When the term “access control” is used in the industrial sector, the first thing that comes to mind is securing access to sites, buildings and factories. Industry has a physical security culture. From the moment you enter the perimeter of a site, building or factory, you are authorised to perform certain actions, because you are in a protected area. This is physical perimeter security: the security perimeter is the controlled space you are in. The same approach can be found on the IT side, with a network-based approach to security perimeters — once you have entered a network, you are authorised to perform a certain number of actions on the network’s resources.
With digital transformation, industrial environments are increasingly complemented by IT environments. And we can truly speak of a culture clash: the highly physical culture of industry is confronted with the logical culture of IT. What about access to industrial control system applications by the operators who need to manage them — updating and configuring applications — on the one hand, and use them on the other? In some factories, are there still not shared workstations with shared sessions, usable by any industrial operator in that area of the plant? How do we know which operator worked on which equipment? How can we ensure accountability, the ability to determine who did what, when and on which equipment? Can we impose authentication on the plant’s industrial employees every time they use these applications, with sophisticated password policies that sometimes lead to insecure behaviour in the name of productivity?
We can also understand this different mindset by looking at the nature of the industrial infrastructures used in these plants. In general there is a large number of equipment and control systems from different manufacturers, and therefore a high degree of heterogeneity, with technologies that are often specific to each manufacturer. That is not like an IT infrastructure, where you find different machines but with much less diversity and more standards: when we talk about administering an IT infrastructure, are we not talking about RDP access for Windows and SSH access for Linux, and a few other standards? Is it not easier to attack a single standard found in all information systems than a manufacturer’s proprietary technology deployed on a more limited basis? In general, proprietary implies secure — or at least less vulnerable, since fewer players are interested in it.
Finally, industrial control systems have generally been, and often still are, accessed exclusively from the plant’s internal network. This is also due to the nature of the protocols and networks used to drive machines and PLCs: we are a long way from the internet, the same network for everyone. However, with the development of ecosystems of manufacturers and service providers, with the consequences of crises such as Covid which forced teleworking where possible, with the growth of cloud processing power for the analysis of industrial data and the application of AI algorithms, and no doubt for other reasons, factories are opening up more and more. Remote access to industrial infrastructures is becoming a real issue.
In this context, even though IT and OT cultures and environments are very different, IT experience in securing access — beyond physical access control — can provide useful solutions. The heterogeneity of industrial solutions from different manufacturers is a real problem for efficiency and productivity: each manufacturer has its own authentication mode, which can be strengthened; its own way of tracing and logging events on its system; and its own format for those events. Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions, widely deployed in the IT world, all have their place in the industrial world. What can they offer here?
- A single access solution for all use cases, and therefore the same user experience when moving from one industrial manufacturer to another.
- Centralised access: security via a single point of access that can be strengthened with multi-factor authentication, identical whatever the system.
- Complete and detailed traceability, common to all manufacturers, so you know who did what on which equipment, system or application — in the form of audits or video recordings, with separate individual user accounts.
- Operators no longer using their own passwords to access systems. If they have to remember every password for every application, with different password policies from one manufacturer to another, they end up writing them down. This is where shared accounts come in.
- The guarantee of regular password changes on industrial systems, without the need for human intervention.
Industrial control system applications are often quite heavy and hosted on a dedicated workstation, by manufacturer for example. The protocols between these applications and the equipment are standard industrial protocols, but not traditional in the IT world: IT PAM solutions do not natively manage sessions in those protocols. Using PAM in industry does not necessarily mean providing direct access to PLCs or equipment over them — it is more a matter of tracking the use of the applications in industrial control systems. Here are some use cases.
A first example is to provide operators working on a particular manufacturer’s equipment with access to the engineering workstation hosting that manufacturer’s applications. Through the PAM, everything the operator does is tracked and recorded. Here, the manufacturer’s application sits on a workstation on the plant’s local industrial network, with the application access network on one side and the equipment and PLC access network on the other. The entire system — applications and equipment — is located in the company’s plant datacentre.
But sometimes the company needs to provide remote access to its industrial infrastructure, to its own employees or to service providers, sometimes starting with the manufacturers of the equipment it has deployed. Remote here means from another network: the workstations of its teleworkers or its ecosystem partners, from their own offices. Instead of having them come in, it can provide secure remote access. If the company has sufficient licences to allow third parties to access its industrial applications, it can give them remote privileged access to the workstation hosting those applications via the PAM solution — all the partner’s actions are then traced and recorded, as in the first example.
However, if the company has not provided a user licence for this scenario, or if it prefers that the partner use its own applications with its own licences from its own network, it can ask the partner to go through the PAM so that all its actions can be tracked and recorded. In this case the industrial applications installed on the partner’s workstation interact remotely with the company’s PLCs, while still being monitored by the PAM solution. The architecture of the solution differs from one industrial manufacturer to another, some requiring it to be on the same network as the PLCs, others allowing remote access on different networks. This is where the architecture of the PAM solution comes into play: it must allow seamless integration into an industrial network architecture, while securing access to applications and equipment.
Often, local PLC networks are isolated by outgoing network diodes, so the solution must be able to operate in these highly secure network environments, applying the principle that access is always from the most secure zone to the least secure. In this case of secure remote access there are two types of architecture. One — preferred, because more secure — is based on an end-to-end secure tunnel, from the output of the industrial application to the input gateway in the industrial network where the PLCs are located, through which the industrial connection protocols to the PLCs and equipment pass. The other is based on a VPN, if possible one that filters flows at the level of network addresses and server input ports, allowing the industrial application to see the PLCs and equipment it controls on the network.

The new generation of solutions makes remote access to a system — whether IT, industrial or mixed — much more secure than in the past. They solve the paradox of creating an impenetrable barrier that can only be crossed by those authorised to do so, while protecting the assets to which they grant access. And even if 100% security does not exist, the benefits in terms of operational efficiency and productivity exceed the risk of not using them: a remote intervention that unblocks a production line is better than waiting for an on-site one, without compromising the security of industrial assets.
Yes, cybersecurity can be a lever for performance.
Tags
- Articles
- ZTNA
- PAM
- Industrial & Manufacturing
- OT & Industrial Security
Check other relevant resources

Meurthe-et-Moselle Departmental Council
Delivering a seamless remote working experience for employees.

Hautes-Alpes Departmental Fire and Rescue Service
Securing and simplifying volunteer firefighters’ access to operational applications.

Bièvre Isère Regional Authority
Bièvre Isère authority chose cyberelements to streamline employee integration and enable staff to be fully operational on their first day.
View All
