Reducing industrial maintenance travel does not mean replacing all on-site visits with remote diagnostics. Certain operations still require a physical presence: part replacement, lockout/tagout, mechanical inspections, on-site measurements, or safety-related work. However, a large portion of diagnostics, acknowledgments, verifications, parameter adjustments, alarm analyses, and manufacturer support can be performed remotely when technicians have secure access to the site’s PLCs, HMIs, SCADA systems, and IP-based equipment.
The Problem
In industry, maintaining automated equipment involves a great deal of travel: alarms to address, faults to diagnose, parameters to adjust, PLC programs to check, logs to review, restart procedures to oversee, or supplier support to coordinate. Each site visit represents a direct cost, but also an opportunity cost: the technician is unavailable for other sites, the diagnosis begins later, and production sometimes remains in degraded mode.
The challenges are very real.
-
A nighttime on-call response may tie up a technician for several hours for a task that takes only a few minutes once connected to the HMI or PLC.
-
Travel time significantly reduces actual efficiency: a two-hour drive for a twenty-minute diagnosis creates an invisible burden on schedules.
-
Long response times prolong downtime or reduced operational capacity: the site has to wait for the right person to physically arrive.
-
Remote sites are less well served, because a technician cannot effectively maintain a dispersed fleet solely by traveling to each location.
-
Rare experts—such as automation engineers specializing in Siemens, Schneider, or Rockwell—become bottlenecks.
-
Emergency calls increase fatigue, stress, and travel-related risks.
-
External service providers sometimes have to travel to the site, even though temporary, monitored access would have allowed for a quick diagnosis.
-
The carbon footprint of maintenance-related travel is becoming a key management issue for organizations with multiple locations.
Industrial remote access makes it possible to change the approach: diagnose first, and only travel to the site if physical intervention is truly necessary.
Which Trips Can Be Avoided
Not all travel can be avoided. The best approach is to categorize activities by type.
| Type of procedure | Can be performed remotely | Example |
|---|---|---|
| PLC diagnostics | Yes | Read CPU, module, and communication faults |
| HMI or SCADA monitoring | Yes | View alarms, trends, and statuses |
| Parameter adjustment | Yes, depending on procedure | Modify thresholds, timeouts, and setpoints |
| Manufacturer support | Yes | Grant temporary access to an expert |
| Software restart | Yes, if authorized | Restart service, IP equipment, or tunnel |
| Hardware replacement | No | Sensor, drive, power supply, contactor |
| Mechanical inspection | No | Bearings, alignment, leaks, wear |
| Electrical lockout | No | On-site safety intervention |
| Critical process validation | Partially | Prepare and assist, but validate locally |
The benefit often comes from the initial diagnosis. Even when an on-site visit is still necessary, remote access ensures that we arrive with the right part, the right expert, and the right procedure.
Our Approach
Eziwan establishes a secure remote connection between the technician and authorized equipment at the industrial site. Through a gateway, the technician can access PLCs, HMIs, SCADA systems, managed switches, IP surveillance cameras, network analyzers, or data loggers, depending on the defined permissions.
Access is not an open VPN available to the entire network. It is designed to be controlled, logged, and revocable.
-
Access to PLCs using industry-specific tools: TIA Portal, STEP 7, EcoStruxure Control Expert, Unity Pro, Studio 5000, GX Works, or other software depending on the system.
-
HMI and SCADA access: View alarms, trends, statuses, logs, and real-time values.
-
Access to IP equipment useful for diagnostics: managed switches, monitoring cameras, data loggers, network analyzers, Modbus or OPC UA gateways.
-
Registered accounts: Each technician or service provider is identified.
-
Fees by site, zone, equipment, and duration.
-
Encrypted connections via an industrial VPN or a secure tunnel.
-
Service logs: user identity, time, duration, affected resource, and access events.
-
Temporary access for an external expert, with automatic expiration.
This approach integrates with the Eziwan gateway, industrial connectivity architectures, and monitoring via the Eziwan cloud.
Architecture of an Industrial Remote Access System
A robust architecture separates the remote user, the access platform, and the site’s OT network. The gateway enforces access rules and logs connections.
The OT network is not directly exposed to the Internet. Data flows pass through a control point that restricts access to only what is strictly necessary.
Access to Functional PLCs
The value of a remote access solution is measured by its compatibility with the tools used by automation engineers. Technicians must be able to work with the software already available in their environment.
Examples of usage:
-
Read the status of a Siemens S7-1200 or S7-1500 PLC using TIA Portal.
-
Diagnose a PROFINET communication issue.
-
View a Schneider M340 or M580 program using Control Expert.
-
Monitor a Rockwell ControlLogix or CompactLogix controller using Studio 5000.
-
Test a Modbus/TCP, EtherNet/IP, or OPC UA communication session.
-
Read alarms from an HMI.
-
Check the status of a drive, gateway, or I/O module.
Access must remain controlled: an automation engineer does not need to view the entire industrial network if the task involves a single line or a single machine.
