Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementTechnologies & SolutionsSecurity Leadership and ManagementSecurity & Business ResilienceInfrastructure:Electric,Gas & WaterTransportation/Logistics/Supply Chain/Distribution/ Warehousing

5 Minutes With

5 minutes with Duncan Greatwood — Securing remote access in critical infrastructure

By Joy LePree Anderson
Duncan Greatwood

Bio image courtesy of Duncan Greatwood

February 7, 2023

As remote access moves beyond office environments and into the critical infrastructure and manufacturing sectors, concerns about cyberattacks that could leave citizens without power, water or transportation or send manufacturing and production to a screeching halt are quickly becoming major issues. Duncan Greatwood, CEO of Xage Security, explains the dangers of using “cobbled together” or insecure solutions to manage remote access in these sectors and why zero trust architecture must play an important role in modern security solutions that protect critical infrastructure and industry.

Security: What is your background, current role and responsibilities?

Greatwood: I have a long history in the tech industry. Before joining Xage, I was an executive at Apple, leading search technology projects and products. I also served as the CEO of Topsy, the pioneer in social media search and analytics that Apple acquired in 2013. Before Topsy, I was the founder and CEO of PostPath, the email and collaboration security company acquired by Cisco in 2008.

Currently, I serve as the CEO of Xage Security, where there is a focus on keeping critical infrastructure running securely for organizations across sectors such as energy, defense, utilities, transportation and manufacturing. I have made bridging the gap between operational technology (OT) and IT teams to secure critical infrastructure a top priority, and I am responsible for ensuring that those who need access to the most sensitive assets and information receive it promptly and securely while adversaries stay out of our nation’s critical infrastructure.

Security: Due to the pandemic, remote access is commonplace and is growing beyond typical office environments. In what sectors has the demand for remote access grown? How/for what functions are these sectors using remote access?

Greatwood: The demand for remote access has grown significantly in critical infrastructure sectors in recent years. System downtime can be hugely disruptive. For example, it can leave populations without essential products and services such as power, water or transportation. Without remote access and distributed workforce collaboration, operators rely on small on-site teams for system maintenance and optimization. But response times are of the essence.

In the case of critical manufacturing operations with distributed assets across facilities, employees and outside contractors need to be able to collaborate remotely to quickly troubleshoot. Whether it’s troubleshooting issues, installing new technologies, maintaining equipment or managing performance optimization, remote access enables better and more efficient work. By removing the hindering necessity of physical location, manufacturers can significantly bolster the daily quality and volume of work along with security measures.

Security: What challenges has this created for cybersecurity in these sectors?

Greatwood: A majority of today’s remote access solutions were built for IT systems and are therefore not suited to OT needs. Current IT-centric remote access security solutions (for example, virtual private networks (VPNs)) do not support defense-in-depth architectures deployed in industrial environments and require the use of vulnerable Windows-based jump servers that require maintenance and risk management. Some of these solutions require software to be deployed on operational systems, which introduces unnecessary risks due to the required software maintenance and sometimes direct internet connectivity for enabling collaboration.

Additionally, legacy remote access technology is often overly reliant on firewalls, which results in complex and unmanageable configurations. These solutions cannot provide limited, controlled access for users to specific devices. Instead, remote users are allowed into an implicit trust zone inside operational networks, where they have access beyond what is required for their task.

Cyberattacks exploiting vulnerable remote access mechanisms are skyrocketing and direct internet connections into OT environments are one of the reasons for the spike. There are also ongoing risks due to zero day vulnerabilities on VPNs and Windows-based jump servers. A successful attack against a manufacturing company’s OT systems, in particular, could cause a harmful disruption to production and cost millions of dollars of business impact daily.

Security: While many organizations have cobbled together solutions, there is obviously a need for modernized, secure remote access. How can this be accomplished?

Greatwood: Due to the pandemic, many companies have transitioned to distributed workforce strategy. Unfortunately, many manufacturers have been pressed to cobble together solutions, as you mentioned. Many of these turn out to be insecure, which opens up the business to significant risk.

Critical infrastructure operators should assess their current security controls in place for access management, secure remote access, privilege access management and secure zones (also referred to as Perdue model) to determine how to modernize their security architecture as well as reduce unnecessary risks and complexity.

Security: How big a role does zero trust play in these solutions and what does it look like for the organizations that employ zero trust?

Greatwood: Zero trust principles emphasize identity-based access management. Asset protection and privileged access management are crucial for modernizing remote access technology. However, it is important not to overlook minimizing disruptions to operations while ensuring current defense-in-depth approaches (like zoning) can remain in place. 

KEYWORDS: critical infrastructure cybersecurity IT security manufacturing security remote access utilities cybersecurity zero trust

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Joy lepree anderson 2023

Joy LePree Anderson is a former Associate Editor of Security magazine.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Career Intelligence
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
  • The Most Influential People in Security 2025

    Security’s Most Influential People in Security 2025

    Security Magazine’s 2025 Most Influential People in...
    Most Influential People in Security
    By: Security Staff
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • critical event management
    Sponsored byEverbridge

    Why a Unified View Across IT, Continuity, and Security Makes or Breaks Crisis Response

  • Charlotte Star Room
    Sponsored byAMAROK

    In an Uncertain Economy, Security Is a Necessity - Not an Afterthought

  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

Popular Stories

The Lourve

The Lourve Heist: What Was the State of the Museum’s Security?

The 2025 Security Benchmark Report

The 2025 Security Benchmark Report

American Airlines

Security Leaders Discuss Cyberattack on American Airlines Subsidiary

University lecture

1.2M Individuals’ Data Stolen In University Hacking

Email app

40B Records Exposed From Marketing and Email Data Platform

Top Cybersecurity Leaders

Events

September 18, 2025

Security Under Fire: Insights on Active Shooter Preparedness and Recovery

ON DEMAND: In today’s complex threat environment, active shooter incidents demand swift, coordinated and well-informed responses.

November 17, 2025

SECURITY 500 Conference

This event is designed to provide security executives, government officials and leaders of industry with vital information on how to elevate their programs while allowing attendees to share their strategies and solutions with other security industry executives.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • 5 minutes with

    5 minutes with Satya Gupta: The surge of remote work and its impact on critical infrastructure organizations

    See More
  • 5 mins with Hamilton

    5 minutes with Mike Hamilton – The biggest threats to the critical infrastructure

    See More
  • 5 mins with Brian H

    5 minutes with Brian Harrell - Critical infrastructure protection and the power grid

    See More

Related Products

See More Products
  • physical security.webp

    Physical Security Assessment Handbook An Insider’s Guide to Securing a Business

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • CASP.jpg.jpg

    CASP+ CompTIA Advanced Security Practitioner Certification All-In-One Exam Guide...

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing