09/28/2026 | Press release | Distributed by Public on 09/28/2026 10:16
In Brief (TL;DR)
Remote access has become one of the most critical security and governance challenges in operational technology (OT). As organizations modernize operations, connect industrial systems, and rely more heavily on vendors and remote support teams, traditional access models such as VPNs and shared accounts are no longer enough. Zero Trust principles, including identity-based access, least privilege, continuous verification, and strong governance, are emerging as the new standard for securing OT environments. Recent updates to NIST's OT security guidance reinforce this shift, highlighting the growing importance of visibility, accountability, and controlled access as organizations work to reduce risk, improve resilience, and support secure IT/OT convergence.
Remote access is no longer just an operational requirement in OT. It's becoming one of the most important identity and security control points in modern industrial environments.
This article builds on a recent collaboration between Xalient and BeyondTrust exploring the growing role of remote access in OT security. Here, we expand on that discussion and share our perspective on why remote access is becoming a critical Zero Trust control point as organizations modernize operations and IT and OT environments become increasingly interconnected.
For years, organizations treated remote access as a necessary compromise. Engineers needed to troubleshoot systems remotely. Vendors required access to maintain equipment. Operations teams needed to support sites without being physically present. The business need was clear, so access was enabled.The challenge is that many of these access models were never designed for today's threat landscape.
VPNs, shared administrator accounts, jump servers, and unmanaged vendor access methods became common across OT environments. While they helped keep operations running, they often provided limited visibility into who was accessing critical systems, why they were connecting, and what they were doing once inside.
Today, that lack of governance is becoming a significant security and operational risk.
The conversation is no longer about whether remote access should exist. It's about whether organizations can govern it.
Traditional OT environments were built around safety, availability, and operational continuity.
However, industrial environments have changed dramatically.
Cloud platforms, connected devices, remote support models, and IT/OT convergence have created new access paths into critical systems. At the same time, skills shortages have increased reliance on third-party vendors and specialist support teams.
Remote access is now a business requirement. The challenge is ensuring it can be controlled and monitored effectively.
Organizations need to be able to answer four fundamental questions:
If those questions cannot be answered quickly and confidently, there is likely a governance gap.
Zero Trust is often associated with IT environments, but its principles are increasingly relevant within OT.
This shift is also being reflected in industry guidance. The latest draft of NIST SP 800-82 Revision 4 places greater emphasis on Zero Trust principles, modern cybersecurity frameworks, and risk-based decision making for operational technology environments. Rather than treating OT as a completely separate discipline, the guidance recognizes the growing convergence of IT and OT and the need for identity, access governance, and continuous verification to play a larger role in protecting critical operations.
Rather than assuming trust based on network location, Zero Trust focuses on continuously verifying users, devices, and access requests.
In practice, this means moving beyond broad network access and applying controls such as:
This approach helps reduce risk while supporting the operational realities of industrial environments.
The goal isn't to stop people doing their jobs. The goal is to ensure access is controlled, monitored, and fully auditable.
Many organizations already have security technologies in place.
The bigger challenge is ensuring those technologies support a consistent operating model.
Access approval processes often differ between sites. Vendor access may be managed manually. Privileged accounts can remain shared across teams. Producing audit evidence can become a time-consuming exercise.
As regulatory expectations continue to increase, organizations are under greater pressure to demonstrate accountability around who has access to critical systems and why.
Technology platforms such as BeyondTrust play an important role in enabling privileged remote access, credential security, and session governance. However, technology alone is rarely enough. The organizations making the greatest progress are creating repeatable operating models that define how access is requested, approved, monitored, reviewed, and removed.
One of the most common OT challenges involves vendors, contractors, and OEMs.
These users often require access to support critical operations, but access can become difficult to manage if it is not governed effectively.
Leading organizations are moving toward models that provide:
This allows organizations to support operational requirements while reducing exposure and improving compliance readiness.
The future of OT security is not about eliminating remote access. It's about making remote access accountable.
As industrial environments continue to modernize, remote access will become even more important.
Organizations that can prove who accessed a system, why they were granted access, and what activity took place will be far better positioned to improve resilience, satisfy compliance requirements, and reduce operational risk.
The future of OT security isn't about replacing VPNs. It's also about aligning security programs to the direction the industry is heading. As frameworks such as NIST SP 800-82 continue to evolve, organizations are being encouraged to move beyond static trust models and adopt approaches that provide greater visibility, accountability, and control over both human and non-human identities.
It's about creating a secure, auditable, and governance-driven access model that supports modern operations.
At Xalient, we believe the future of OT security lies in combining identity, privilege, governance, and operational resilience into a single strategy. As IT and OT continue to converge, organizations will need a consistent control model that spans users, devices, applications, service accounts, and machine identities without compromising operational continuity.
Ready to make AI Accountable?
About the author
Field CTO at Xalient
David (DJ) Morimanno is the Field CTO at Xalient, where he helps organizations design and deliver identity-centric security strategies for complex, fast-evolving environments.