5 min read

The Remote Maintenance Problem

Remote maintenance is essential—but every supplier connection extends the attack surface. Shared accounts, forgotten VPNs and unmanaged maintenance access create governance risks that many organisations still underestimate.
The Remote Maintenance Problem
Foto by E. Mehler 2026

Part 4 of the series 

The Building Is Now Part of the Attack Surface


By Eckhart Mehler for CISOsCISO — a perspective on cybersecurity leadership, governance and the decisions that determine whether organizations retain control.


Every modern building depends on trust.

Not only trust in people.

Trust in companies that never appear on the organisation chart.

Elevator manufacturers.

HVAC contractors.

Building automation specialists.

Fire-protection vendors.

Energy-management providers.

Electronic locking suppliers.

System integrators.

Cloud platform operators.

Without them, buildings would quickly become impossible to operate efficiently.

Without proper governance, they can also become one of the largest attack surfaces an organisation owns.

The Privileged Outsider

Most organisations spend enormous effort controlling privileged internal users.

Administrative accounts are reviewed.

Identity governance is implemented.

Privileged Access Management is introduced.

Multi-factor authentication becomes mandatory.

Sessions are monitored.

Yet another category of privileged user often remains largely outside this governance model.

The maintenance engineer.

A building contractor may possess more persistent access to operational infrastructure than many internal administrators.

Unlike employees, these accounts often exist for years.

Sometimes for decades.

Nobody questions them because they were created for operational necessity.

Necessity, however, does not eliminate risk.

The Business Case for Remote Maintenance

Remote maintenance is not inherently insecure.

In fact, it is often essential.

It enables:

  • faster incident response,
  • lower maintenance costs,
  • access to specialist expertise,
  • predictive maintenance,
  • software updates,
  • diagnostics,
  • reduced travel,
  • improved operational availability.

Without remote connectivity, many global organisations could not operate their building infrastructure efficiently.

The objective is therefore not to eliminate remote access.

The objective is to govern it.

How Complexity Accumulates

Very few organisations intentionally design insecure remote access.

The problem develops gradually.

An HVAC supplier installs a VPN.

An elevator vendor introduces its own support gateway.

The access-control provider uses a cloud portal.

The fire-protection contractor requires permanent connectivity.

Energy-management systems transmit telemetry to external analytics platforms.

Each project is individually justified.

Collectively they create an architecture that nobody designed.

Security does not fail because of one poor decision.

It fails because hundreds of reasonable decisions were never evaluated together.

The Invisible Third Party

Ask most CISOs how many privileged internal administrators exist.

They usually know.

Ask how many external companies possess technical access to building infrastructure.

The answer often becomes uncertain.

The challenge extends far beyond contracts.

Questions include:

  • Which companies still have active access?
  • Which engineers authenticate?
  • Are accounts individual or shared?
  • Is multi-factor authentication enforced?
  • Are sessions logged?
  • Are suppliers allowed to subcontract?
  • Who reviews access after contract changes?
  • Which credentials belong to former vendors?
  • Are emergency accounts permanently enabled?

If these questions cannot be answered, governance has already failed.

Shared Accounts Create Shared Blindness

One of the oldest practices in operational environments remains one of the most dangerous.

Shared credentials.

Accounts named:

  • service,
  • maintenance,
  • administrator,
  • vendor,
  • support.

Everyone knows the password.

Nobody owns the accountability.

When an incident occurs, forensic investigation becomes almost impossible.

Who logged in?

Who changed the configuration?

Who deleted the logs?

Who introduced the vulnerability?

Nobody can say with confidence.

Identity without accountability is not identity.

It is anonymity.

Maintenance Laptops

Organisations often focus on protecting their own endpoints.

Meanwhile, contractors connect unmanaged devices directly to operational infrastructure.

Maintenance laptops may contain:

  • diagnostic software,
  • engineering tools,
  • vendor credentials,
  • firmware,
  • proprietary applications.

But they may also lack:

  • endpoint detection,
  • encryption,
  • security monitoring,
  • enterprise patch management,
  • device compliance,
  • central logging.