Real-time Alarm Monitoring
Many service calls begin with a vague report: “The line won’t start,” “The HMI is displaying an error,” “The pump is in safety mode,” “The drive is unresponsive.” Remote access allows you to quickly check the HMI, SCADA system, or PLC data to assess the severity of the issue.
Remotely, the technician can often:
-
Identify the specific alarm.
-
Check whether the defect is still active.
-
View recent history.
-
Check the process values.
-
Compare the status of the sensors.
-
Confirm whether a restart is permitted.
-
Determine whether a part or an on-site visit is necessary.
This initial analysis reduces unnecessary travel and improves the trips that are still necessary.
Simultaneous Multi-Device Access
Industrial diagnostics rarely involve a single piece of equipment. A PLC malfunction can be caused by a switch, a drive, a network sensor, an HMI, a local server, or a camera. A secure tunnel to the site allows simultaneous access to authorized resources.
| Equipment | Diagnostic use |
|---|---|
| PLC | Faults, program status, modules, variables |
| HMI | Alarms, acknowledgments, operator status |
| SCADA | Trends, events, history |
| Managed switch | Ports, errors, topology, VLAN |
| IP Camera | Visual inspection without leaving the site |
| Network Analyzer | Voltage, current, power quality |
| Data Logger | Local history and measurements |
| Modbus Gateway | Field communication status |
This comprehensive approach reduces the number of incomplete diagnoses. It also prevents sending a technician without knowing whether the problem is electrical, network-related, PLC-related, or process-related.
Mobile Access for Rapid Diagnostics
An on-call technician isn’t always at their workstation. Mobile access can help them quickly assess an alert: view a dashboard, check the status of a site, review an alarm, or initiate the appropriate response.
Mobile usage must remain appropriate.
-
Viewing alerts.
-
Condition check.
-
Access to a web-based user interface, if it is designed for that purpose.
-
Escalate to an expert.
-
Confirmation that travel is necessary.
Sensitive operations, such as modifying a PLC program, must be carried out in accordance with company procedures and performed from a designated workstation.
Automatic Service Logs
Remote access logs provide a level of traceability that manual on-site interventions do not always offer. They make it possible to determine who logged in, when, for how long, and to which resource.
A useful log should contain:
-
Technician’s identity.
-
Organization or role.
-
Site in question.
-
Start and end times.
-
Resources reached.
-
Access rule used.
-
Attempts rejected.
-
Temporary access granted to an expert.
-
Events leading to revocation or expiration.
These logs are useful for maintenance contracts, internal audits, NIS2 or IEC 62443 compliance efforts, and the analysis of recurring failures.
Session Sharing with a Remote Expert
When a problem goes beyond the local level, it is often necessary to bring in a construction expert, a senior automation engineer, or a process specialist. Without remote access, that expert must travel to the site or guide the team without being there in person.
With temporary access:
-
The expert is granted access limited to the site and the duration of the assignment.
-
The site or maintenance manager may be notified.
-
Actions are logged.
-
Access expires automatically.
-
The local team can monitor the diagnosis at the same time.
This model makes it possible to tap into the right expertise without creating permanent access.
Proactive Alerts and Preventive Maintenance
Reducing travel doesn’t just mean handling issues remotely. It also means preventing emergencies. Proactive alerts help detect deviations before they require immediate action.
Examples of useful alerts:
-
Loss of communication with a PLC.
-
Weak 4G signal in a remote location.
-
Temperature, vibration, or current above a threshold.
-
Recurring fault in a drive.
-
Loss of a Modbus device.
-
Unusual reboot of a gateway.
-
High network error rate on a switch.
-
Unstable VPN tunnel.
These alerts make it possible to plan actions: remote diagnostics, adjustments, part preparation, batch maintenance, or targeted on-site visits.
Calculating the ROI of Industrial Remote Maintenance
The ROI of remote access depends on the number of sites, the frequency of on-site visits, the average travel cost, the downtime avoided, and the remote resolution rate. Generic promises should be avoided; calculations should be based on the organization’s specific data.
Simple formula:
gain_annuel = interventions_evitees * cout_moyen_deplacement
+ heures_arret_evitees * cout_horaire_arret
- cout_solution
Example of parameters to enter:
| Parameter | Example to be adapted |
|---|---|
| Number of sites | 50 |
| Service calls per site per year | 6 |
| Percentage of calls that can be resolved remotely | 30% |
| Average travel cost | €450 |
| Downtime avoided per intervention | 0.5 h |
| Hourly downtime cost | Varies by line or process |
| Solution cost | Subscription, gateway, deployment |
An ROI dashboard must distinguish between interventions that were actually avoided, those that were better prepared, and those that remained physical. It is this distinction that makes the calculation credible.
