How to Secure Remote SCADA Access Without Interrupting Operations
By Timehri Networks LLC
Introduction
Operational Technology (OT) environments have evolved significantly over the past decade. Water and wastewater utilities, electric utilities, municipalities, and industrial facilities increasingly rely on remote connectivity to support Supervisory Control and Data Acquisition (SCADA) systems, troubleshoot equipment, maintain programmable logic controllers (PLCs), and provide vendor support. While remote access improves operational efficiency and reduces maintenance costs, it also introduces one of the most significant cybersecurity risks facing critical infrastructure.
Recent cyber incidents have demonstrated that attackers frequently exploit weak remote access controls to gain unauthorized access to industrial control systems (ICS). Once inside a network, adversaries may attempt to disrupt operations, steal sensitive information, deploy ransomware, or manipulate industrial processes.
Organizations should therefore design remote access solutions that support operational requirements while minimizing cybersecurity risk. Security controls should enable maintenance and monitoring activities without compromising the safety, availability, or reliability of critical infrastructure.
Why Remote Access Matters
Modern utilities depend upon remote access for numerous operational functions, including:
- Vendor support for SCADA applications
- PLC programming and troubleshooting
- Remote monitoring of pump stations
- Software updates
- Emergency response
- After-hours engineering support
- Cybersecurity monitoring
Although these capabilities improve operational efficiency, they must be implemented using a defense-in-depth strategy that limits opportunities for unauthorized access.
Common Remote Access Risks
Utilities frequently encounter several cybersecurity weaknesses within remote access environments.
Shared Accounts
Shared administrator accounts eliminate accountability and make it difficult to determine who performed system changes.
Weak Passwords
Passwords alone no longer provide adequate protection for critical infrastructure.
Always-On Vendor VPNs
Permanent vendor VPN connections significantly increase the attack surface.
Direct Internet Access
Industrial devices should never be directly accessible from the Internet.
Lack of Monitoring
Many organizations collect VPN logs but rarely review them for suspicious activity.
Recommended Secure Remote Access Architecture
A secure remote access solution should include multiple security layers rather than relying upon a single control.

This layered approach limits the potential impact of compromised credentials and provides additional opportunities to detect unauthorized activity.
Best Practices for Securing Remote SCADA Access
1. Require Multi-Factor Authentication
All remote users should authenticate using MFA before accessing any industrial resources. MFA significantly reduces the likelihood that stolen credentials alone can be used to compromise critical systems.
2. Eliminate Shared Accounts
Every engineer, contractor, and vendor should have an individual account with appropriate permissions. Individual accounts improve accountability and simplify forensic investigations.
3. Disable Vendor Access When Not Needed
Vendor accounts should only remain active during approved maintenance windows. Disabling accounts when work is complete reduces unnecessary exposure.
4. Use Jump Servers
Remote users should connect first to a hardened jump server located within an Industrial Demilitarized Zone (IDMZ). Direct VPN connections into the SCADA network should be avoided.
5. Log Every Session
Organizations should maintain detailed logs documenting:
- Login attempts
- Successful authentications
- Failed logins
- Configuration changes
- File transfers
- Administrative activities
Security logs should be reviewed regularly for anomalous behavior.
6. Restrict User Privileges
Users should receive only the permissions necessary to perform assigned tasks. Administrative privileges should be granted only when operationally required.
7. Monitor Remote Sessions
Continuous monitoring allows organizations to detect unusual behavior, including:
- Connections outside normal business hours
- Access from unexpected geographic locations
- Repeated failed login attempts
- Large file transfers
- Unauthorized configuration changes
8. Separate IT and OT Networks
Industrial control systems should remain isolated from corporate business networks using firewalls, network segmentation, and Industrial DMZs. Proper segmentation reduces the likelihood that an IT compromise will spread into operational environments.
9. Review Firewall Rules Regularly
Firewall rules should be reviewed periodically to remove obsolete access, close unnecessary ports, and verify that only authorized communications are permitted.
10. Develop an Incident Response Plan
Every utility should establish procedures for responding to suspected remote access compromises. Incident response plans should define roles, communication procedures, evidence preservation, and system recovery activities.
Alignment with Industry Standards
The cybersecurity practices described in this article align closely with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0, which emphasizes governance, asset identification, protection, detection, response, and recovery as the foundation of an effective cybersecurity program.
Additionally, NIST Special Publication 800-82 Revision 3 recommends secure remote access architectures, network segmentation, strong authentication, continuous monitoring, least privilege, and defense-in-depth principles specifically for Operational Technology (OT) and Industrial Control Systems (ICS).
Water and wastewater utilities can further strengthen their cybersecurity programs by applying the American Water Works Association (AWWA) Water Sector Cybersecurity Risk Management Guidance and associated Risk Management Tool to identify sector-specific risks and prioritize mitigation activities.
Conclusion
Remote access is essential for modern critical infrastructure operations. However, convenience should never outweigh security. Organizations that implement layered security controls, continuously monitor remote access activities, and align their cybersecurity programs with recognized industry standards are better positioned to protect operational continuity, public health, and public safety.
Timehri Networks LLC assists utilities and critical infrastructure organizations in designing secure remote access solutions that reduce cyber risk while supporting reliable operations.
References
American Water Works Association. (n.d.). Cybersecurity Guidance and Water Sector Cybersecurity Risk Management Tool. American Water Works Association.
American Water Works Association. (n.d.). Water Sector Cybersecurity Risk Management Guidance. American Water Works Association.
National Institute of Standards and Technology. (2023). Guide to Operational Technology (OT) Security (Special Publication 800-82 Revision 3). U.S. Department of Commerce.
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0. U.S. Department of Commerce.