These devices routinely cross organisational boundaries.

From a security perspective, they represent mobile trust relationships.

The Permanent Tunnel

Convenience has a habit of becoming architecture.

Temporary remote access gradually becomes permanent.

Permanent access eventually becomes forgotten.

Years later, organisations discover:

  • VPN connections that nobody remembers approving,
  • cellular routers hidden inside control cabinets,
  • unmanaged remote desktop gateways,
  • supplier-owned cloud brokers,
  • firewall exceptions created for projects long completed.

None of these necessarily represent compromise.

But every undocumented connection increases uncertainty.

And uncertainty is the enemy of security governance.

Procurement Is Where Security Begins

Many organisations attempt to solve remote-access problems after systems are already operational.

That is too late.

Security requirements belong in procurement.

Contracts should define:

  • identity requirements,
  • authentication methods,
  • privileged-access controls,
  • session monitoring,
  • logging,
  • notification obligations,
  • subcontractor restrictions,
  • vulnerability disclosure,
  • support lifecycles,
  • incident reporting,
  • account removal after contract termination.

Security added after commissioning usually costs more and achieves less.

The Supplier Chain Nobody Maps

Third-party risk rarely stops with one supplier.

The building automation vendor may subcontract networking.

Networking may subcontract maintenance.

Maintenance may subcontract regional support.

Regional support may use freelance specialists.

Each additional layer introduces:

  • new identities,
  • new devices,
  • new credentials,
  • new responsibilities,
  • new uncertainty.

Organisations often know their direct supplier.

They rarely understand the complete operational trust chain.

Attackers do.

Monitoring Without Context

Many organisations successfully monitor VPN connections.

That alone is insufficient.

Security teams also need context.

Is this maintenance window authorised?

Should this supplier be connected today?

Which building is affected?

Which controller is being modified?

Is configuration expected?

Should engineering software be running?

Without operational context, technical monitoring produces noise rather than intelligence.

Facility management and the SOC must therefore work together.

Neither can interpret these events alone.

Trust Is Not a Security Control

A common sentence appears during supplier discussions.

“We trust this vendor.”

Trust is important.

It is not a control.

Controls exist precisely because trusted relationships can fail.

Suppliers may experience:

  • ransomware,
  • credential theft,
  • insider abuse,
  • compromised laptops,
  • phishing attacks,
  • cloud compromise,
  • subcontractor failures.

The organisation does not control those environments.

It only controls how much access they receive.

Zero Trust Includes Buildings

Zero Trust is frequently discussed in relation to users, devices and cloud services.

The same principles apply to facility infrastructure.

Never assume trust simply because access has existed for years.

Verify identity.

Limit privilege.

Restrict duration.

Monitor activity.

Review necessity.

Remove unused access.

The objective is not to eliminate suppliers.

The objective is to minimise unnecessary trust.

What Mature Organisations Do Differently

Organisations with mature governance approach remote maintenance differently.

They establish:

  • individual supplier identities,
  • strong authentication,
  • just-in-time privileged access,
  • time-limited approvals,
  • comprehensive session logging,
  • central supplier inventories,
  • periodic access reviews,
  • documented ownership,
  • security clauses in contracts,
  • joint incident procedures.

Remote maintenance becomes visible.

Visibility creates accountability.

Accountability creates resilience.

Conclusion

Remote maintenance is one of the greatest examples of modern enterprise dependency.

It connects organisations to expertise they cannot replace.

It also connects attackers to infrastructure they could never reach alone.

The question is therefore not whether suppliers should receive remote access.

They must.

The question is whether that access is governed with the same discipline applied to internal privileged identities.

Because every trusted connection eventually becomes part of the attack surface.

And every unmanaged connection eventually becomes someone else’s incident.


Publication Note & Disclaimer
This article reflects my personal professional perspective and does not represent the official policy or position of my employer. Drafting and editorial refinement may have been supported by commercially available AI-assisted tools. The analysis, conclusions and final curation are entirely my own.

For information regarding image credits, copyrights, trademarks and other intellectual property rights, please refer to the Imprint.