Remote diagnostics should not be accepted as a minor accessory to a laser, press brake, CNC machine, robotic cell, or material handling system. If the quote includes an OEM router, VPN gateway, cloud portal, cellular connection, or supplier-managed account, that architecture belongs in the purchase specification and machine acceptance plan.
My default is plant-controlled access. The plant should control identities, authorization, reachable assets, activity records, shutdown authority, and recovery. An OEM-specific method can remain an option, but it should enter the project as a documented exception with clear technical and commercial boundaries.
Remote access is a lifecycle commitment
The connection adds user accounts, authentication methods, software dependencies, external services, network rules, data flows, patch responsibilities, support terms, and recovery obligations.
Without a plant standard, one machine can end up with shared supplier credentials, another with permanent unattended access, and a third with a cloud account that no current employee administers. Those arrangements become difficult to unwind when personnel change, equipment moves, support contracts expire, or a different integrator assumes responsibility.
Automation World has reported on the governance burden created by numerous proprietary remote-access methods. Its January 2026 OT cybersecurity coverage also emphasized that security technologies need to work as an integrated system rather than as isolated purchases.
The January 2026 multiagency Secure Connectivity Principles for Operational Technology moves the issue into capital planning. It calls for a documented business case covering the purpose of the connection, expected benefit, acceptable risk, introduced dependencies, potential consequences, and accountable owner.
Those questions should be resolved before production depends on outside access.
One plant standard does not mean one product
A plant-controlled standard does not require every OEM to use the same diagnostic software or communication protocol. It defines the boundary within which those tools must operate.
Named users should replace shared vendor credentials. Multifactor authentication should protect external access. Permissions should be limited to the machine and functions required for the service task, then removed or allowed to expire when the approved support window closes.
Network reach matters as much as login security. A technician troubleshooting a laser control should not automatically gain access to press brakes, robots, storage automation, engineering workstations, or unrelated equipment.
OMAC manufacturing guidance connects asset inventory, network segmentation, unique identities, multifactor authentication, target-device verification, and centralized activity documentation. NIST SP 800-82 Rev. 3 similarly recommends allowing remote access only when justified, limiting it to the business requirement, monitoring activity, removing access when it is no longer needed, and preventing the connection from bypassing existing safety or security controls.
Operations personnel also need to know when remote work is planned and how to disconnect the connection without disrupting the process.
Separate login permission from change authority
Authentication establishes who entered the system. It does not determine what that person may change.
Viewing alarms and collecting diagnostic files do not carry the same production exposure as changing CNC parameters, editing PLC logic, loading a robot program, updating firmware, modifying drive settings, or changing a safety-related configuration.
The commissioning plan should assign approval levels to those activities. It should identify who confirms the machine state before work begins, who authorizes the change, and who validates operation before the equipment returns to production.
Logging capability varies by machine and access platform. At minimum, determine whether the plant can retrieve the user identity, target asset, login time, connection duration, and relevant change events. If command logs or session recording are available, assign ownership and retention responsibility during the project.
The CISA-led Secure by Demand procurement guidance treats configuration control, baseline logging, product ownership, strong authentication, vulnerability management, and patch tooling as product-selection issues. That makes them quote-stage requirements, not corrective work to be funded after startup.
Close the controls-handoff loop
A technician can clear a fault remotely while leaving the plant with an outdated program or configuration backup. Immediate recovery and long-term recoverability are different outcomes.
The handoff should identify the authoritative versions of CNC parameters, PLC and HMI applications, robot programs, drive settings, network-device configurations, gateway settings, and other files needed to restore the system. It should also assign responsibility for updating those records after an approved remote change.
A backup file alone is not acceptance evidence. Recovery can also depend on the correct software version, licenses, credentials, hardware assumptions, restore sequence, and responsible personnel.
NIST recommends verifying backup reliability, testing restoration, and incorporating backup procedures into configuration or change management. The agreed restoration method should be proven through a controlled test that does not place normal production at risk.
Operations, controls, IT, the integrator, and the OEM need one commissioning record. ISA identifies shared responsibility among asset owners, product suppliers, integrators, and service suppliers as a founding principle of the ISA/IEC 62443 series. The purchase order and support agreement still need to convert that principle into machine-specific responsibilities.
OEM-specific access can be a controlled exception
Some equipment may rely on a supplier-managed gateway, proprietary diagnostic service, licensing system, or cloud function that cannot operate through the normal plant architecture. That does not automatically disqualify the equipment, but it changes the review.
Confirm which assets the connection can reach, how a session is initiated, who owns the accounts, where logs and machine data are stored, who patches the gateway or application, and what happens when the subscription or support agreement ends.
The commercial review should determine whether disabling the connection affects warranty terms, diagnostic capability, escalation procedures, or service commitments. Those consequences need to be documented before an outage exposes them.
A controlled exception should have a review date, local disconnection method, configuration backup, assigned account owner, and exit plan. If the connection boundary cannot be documented or the plant cannot monitor and disable access, remote support should remain off until the implementation is ready.
Prove the workflow during acceptance
Use commissioning to prove that remote support works through the approved architecture and that plant personnel can control what happens afterward.
- Deliver an as-built network diagram showing the machine, gateway, remote platform, required ports, protocols, and external services.
- Identify every asset reachable through the connection and demonstrate that unrelated equipment cannot be reached.
- Create a named support account, demonstrate multifactor authentication, and show how authorization is granted and removed.
- Generate the available access and change records and show plant personnel how to retrieve them.
- Demonstrate the local disconnection method and train the people responsible for using it.
- Define approval requirements for CNC parameters, PLC and HMI applications, robot programs, firmware, drives, and network settings.
- Deliver current configuration backups and prove the agreed recovery method in an appropriate controlled test.
- Assign account administration, patch decisions, support escalation, post-service validation, and backup updates.
Acceptance should prove more than the supplier’s ability to connect. It should prove that the plant can close the connection, identify what changed, validate the machine, and recover the system without creating a second production problem.
Share the proposed network diagrams, vendor access methods, support agreements, account structure, controls backups, recovery procedures, and commissioning responsibilities with Adam Quoss, Vice President of Sales at Mac-Tech. Adam Quoss can help determine whether the equipment should use the plant standard, receive a controlled OEM exception, or defer remote connectivity until the implementation is ready.
Sources
- Building Robust OT Cybersecurity: A Strategic Framework for Industrial Operations
- Secure Connectivity Principles for Operational Technology
- Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products
- Guide to Operational Technology Security, NIST SP 800-82 Rev. 3
- Practical Guide for Remote Access to Plant Equipment
- ISA/IEC 62443 Series of Standards
Get Weekly Mac-Tech News & Updates
