OT Remote Access & Vendor Security by Kai London
The most reliable route into an industrial network is not an exploit. It is a legitimate account belonging to someone who does not work for you. This field guide governs that route end to end — from the contract clause to the session recording — without stopping the engineer who genuinely needs in at two in the morning.
Available on Amazon.
What is inside
Mapping every route in
Vendor VPNs, cellular modems, OEM support tunnels and the connections installed with the equipment years ago.
Brokered access architecture
Jump servers, industrial DMZs and session brokers designed so no third party lands directly on the control network.
Identity and privilege
Named accounts, MFA, just-in-time elevation and time-bound access instead of a shared password on a whiteboard.
Session control and recording
Approval, supervision, recording and termination — the evidence that a maintenance session was what it claimed to be.
Contracts and onboarding
Security clauses, obligations and offboarding that actually revoke access when the contract ends.
Monitoring third-party behaviour
Detecting a compromised vendor account doing something a maintenance engineer would never do.
Who it is for: OT security teams, plant and maintenance engineering, procurement and vendor management, and CISOs whose third-party register has more entries than their asset register.
Every standing vendor tunnel is a door you left open for someone who has since changed employer.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.