Establish business need and access inventory
Remote access is rarely just a network issue. It connects a maintenance need with identities, target systems, time windows, suppliers and operational accountability. Without complete ownership, old and parallel access paths remain in place.
The starting point is a dependable inventory covering supplier, purpose, target, technical method, internal owner and approved operating window.
- Remove access that is no longer required or cannot be assigned
- Treat emergency access separately and exercise it regularly
- Identify shadow access through private routers, modems or unmanaged tools
Use named identities and strong authentication
Shared supplier accounts prevent dependable attribution. Named users, strong authentication, limited privileges and time-bound authorisation establish accountability.
Permissions should match the work order and target system. Standing administrator access is not a practical shortcut; it is an uncontrolled transfer of risk.
Broker and segment technical access
Connections should pass through controlled gateways, jump hosts or equivalent access brokers. Direct inbound connectivity and unrestricted network reach should be avoided.
The architecture must account for availability, safety, maintainability and emergency operation. A technically maximal design that operations bypass is not effective.
Approve, monitor and terminate sessions
Each session should have a traceable purpose, time window, target, approver and expected activity. Logging, session oversight, emergency termination and periodic review support later assessment.
Monitoring does not replace explicit approval. Approval must not become a standing authorisation for different systems or future maintenance windows.
Govern the full supplier lifecycle
Security requirements, incident communication, subcontractors and access termination belong in both contracts and operating processes. Technical accounts must follow personnel changes, contract termination and security events.
Periodic review should cover actual use, exceptions, obsolete technology and the continuing business need—not only whether an account exists.
Service boundary
Support covers governance, risk assessment, target architecture and remediation planning. Technical approval, operational safety, production accountability and live changes remain with the operator’s authorised functions.