Securing Remote Access Without Disrupting Water Utility Operations
This analysis draws on research from the Our Future Water Intelligence report Cybersecurity for Water Utilities.
Remote access allows specialists to diagnose equipment, update systems, and support distant sites without waiting for travel. That efficiency also creates a high-value route into operational technology when credentials, gateways, vendor practices, and network boundaries are weak. Because these sessions often use legitimate tools, malicious activity can resemble authorized maintenance unless context and accountability are visible.
The first design question is which tasks genuinely require remote connectivity. Utilities should document the assets, users, business purpose, approved hours, operational constraints, and safety consequences for each access path before selecting technology or granting an account.
Direct internet exposure should be removed wherever feasible. Managed gateways, controlled jump hosts, application proxies, and tightly governed conduits create a place to authenticate users, validate devices, enforce policy, record sessions, and disconnect access without touching individual controllers.
Identity must be attributable to a person or managed service rather than a shared vendor account. Strong authentication, separate privileged identities, device checks, least privilege, and time-limited authorization reduce the risk that a stolen credential becomes persistent operational access.
Approval should be tied to an expected task. An engineer who needs temporary diagnostic access should not receive permanent reach across multiple plants, and an equipment supplier should not inherit broad privileges simply because its product is widely installed.
Session logging provides evidence for operations and investigations. Utilities should record who connected, through which controlled path, which assets were reached, what changes were made, and when access ended, while using supervision or recording for work on critical equipment.
Remote access cannot be governed independently from segmentation. A secure gateway loses value if it opens into a flat control network, so each connection should terminate within a defined zone and permit only the protocols and destinations required for the approved task.
Legacy devices complicate implementation because they may not support modern authentication or logging. Compensating controls can isolate those assets, restrict the systems that can communicate with them, monitor permitted traffic, and require supervised access through hardened intermediary systems.
Supplier governance extends beyond account creation. Contracts should define security responsibilities, personnel changes, subcontractors, vulnerability notification, patch support, incident assistance, evidence preservation, continuity arrangements, and the utility’s right to suspend or terminate access.
Emergency access needs advance design rather than informal bypasses. Protected break-glass credentials, dual authorization, rapid notification, enhanced logging, and post-event review can support urgent work without normalizing uncontrolled accounts or undocumented connections.
Operational teams should participate in access policy because maintenance windows, process conditions, and safety constraints affect what can be done remotely. Security teams in turn need enough process knowledge to recognize when an apparently valid session creates unusual operational risk.
Monitoring should combine technical and operational context. A connection from a known account may still be suspicious if it occurs outside an approved window, reaches an unusual asset, transfers unexpected files, changes controller logic, or coincides with abnormal process conditions.
Exercises should test compromised credentials, an unavailable vendor, a failed gateway, and the need to revoke many accounts quickly. They should also confirm that local teams can continue essential maintenance and operation when remote services or communications are unavailable.
Procurement decisions can reduce future complexity by requiring supported identity standards, secure default configurations, useful logs, controlled update mechanisms, documented interfaces, and customer authority over remote support. Lifecycle evaluation should include the cost of compensating for weak capabilities.
Board and executive oversight should focus on exposure and control effectiveness. Leaders need to know how many remote paths exist, whether each has an accountable owner, how quickly access can be revoked, whether privileged sessions are reviewed, and whether exceptions are declining.
Secure remote access is therefore an operating model, not a gateway purchase. Its strength comes from aligning identity, architecture, suppliers, maintenance, monitoring, incident response, and recovery around narrowly approved access to essential water systems.
Utilities should maintain an authoritative register of remote pathways and reconcile it with network diagrams, identity systems, contracts, and actual traffic. Stale records can conceal abandoned modems, duplicate gateways, inherited cloud connections, or support channels that survived equipment changes. Periodic field confirmation helps ensure that the governed design matches what is physically connected. Exceptions should carry an owner, operational justification, expiry date, and compensating measures that are reviewed until closure.
Change control should evaluate both the requested engineering task and the access mechanism used to perform it. A safe configuration change can still create risk if files arrive through an unmanaged device, credentials are shared informally, or the session bypasses logging. Coordinated review allows operations, engineering, and security teams to preserve maintenance speed while maintaining evidence and accountability. Post-work verification should confirm that temporary privileges, routes, and transferred files were removed or retained under explicit control.
Expert Follow-Up Questions
Why is remote access a recurring water-sector risk?
It combines operational usefulness with credentials, internet connectivity, vendor dependencies, and paths into sensitive control environments.
What should replace direct internet exposure?
Managed gateways, controlled jump hosts, strong identity, device validation, narrow authorization, and detailed session evidence.
How should vendor accounts be governed?
Each account needs an attributable user, sponsor, approved purpose, limited privilege, review date, and rapid revocation route.
Can legacy equipment support secure access?
Compensating controls can isolate legacy assets and require monitored access through hardened intermediary systems.
What should utilities test?
They should test compromised credentials, mass revocation, unavailable vendors, failed gateways, and operation without remote services.
The full Cybersecurity for Water Utilities clarifies how identity, network architecture, supplier governance, monitoring, and incident readiness combine to make remote operational access accountable.