I was recently browsing r/PLC, a Reddit community where PLC programmers, controls engineers, systems integrators, and industrial automation professionals trade advice and troubleshoot real-world problems, when a simple question caught my eye:
What hardware do you use for remote support?
The original poster (OP), an OEM systems integrator, explained that he’d been using point-to-point remote access boxes for years to support PLCs in the field. This worked, mostly. But the vendor had recently rebranded and started charging a monthly fee per device, prompting the OP to ask what everyone else was using.
More than 30 comments later, the thread had become a live debate about what "good" remote access to OT actually looks like — and who should manage it.
Unsurprisingly for a Reddit thread, the first reply didn't answer the hardware question at all. Instead, it challenged the premise.
An experienced controls engineer argued that the real issue isn't which remote access appliance to buy but rather who should administer that access in the first place.
In his view, point-to-point remote access boxes create unnecessary risk because they leave too much control in the hands of the vendor. Facilities should administer vendor access themselves, decide when vendors are allowed in, monitor every session, and revoke access when the work is done.
This isn't a controversial opinion inside OT security circles, but it runs counter to the way many OEMs and field service organizations have traditionally approached remote support.
The appeal of a plug-in remote access box is obvious. It gives vendors a fast, relatively reliable way to support equipment in the field without lengthy deployment projects.
The tradeoff is visibility and control. The facility may have limited oversight into who has access, when they're connected, or how that access is managed.
Operating this way is rarely the plant’s preferred approach. More often, the remote access solution came with the machine, the OEM expects to use it, and replacing it means coordinating operations, IT, and the vendor — all while keeping production running.
The engineer went on to describe how his own facility manages vendor access:
Every vendor account is centrally managed by the facility — not self-provisioned by the vendor.
Access must be explicitly requested and approved by the specific person the vendor is working with — no standing, always-on tunnels.
Every session is recorded and retained for 60 days.
The facility can watch sessions live and terminate them immediately if something looks wrong.
He noted that his organization uses Cyolo to support this workflow.
What happened next mirrors what is happening inside many organizations (not to mention on many Reddit threads!)
Another contributor to the thread dismissed the engineer’s approach as unrealistic and suggested it’s the kind of thing someone without real-world OT experience would propose.
The engineer pushed back, stating that he personally administers an OT network with more than 2,000 connected devices and that this is exactly how his organization handles vendor access today.
Neither side backed down, and that's probably an honest snapshot of where the industry currently stands.
Whether you agree with the engineer or the skeptic, this thread highlights how the conversation around OT remote access is changing.
The original question was about remote access appliances, but the comments sections quickly became a debate over who should administer remote access — not which device should provide it.
Request-based access, individual approvals, session recording, and real-time monitoring aren't theoretical security controls. They're already part of day-to-day operations in some large OT environments.
The pushback in the thread wasn't about whether the technology could support this model, but whether this way of administering vendor access is practical in the real world.
That's an important distinction because it shifts the conversation from choosing a remote access solution to deciding how vendor access should be managed — an even bigger decision for organizations with existing equipment, established OEM relationships, and production lines to keep running.
For many organizations, the primary challenge isn't getting vendors connected. It's how to give them the access they need while ensuring the organization maintains full visibility and control.
That's exactly the operating model described by the engineer in this Reddit thread: vendor accounts managed by the facility, access granted on request, every session recorded, and the ability to monitor or terminate sessions in real time.
Cyolo was built around this model. Rather than asking organizations to choose between security and operational efficiency, Cyolo PRO (Privileged Remote Operations) gives them a secure way to administer vendor access while keeping the organization in control.
Looking for a way to give vendors and field technicians remote access to critical systems without relying on standing VPN tunnels or unmanaged remote access boxes? Schedule a demo today to see how Cyolo PRO enables identity-based, fully auditable remote access designed for OT environments.
8 Tips for Choosing a Future-Proof Solution
Author
Dvir Peretz is Director of Marketing Operation & Growth at Cyolo. He previously worked at HiBob and Firedome.