Remote access is the lifeblood of modern industrial operations. For plant managers and OT engineers, tools like TeamViewer, Splashtop, and Atera are essential for keeping production lines running when experts cannot be physically present. However, the convenience of these legitimate remote-support pathways creates a significant attack vector. When threat actors compromise an endpoint, they often weaponize these very tools to maintain persistent access, bypassing traditional perimeter defenses.
This is not a hypothetical scenario. In our recent engagements, we have observed how easily these “genie-in-a-bottle” risks materialize in operational technology environments. The following insights are drawn from direct Red Trident assessments of industrial networks, combined with industry-wide research on remote access exploitation.
The Reality of Legacy Remote Access in OT
Industrial environments have historically relied on perimeter-based security models. However, the shift toward remote maintenance and support has rendered static firewalls insufficient. The challenge is that many legacy systems lack native visibility into remote access activities, creating blind spots for security teams.
In our assessments, we frequently encounter endpoints with multiple legitimate remote-support pathways active or permitted. To be precise: in 2 of 2 endpoint assessments from the same industrial organization, Red Trident found multiple legitimate remote-support or remote-management pathways. On one endpoint, four named third-party support/management components were present with related active connections: AteraAgent, TeamViewer, Splashtop, and Dell SupportAssist. On the second, AteraAgent and Splashtop were installed and running, while inbound firewall exceptions also permitted Remote Assistance, Zoom, Teams, and Splashtop-related traffic.
This finding highlights a critical issue: layered remote-support pathways increase the attack surface exponentially. Each active tool represents a potential entry point for lateral movement. When combined with weak authentication or outdated configurations, these tools become the primary conduit for attackers to move from an IT network into the OT zone.
Case Study: The Dual-Route Workstation
Consider a specific case where we assessed an OT remote-operation workstation. We observed two simultaneously active network interfaces on separate networks, with a default gateway on each interface, while the Windows Internet Connection Sharing service was also running.
This configuration is dangerous for several reasons:
- Segmentation Bypass: The dual default routes allow the workstation to act as an unintended bridge between networks.
- Unintended Transit: Traffic can be routed outside of monitored security zones, bypassing firewalls and intrusion detection systems.
- Operational Risk: If a remote access tool is compromised on this machine, the attacker gains direct access to multiple network segments simultaneously.
This single-host observation underscores the need for rigorous configuration management. It is not enough to simply install security tools; their interaction with the underlying network architecture must be carefully controlled.
Prioritizing Remediation: Beyond Patching
Many organizations attempt to remediate remote access risks by simply patching software or disabling all third-party tools. This approach is flawed because it ignores operational reality. In OT, availability and safety are paramount. Removing all remote access capabilities can halt production and compromise safety systems.
Instead, remediation must be prioritized based on exploitability, potential operational consequence, exposure, compensating controls, and feasibility. As we often advise our clients: use defense-in-depth for legacy systems. When systems cannot be patched or replaced, compensating controls such as segmentation, access control, firewalling, monitoring, secure remote access, and enhanced logging may reduce exposure.
Step-by-Step Hardening Procedure
To effectively harden remote access after a potential incident, follow these concrete steps:
- Inventory All Remote Access Tools: Identify every instance of TeamViewer, Splashtop, Atera, and other third-party tools across your OT environment. This includes hidden agents on PLCs, HMIs, and engineering workstations.
- Map Network Flows: Document all allowed connections for each tool. Which IP addresses are permitted? Are they restricted to specific subnets?
- Enforce Single-Path Routing: Ensure that OT workstations do not have multiple active default routes unless strictly necessary and monitored. Disable Internet Connection Sharing on critical assets.
- Implement Zero Trust Principles: Require multi-factor authentication (MFA) for all remote access sessions. Verify the identity of every user and device before granting access.
- Monitor for Anomalies: Use network monitoring tools to detect unusual outbound connections, such as those from legacy systems that do not typically initiate internet traffic.
The Role of Standards in Remote Access Security
Compliance frameworks like IEC 62443, NIST SP 800-82, and NERC CIP provide valuable guidance for securing OT environments. These standards emphasize the importance of network segmentation and access control. However, translating these requirements into practical steps can be challenging.
For example, IEC 62443 recommends defining security zones and conduits to limit the flow of traffic between areas with different security requirements. In the context of remote access, this means that remote support sessions should only traverse necessary conduits and be strictly monitored. Cross-functional collaboration between OT and IT teams is critical for rapid threat detection in industrial networks.
Furthermore, implementing zero-trust architectures in OT environments can mitigate risks from insider threats and compromised devices. This involves continuously verifying the trustworthiness of every connection request, regardless of its origin.
Lessons from Recent Industrial Cyberattacks
Recent large-scale industrial cyberattacks have highlighted the non-obvious strategies for building cybersecurity resilience. One key lesson is the value of post-incident analysis in preventing future attacks. By understanding how attackers exploited remote access tools, organizations can better defend against similar tactics.
Research from Nozomi Networks Labs emphasizes that remote access tools, when misconfigured, are increasingly being weaponized by attackers for persistent OT system infiltration. This underscores the need for proactive security measures beyond traditional perimeter defenses. Organizations must implement Zero Trust principles and continuous monitoring for remote OT access sessions.
Addressing Supply Chain Risks
Another critical aspect of remote access security is the supply chain. The shift to remote work during recent global events has exposed new OT security vulnerabilities, emphasizing the need for enhanced network segmentation and real-time monitoring. The underappreciated risk of supply chain disruptions exacerbating OT system weaknesses cannot be overstated.
To mitigate these risks, organizations should conduct regular OT-specific ransomware simulations to identify blind spots. This proactive approach helps ensure that security controls are effective and that response plans are robust.
Validating Remediation Efforts
Every remediation project should validate that controls meet design objectives without compromising operational performance. This validation process is crucial for ensuring that hardening measures do not inadvertently disrupt production.
When we assess our clients, we look for evidence that security controls are functioning as intended. This includes verifying that firewall rules are correctly applied, that MFA is enforced, and that monitoring systems are generating alerts for suspicious activity. Improving architecture, not just devices, is essential for reducing blast radius and making monitoring more effective.
Common Pitfalls to Avoid
- Acknowledging the Genie: The remote access genie is out of the bottle. Trying to eliminate all third-party tools is often impractical. Instead, focus on controlling and monitoring them.
- Neglecting Legacy Systems: Legacy OT systems lack native visibility into remote access activities. Use external monitoring tools to fill this gap.
- Ignoring Configuration Drift: Remote access configurations can change over time due to updates or administrative errors. Regular audits are necessary to maintain security posture.
Conclusion
Hardening remote access after a third-party RAT incident requires a comprehensive approach that balances security with operational needs. By prioritizing findings based on risk, implementing defense-in-depth strategies, and adhering to established standards, industrial operators can significantly reduce their exposure to remote access threats.
The findings from our recent engagements serve as a stark reminder of the risks involved. In 2 of 2 endpoint assessments from the same industrial organization, Red Trident found multiple legitimate remote-support or remote-management pathways active or permitted. This data underscores the need for vigilance and proactive management of remote access tools.
As you review your own environment, consider conducting a thorough assessment of your remote access configurations. Identify any dual-route workstations, excessive tool installations, or unmonitored connections. By taking these steps, you can build a more resilient OT security posture that protects both your operations and your data.
Ready to secure your OT environment? Contact Red Trident for a free OT security assessment consultation. We will help you identify vulnerabilities, prioritize remediation efforts, and implement effective controls tailored to your industrial operations.
