Phi Tech Solutions

Engineering for process plants since 2005

phitech.com.pk (opens in a new tab)

Process engineering, process control and OT security, in one company.

Phi Tech Solutions has worked in process plants since 2005. PhiSecure is its OT cybersecurity practice, working alongside the company's process engineering, process control and reliability teams.

Visit phitech.com.pk (opens in a new tab)
A control room where an engineer stands at a mobile laptop cart in front of a curved wall of process dashboards, with equipment racks along the far wall

L3.5

Secure Remote Access

A shared, always-on VPN account gives every vendor the same permanent access to your plant. It is often set up for a single job, the password is then shared more widely, and there is no record of who used it or what they did.

Where this sits

  1. L4Enterprise network
  2. L3.5DMZ
  3. L3Operations
  4. L2Supervisory
  5. L1Control
  6. L0Process
1.0

What we install

We install an access broker between external networks and your plant. Each account belongs to one named person, access is opened for an approved job and closed when the job ends, and every session is recorded.

What is included

  • A brokered access path, so no external connection ends inside the plant
  • Individual accounts for named people, never shared by a company or a role
  • Access opened for approved work and closed when the work ends
  • Least privilege access, so a vendor reaches only the system they need
  • A record of each session that your own team can review
2.0

Where it sits

  1. L4Enterprise networkBusiness systems, email, the internet
  2. L3.5DMZWhere this sits
  3. L3OperationsHistorians, domain services, engineering
  4. L2SupervisorySCADA servers and operator stations
  5. L1ControlPLC and DCS controllers, safety systems
  6. L0ProcessInstruments and final elements

The access path ends in the DMZ. Vendors never connect directly to the process network. They connect to a system that can reach it, under rules your team sets.

3.0

How it is installed

The steps we follow

  1. 01

    We list who connects from outside today, what they connect to and why. The list is often longer than expected.

  2. 02

    The access path and rules are designed and agreed with your team before anything is built.

  3. 03

    The broker is built and tested while your existing VPN remains in use.

  4. 04

    Vendors are moved across one at a time, so any problem affects only one supplier.

  5. 05

    The old shared account is closed, and you receive a record of its last use.

4.0

What this solution is not

  • Not a renamed VPN.

    A VPN connects the vendor’s computer to your network. With a broker, the session ends at the broker and the vendor works through it, so their laptop never connects to your plant.

  • Not a way to block vendors.

    It gives vendors controlled, recorded access. If it made routine work harder than the shared account did, staff would find ways around it.