Remote maintenance needs a
defined access to the plant

Limit external access to released systems, people and time windows.

Service partners need access without entire network areas becoming permanently reachable as a result. Remote access has to fit segmentation and operating responsibility.

IQstruct Engineering plans and integrates remote access with suitable access paths. VPN, jump hosts, MFA and time-limited releases can be combined. The choice is coordinated with the existing infrastructure, roles and security requirements.

Start now at no cost

In a free first conversation we clarify which suppliers have access today and what the controlled way there looks like.

See the person in charge

Scope of services

Release target systems specifically

Access is aligned with the agreed need.

Connect identity and release

Multi-factor sign-in and time-limited authorisation complement the technical access.

Fit service into operation

Responsibilities and agreed service hours determine the procedure.

A defined access for every service case

IQstruct Engineering plans and integrates secure remote access for machines and industrial systems.

VPN, jump hosts, multi-factor authentication and time-limited releases are combined and adapted to the infrastructure, the role model and the security requirements.

External access is set up for a specific occasion. Target system, authorised person and release period are therefore part of the planning. The connection with identity services and network segmentation embeds remote access in operating responsibility; support hours and responsibility are set out in the scope of service.

Network switches with connected patch cables and status indicators

Remote access

Service partners reach exactly the released plant

Access applies to defined systems, people and time windows, and entire network areas stay closed.

Approach in the project

  1. An employee plans access paths through firewall and DMZ on the screen while a colleague works at the network rackAi

    1

    Plan remote access

    Incoming and outgoing maintenance paths are defined with responsibilities.

  2. Three people set up remote access with authentication on the screenAi

    2

    Set up remote access

    Access on computers and servers is configured with authentication.

  3. An employee maintains the company's systems from outside through a secured accessAi

    3

    Use access into the company

    Authorised specialists maintain company systems via the released access.

  4. Two employees access a customer system in a controlled wayAi

    4

    Maintain customer systems remotely

    Employees access customer systems under control and for a limited time.

Building blocks of remote access

VPN

Encrypted connection into the released network area.

Jump host

A controlled intermediate point in front of the target system.

Time-limited releases

Access only applies for the agreed period.

IT/OT

Looking after infrastructure and protective measures together

Changes to servers and access often affect several systems at once.

A certified IT security auditor (TÜV) works in the team. The access paths are chosen vendor-neutrally to match your infrastructure. Dependencies, access paths and affected applications are therefore reviewed together before a change. The agreed procedure includes a maintenance window, the functional test and a documented way back. Ongoing support keeps configurations and responsibilities current, so that later extensions stay traceable as well.

Network security

Frequently asked questions

We are glad to answer your detailed questions in a personal conversation.

Which access and service hours are intended?

We coordinate access rights, releases and service hours with your operation.

Which products do you use?

The choice is made per project to suit your infrastructure and your security requirements.

Do you offer round-the-clock support?

We define service hours and response targets in the scope of service.

First conversation

Arrange a free first conversation

Describe your task. We agree a date and discuss the possible project scope.

  1. Notebook on a desk with an open calendar and a selected appointmentAi

    1

    You request an appointment

  2. Joint planning of a segmented IT and OT infrastructure on a network diagramAi

    2

    We discuss your requirements

  3. Discussion of a security analysis with a network diagram and a list of measuresAi

    3

    You receive a quotation for the agreed scope

Philipp Niemann-Stryczek
Philipp Niemann-StryczekManaging DirectorLeads the company on the commercial side and answers questions on IT/OT security, asset administration shells, compliance and research projects.
Free first conversation

Describe your task in the contact form. We come back with a proposed date.

Arrange a first conversation

Not quite what you need?

Discover further suitable services.

Network security and zones

Separate production and office areas and define the communication paths required.

Directory services and identities

Connect applications with central identities, roles and multi-factor authentication.

IT operations and managed services

Combine monitoring, updates and support in one agreed operating model.