Mature, controllable architecture |
| ZTNA/broker → OT DMZ jump server → ICS | ⭐ Best for most new deployments | Strong identity, least privilege, segmentation |
| Vendor remote-access appliance/service | Good when properly isolated | Useful for third-party maintenance |
| Remote desktop gateway with MFA + session recording | Excellent for engineering access | Limits direct access to OT assets |
The important distinction is that ZTNA should not mean putting an agent on every PLC or blindly applying an IT-style zero-trust product to the control network. Legacy OT equipment often cannot support modern authentication, agents, or frequent security changes. NIST explicitly recognizes these OT constraints.
My default recommendation:
MFA-protected remote-access gateway → OT DMZ → hardened jump server/engineering workstation → tightly filtered firewall connection to the required OT assets, with JIT access, session logging, and continuous monitoring.
If you tell me whether your environment is manufacturing, power, water, oil & gas, etc., and whether remote access is primarily for employees, vendors, or both, I can recommend a specific architecture and compare products such as Palo Alto, Fortinet, Zscaler, BeyondTrust, CyberArk, Claroty, and Nozomi.
Providing secure remote access to Industrial Control Systems (ICS) and Operational Technology (OT) networks requires a strategy that balances strict security with operational uptime. Traditional IT virtual private networks (VPNs) are no longer considered best practice because they grant broad network-level access once authenticated, exposing critical OT assets to lateral movement if credentials are compromised.
The consensus best solution for secure OT remote access is a Zero Trust Network Access (ZTNA) architecture tailored for OT , combined with specific hardware-enforced boundaries.
Top Solutions and Architectures
Key Features of the Best Solution
If you'd like to narrow this down, tell me:
I can recommend a specific architectural approach or vendor shortlist for your environment.
For most industrial environments, the best approach is a purpose-built, brokered OT remote-access architecture—not a traditional VPN directly into the control network.
NIST recommends separating OT from corporate networks and minimizing the connections between them; CISA likewise emphasizes that remote access can introduce significant risk to control systems.
Remote user/vendor → MFA + access broker/jump server → OT DMZ → OT jump host → specific ICS asset
The key controls should be:
OT network segmentation
Privileged access management (PAM)
Jump server / remote-access gateway
Just-in-time access
Application/protocol-level control
Full monitoring and logging
Vendor access through the same controlled mechanism
| Approach | Security | OT suitability |
|---|---|---|
| Direct Internet → PLC/HMI | ❌ Very poor | Avoid |
| Port forwarding/RDP directly into OT | ❌ Poor | Avoid |
| Permanent VPN into OT VLAN | ⚠️ Moderate/poor | Generally avoid |
| VPN → OT DMZ → jump host | ✅ Good | Good |
| ZTNA/PAM broker → OT DMZ → jump host → specific asset | ⭐⭐⭐⭐⭐ | Best general choice |
| Completely disconnected/break-glass access | ⭐⭐⭐⭐⭐ | Best where operationally feasible |
The important nuance is that “Zero Trust” by itself isn't the solution. For OT, you want a solution designed around availability, safety, legacy protocols, and deterministic behavior. NIST's current OT guidance explicitly addresses these unique requirements.
My recommendation: implement an OT-specific remote access gateway/PAM platform in an OT DMZ, with MFA, just-in-time authorization, per-asset access controls, session recording, and centralized logging. Keep the actual PLC/DCS/SCADA network inaccessible directly from the Internet and preferably inaccessible directly from the corporate VPN.
NIST's OT security project currently lists SP 800-82 Rev. 3 as the final guidance and notes that Rev. 4 is in draft, so I'd use Rev. 3 as the current baseline while watching the Rev. 4 development.
If you tell me whether this is manufacturing, energy, water, oil & gas, etc., and whether you need employee access, vendor access, or both, I can narrow this down to the best architecture and specific products/vendors.