Group Purchasing
Group Purchasing

Securing Remote Access in OT: A Critical Control for Modern Risk

Securing Remote Access in OT: A Critical Control for Modern Risk (PDF, 2.08MB)Published: 13 Jan, 2026
Created by:

Thank You to Our Sponsor

The Securing Remote Access in OT: A Critical Control for Modern Risk product review, published by SANS Institute in January 2026, evaluates how the Dispel Zero Trust Engine operationalizes the SANS Five ICS Cybersecurity Critical Controls (5CC) framework for industrial control system (ICS) and operational technology (OT) environments. The paper focuses on Control 4: Secure Remote Access, examining architecture, deployment models, and use cases for securing the connections that vendors, engineers, and OEMs use to remotely monitor and maintain industrial assets.

Key findings:

  • Remote access remains one of the top three initial access vectors in OT security incidents globally, according to the Dragos 2025 OT Security Financial Risk Report
  • Implementing a secure remote access solution can reduce overall organizational risk by more than 12% (12.18%)
  • Risk reduction by SANS ICS Critical Control (Dragos 2025 data): Incident Response 18.46%, Defensible Architecture 17.09%, Network Visibility and Monitoring 16.47%, Risk-Based Vulnerability Management 13.87%, Secure Remote Access 12.18%
  • The SANS Five ICS Cybersecurity Critical Controls are: ICS Incident Response, Defensible Architecture, ICS Network Visibility and Monitoring, Secure Remote Access, and Risk-Based Vulnerability Management
  • Historical incidents cited as evidence of remote-access risk include the 2015 and 2016 Ukraine power grid attacks and the 2021 Colonial Pipeline ransomware incident, which halted petroleum distribution across the Eastern United States
  • Dispel's architecture places controlled gateways called "Wickets" inside the OT DMZ to enforce segmentation and logging while isolating users from direct access to control assets
  • Dispel organizes environments in a four-level hierarchy: Organization, Region, Facility, and Wicket
  • Dispel offers three remote access connection modes: clientless browser-connect (HTML5-based), virtual desktop infrastructure (VDI) for complex engineering work, and local application for single-protocol, policy-restricted access
  • Dispel supports three deployment models: software-as-a-service (SaaS), bring-your-own-cloud (private-cloud), and fully on-premises
  • Dispel's approach aligns with NIST SP 800-53, NIST SP 800-82, ISO/IEC 27001, SOC 2 Type 2, ISA/IEC 62443, NIS2, and NERC CIP
  • Organizations can roll out Dispel globally at a pace of one site per day without endpoint installations or disruptive configuration changes
  • Dispel's 24/7 managed threat monitoring capability is backed by Google SecOps, Mandiant, and SentinelOne

Across the SANS 5CC, the report finds that Defensible Architecture and Secure Remote Access are the most tightly intertwined, since connectivity is only as secure as the segmentation and monitoring around it. Rather than treating remote access as an unavoidable liability, the paper frames it as a control function that, when built on disposable, auditable infrastructure, can strengthen rather than weaken an OT environment's overall security posture. This is a SANS product review: an independent evaluation of Dispel's platform against the SANS Five ICS Cybersecurity Critical Controls framework, informed by SANS field experience and the Dragos 2025 OT Security Financial Risk Report.

Securing Remote Access in OT: A Critical Control for Modern Risk

Related Webcast

Mike Hoffman will explain how Dispel’s OT-first remote access platform implements 5CC-aligned safeguards—covering architecture, deployment patterns, connection models, and operational controls. You’ll see how moving-target defense, disposable sessions, vaulted credentials, granular auditing, and compliance artifacts can reduce dwell time and simplify investigations—while preserving operator productivity.

Man presenting webcast to laptop screen

FAQs:

Implementing a secure remote access solution can reduce overall organizational risk by more than 12% (12.18%), according to the Dragos 2025 OT Security Financial Risk Report cited in the SANS review.

They are ICS Incident Response, Defensible Architecture, ICS Network Visibility and Monitoring, Secure Remote Access, and Risk-Based Vulnerability Management. 

Remote access remains one of the top three initial access vectors in OT security incidents, with compromised credentials, misconfigured VPNs, and unsecured vendor connections enabling attackers to bridge the IT/OT divide. 

Three modes: clientless browser-connect for fast, task-based sessions; virtual desktop infrastructure (VDI) for complex engineering work; and local application access for single-protocol, time-limited connections to legacy systems. 

Yes. Dispel supports SaaS, bring-your-own-cloud (private-cloud), and fully on-premises deployment models to accommodate different regulatory and data residency requirements. 

Meet Your Author

Michael Hoffman
Michael Hoffman

Michael Hoffman

Certified Instructor

Michael Hoffman teaches ICS410 and ICS612 with a plant floor mindset, turning complex ICS/OT concepts into clear, repeatable practices. Students leave with practical skills that enable them to protect essential services without compromising safety or uptime.

Read more about Michael Hoffman