
L3.5
Secure Remote Access
A shared, always-on VPN account gives every vendor the same permanent access to your plant. It is often set up for a single job, the password is then shared more widely, and there is no record of who used it or what they did.
Where this sits
- L4Enterprise network
- L3.5DMZ
- L3Operations
- L2Supervisory
- L1Control
- L0Process
What we install
We install an access broker between external networks and your plant. Each account belongs to one named person, access is opened for an approved job and closed when the job ends, and every session is recorded.
What is included
- A brokered access path, so no external connection ends inside the plant
- Individual accounts for named people, never shared by a company or a role
- Access opened for approved work and closed when the work ends
- Least privilege access, so a vendor reaches only the system they need
- A record of each session that your own team can review
Where it sits
- L4Enterprise networkBusiness systems, email, the internet
- L3.5DMZWhere this sits
- L3OperationsHistorians, domain services, engineering
- L2SupervisorySCADA servers and operator stations
- L1ControlPLC and DCS controllers, safety systems
- L0ProcessInstruments and final elements
The access path ends in the DMZ. Vendors never connect directly to the process network. They connect to a system that can reach it, under rules your team sets.
How it is installed
The steps we follow
- 01
We list who connects from outside today, what they connect to and why. The list is often longer than expected.
- 02
The access path and rules are designed and agreed with your team before anything is built.
- 03
The broker is built and tested while your existing VPN remains in use.
- 04
Vendors are moved across one at a time, so any problem affects only one supplier.
- 05
The old shared account is closed, and you receive a record of its last use.
What this solution is not
Not a renamed VPN.
A VPN connects the vendor’s computer to your network. With a broker, the session ends at the broker and the vendor works through it, so their laptop never connects to your plant.
Not a way to block vendors.
It gives vendors controlled, recorded access. If it made routine work harder than the shared account did, staff would find ways around it.

