Blog
Oct 1, 2026
4 min read

Why OT Remote Access Requires Continuous Monitoring and Oversight in the Age of AI

Google Cloud's recent guidance on secure agentic AI in manufacturing emphasizes continuous oversight, context, and human control. These same principles are increasingly important for secure OT remote access, where AI can help teams detect and respond to risk during active sessions.

Written By

Michael Langer

Zero Trust Doesn’t End at Login

Google Cloud’s Office of the CISO recently published an article entitled, A manufacturing blueprint for secure agentic AI. The article offers a practical look at how AI agents are moving from analysis to action on the factory floor.

One principle that stands out for anyone responsible for securing plant operations is Zero Trust. Google describes “continuously enforc[ing] Zero Trust policies from the enterprise cloud down to shop-floor PLCs,” with behavioral and operational context analyzed in real time so that every actor touching those systems—whether a human operator, robotic controller, or autonomous software—stays within verified boundaries.

The blueprint also addresses scale. With adversaries increasingly using AI to advance their attacks, Google positions AI security agents as a force multiplier for resource-constrained security teams: filtering out noise, triaging large alert volumes, and isolating the threats that genuinely deserve a human’s attention. This final challenge is especially acute in OT, where experienced security analysts who understand industrial environments are hard to find and harder to scale.

Bringing Continuous Oversight to Remote OT Sessions

At Cyolo, we see the impact of these pressures every day, and they converge at one of the most critical points of exposure in OT: the live remote session, when employees, vendors, and OEMs are actively working on cyber-physical systems. Getting the right person connected to the right system is essential, but risk doesn’t stop once the user’s identity is verified and the connection is approved. A compromised account can look legitimate at login. A trusted vendor or employee can make a costly mistake. And individually harmless actions can combine to signal an attack. Yet no team has the time or manpower to monitor every potentially risky remote OT session one-to-one.

This is why Cyolo introduced Live Risk Detection, an AI-powered capability for our Cyolo PRO (Privileged Remote Operations) access solution. Live Risk Detection supervises and evaluates active remote OT sessions both in real-time and in the context of the full session, rather than relying only on static allow/block rules. When it identifies malicious behavior, unsafe actions or changes that could disrupt production, it alerts the right security and operations stakeholders within seconds, with the risk level, activity details, and user identity they need to respond while the session is still active.

Instead of adding noise, Live Risk Detection replaces blind spots with prioritized signals: teams set sensitivity and severity thresholds, and alerts flow into existing SIEM workflows. For teams short on analysts and time, every session gets AI supervision, and scarce human attention gets focused where it matters most.

Live Risk Detection also puts Google’s Zero Trust principle into practice in a place the blueprint doesn’t cover in detail: interactive remote sessions performed by employees and third-party vendors. Zero Trust has to start with verifying who is connecting and what they’re allowed to access, but it can’t end there. Risk can emerge after the session begins, so oversight must continue throughout the live session and account for what the user is actually doing while connected to critical systems.

Google’s blueprint also urges security leaders to plan for a governance shift from human-in-the-loop to human-on-the-loop oversight as AI agents take on more autonomous roles. Live Risk Detection applies a related principle: AI can scale human oversight without removing human control. Humans no longer need to manually monitor every session, because AI supervises them continuously. But when it comes to taking action on a session that can affect physical equipment, a human stays firmly in the loop.

The factory of the near future will have more remote connections, more third parties, and more AI agents acting on plant systems. The principle that should govern all of them is the same: verify continuously, supervise in context, and keep humans in charge. We’re starting where risk is highest today—the remote OT session. We believe this same approach will be increasingly essential as agentic AI arrives on the shop floor.

If you’re rethinking how you monitor and manage remote access risk across your plants, we’d love to show you Live Risk Detection in action.

Read the solution brief or request a demo today.

Michael Langer

Author

Michael Langer is VP of Product at Cyolo. He previously served as Chief Product Officer at Radiflow and Cyber Security Advisor at the Israel National Cyber Directorate.

Subscribe to Our Newsletter