The Session You Didn't Know Was Open: Remote Access Blind Spots in Critical Infrastructure
About This Session
Remote access to OT environments expanded massively post-COVID. It never contracted. Most operators don't know who's connected, when, or what they're doing, in real time or after the fact.
This session examines three patterns seen across water, energy, and transportation infrastructure:
Ghost sessions: legacy vendor connections that persist beyond maintenance windows, invisible to both operators and security teams
Credential blur: shared accounts across contractors and OEMs that make attribution impossible after an incident
Audit theater: logging that exists on paper but cannot reconstruct an actual session when regulators or incident responders ask
We'll walk through what these failure modes look like operationally, how they've contributed to real incidents (anonymized), and what a defensible remote access architecture actually requires, independent of any specific vendor or product.
Attendees leave with a maturity framework they can apply to their own environment on Monday morning.
FORMAT: 35 minutes + 10 min Q&A
AUDIENCE: OT security leads, control engineers, plant managers, IT/OT convergence teams
This session examines three patterns seen across water, energy, and transportation infrastructure:
Ghost sessions: legacy vendor connections that persist beyond maintenance windows, invisible to both operators and security teams
Credential blur: shared accounts across contractors and OEMs that make attribution impossible after an incident
Audit theater: logging that exists on paper but cannot reconstruct an actual session when regulators or incident responders ask
We'll walk through what these failure modes look like operationally, how they've contributed to real incidents (anonymized), and what a defensible remote access architecture actually requires, independent of any specific vendor or product.
Attendees leave with a maturity framework they can apply to their own environment on Monday morning.
FORMAT: 35 minutes + 10 min Q&A
AUDIENCE: OT security leads, control engineers, plant managers, IT/OT convergence teams
Speaker
Bernhard Hecker
CEO - Netop
Bernhard Hecker is the CEO leading Netop’s return to the market as a trusted provider of remote access and remote control solutions for defense, critical infrastructure, and public-sector organizations. A natural seer-builder, he brings clarity, strategic architecture, and a strong commitment to digital sovereignty to every decision.
Bernhard has led product, strategy, and policy efforts at SUSE, Pluxee, Sympa, and Retarus, shaping secure systems and digital frameworks at the EU level. At Netop, he concentrates on rebuilding with integrity, resilience, and mission-critical reliability, ensuring that organizations operating in high-stakes environments can stay connected, secure, and in control.
Bernhard has led product, strategy, and policy efforts at SUSE, Pluxee, Sympa, and Retarus, shaping secure systems and digital frameworks at the EU level. At Netop, he concentrates on rebuilding with integrity, resilience, and mission-critical reliability, ensuring that organizations operating in high-stakes environments can stay connected, secure, and in control.
