İçereği Atla

One place that records which remote access routes exist at all

Why the question of external access to production goes unanswered in many companies, and how AIM turns scattered manufacturer connections into a managed overview.

The typical starting position

Modern production plant comes with remote maintenance. The manufacturer connects in, reads out fault memories, installs updates and helps with troubleshooting. Without this option, repairs take considerably longer, and a day of travel often sits between the fault and the fix.

In practice, the access route usually came about in whatever way was quickest during commissioning. A router next to the machine with its own mobile or DSL line, a remote maintenance box brought along by the manufacturer, or a permanently configured VPN connection with far-reaching rights. Each of these routes was set up individually, usually by different people and spread across several years of investment.

Why this is a problem

Every one of these variants shares the same core issue. There is a route from outside into production that the company does not fully control.

A manufacturer's own router creates a second internet connection that bypasses the company firewall. The company does not know who connects in and when, and in case of doubt does not even see that the line exists. With permanent VPN access, the connection is available at all times, including during the months in which there is no service case at all. Credentials are shared within the manufacturer's service team and outlive staff changes.

The core of the problem, however, is a different one, and it becomes apparent the moment an auditor, a customer or an insurer asks the simplest of all questions: which external access to your production exists? In many companies there is no list to answer that question, only people who remember. What is not documented can neither be switched off nor defended.

On top of this comes regulatory pressure. NIS2 explicitly addresses supply chain security, and customers pass corresponding requirements down to their suppliers.

The approach

Technically, remote access is routed through AIMdefense. The route then runs through the company's central firewall, it is opened for the service case and closed again afterwards.

The real benefit, however, lies one level above. Through AIM – Advanced Infrastructure Management, the configured access routes remain visible centrally:

  • A managed overview of all remote access routes. Which plant supplier reaches which system, by which route and since when. Particularly in companies with many plant suppliers, this is the point at which the situation can be assessed at all.
  • Asset discovery as the foundation. Only a recorded device inventory shows which systems can actually be reached behind a given access route. Frequently there are more of them than was assumed when it was set up.
  • Assessment through the VAS module on precisely those systems, with appropriate restraint for production technology, because active scans can disturb sensitive controllers.
  • Central configuration backup. The rule sets that bound an access route are themselves configuration. They are backed up automatically, and changes to them are traceable.
  • Integrated wiki and maintenance calendar. Service contracts, contacts at the manufacturer and deadlines are held against the same systems as the access route itself.

A collection of individual connections thus becomes a managed installed base.

Getting there

The first step is taking stock, and it regularly brings to light access routes that nobody in the company remembered. Machines from earlier investments, lines that were supplied at commissioning, credentials belonging to engineers who left long ago.

Next comes the conversation with the plant suppliers. Some service contracts assume particular forms of access. That is negotiable, but it has to be settled before an existing route is switched off. Experience shows that most manufacturers accept controlled access, because what mainly changes for them is that they announce themselves instead of dialling in at any time.

Only then is the changeover made, machine by machine. No standstill is required for this. The new route is set up, tested and documented in AIM before the old one is removed. The decisive difference from a one-off clean-up lies in what happens afterwards: the inventory stays under management instead of being out of date again six months later.

What changes afterwards

Remote maintenance continues to work, with the same response time and often faster, because the route is defined rather than improvised. What disappears are the unknown doors.

For the company this above all means being able to give answers. Anyone who asks which external access to production exists receives a reply from a maintained source. In front of auditors, customers and insurers, that is the difference between evidence and an assumption. It does not guarantee compliance, but it does support the evidence that the access routes are known, bounded and documented.

At a glance

Field of applicationManufacturing with remotely maintained plant
Initial problemUnknown manufacturer access, no reliable overview
AIM productsAIM including VAS module, AIMdefense
Role of AIMCentral overview of all remote access routes, inventory, assessment, documentation
ApproachTake stock, agree with the suppliers, change over machine by machine
Reference frameworkSupply chain security in the sense of NIS2

More about AIM

For the evidence that arises from a managed installed base, backed-up configurations and continuous assessment, please see the Compliance page.

For an example of how complete inventory management is built in a grown multi-vendor environment, see the success story Hospital group with more than 20 hospitals.