Example of an ROI Dashboard
| Indicator | What it measures |
|---|---|
| Remote interventions | Number of actions performed without on-site visits |
| Avoided on-site visits | Interventions that would have required an on-site presence |
| Better-prepared on-site visits | On-site interventions with prior diagnosis |
| Average diagnosis time | Time between alert and assessment |
| Avoided downtime | Estimate validated with production |
| Avoided travel costs | Transportation, on-call fees, technician time |
| Most active sites | Prioritization of improvements |
| Experts called upon | Measurement of temporary access |
| Remote resolution rate | Effectiveness of remote maintenance |
| Emissions avoided | Estimate based on trips not taken |
These metrics help justify the investment to management and also help improve the maintenance organization.
Safety: An Essential Requirement
Poorly designed industrial remote access can increase cyber risk. Reducing travel should never result in exposing a PLC, HMI, or RDP directly to the Internet.
The best practices are as follows.
-
No OT services are publicly exposed.
-
Individual accounts for each technician.
-
Strong authentication for remote access.
-
Rights are limited by location, equipment, and duration.
-
Temporary windows for service providers.
-
Connection logging.
-
Quick revocation of access.
-
Segmentation between IT, DMZ, and OT.
-
Notifications to the site manager.
-
Periodic review of rights.
This approach aligns with zero-trust principles and the traceability requirements expected in modern industrial environments.
Phased Rollout
An industrial remote access project should start with the sites and use cases that provide the most value, without trying to cover everything right away.
| Step | Objective | Expected Result |
|---|---|---|
| Inventory | Identify existing sites, PLCs, HMIs, and access points | Initial mapping |
| Pilot | Test a few representative sites | Technical and security validation |
| Profiles | Define permissions by role | Controlled access |
| Logs | Enable logging and notifications | Traceability |
| Expansion | Deploy by region or machine family | Progressive coverage |
| ROI | Measure travel avoided | Quantified justification |
| Optimization | Adjust permissions, alerts, and procedures | Sustainable operation |
The pilot must include the actual industry tools: TIA Portal, Control Expert, Studio 5000, web HMI, monitoring, and network diagnostics.
Pre-Production Checklist
| Control | Question | Priority |
|---|---|---|
| Inventory | Is accessible equipment listed? | High |
| Permissions | Do users have named accounts? | High |
| MFA | Is strong authentication enabled? | High |
| Segmentation | Is access limited to necessary resources? | High |
| Logs | Are connections logged? | High |
| Notification | Is the site notified of external access? | Medium |
| Revocation | Can access be revoked immediately? | High |
| Business Tests | Do automated software tools work remotely? | High |
| Procedures | Are authorized remote actions defined? | High |
| ROI | Are avoided travel costs measured? | Medium |
This checklist helps avoid the pitfall of an overly broad VPN, which works technically but unnecessarily exposes the OT network.
Common Mistakes to Avoid
Set up a VPN to the entire OT network
A general-purpose VPN may provide access to far more devices than necessary. Access rights should be restricted by site, zone, PLC, HMI, and duration.
Removing field operations too quickly
Remote access is a diagnostic and optimization tool. It does not replace physical inspections, safety procedures, lockout/tagout procedures, or mechanical work.
Do not track contractor access
A service provider can work remotely effectively, but their access must be personalized, temporary, limited, and logged.
Neglecting business tools
Remote access must be tested using the actual software. A simple network connection does not guarantee that TIA Portal, Studio 5000, or a web-based HMI will function properly in the field environment.
Do not measure the gain
Without proper metrics, remote access is still viewed as merely a technical convenience. By tracking the trips it helps avoid, it becomes an economic and operational driver.
How Eziwan Reduces Field Trips
| Need | Eziwan’s Response | Benefit |
|---|---|---|
| Quick diagnosis | Remote access to PLCs, HMIs, and SCADA | Shorter wait times before troubleshooting |
| Avoid unnecessary travel | View alarms and statuses | Fewer business trips |
| Call in an expert | Temporary external access | Expertise without travel |
| Secure access | VPN, MFA, limited permissions | No direct exposure of the OT |
| Track interventions | Access logs | Audits and maintenance contracts |
| Prevent emergencies | Proactive alerts | Better-planned interventions |
| Measure ROI | Intervention dashboard | Economic justification |
| Deploy across multiple sites | Eziwan gateway and cloud | Scalable maintenance |
Eziwan transforms remote access into a business tool: diagnostics, security, traceability, collaboration, and cost management.
Conclusion
Reducing on-site travel through industrial remote access does not mean performing maintenance “remotely at any cost.” It means diagnosing issues faster, mobilizing the right expertise, avoiding unnecessary trips, better preparing for on-site interventions, and securing access to OT equipment.
With an Eziwan gateway, encrypted tunnels, named accounts, restricted access rights, intervention logs, temporary expert access, and an ROI dashboard, maintenance teams can significantly reduce travel while improving responsiveness. For multi-site fleets, OEMs, and industrial operators, this is a practical way to save time, reduce costs, and ensure reliable operations.
Further Reading
- Industrial Remote Diagnostics — diagnose and resolve issues remotely without sending a technician
- Monitoring and Remote Assistance — combine proactive alerts and remote assistance for your teams
- Industrial Remote Access — securely access your PLCs and HMIs from anywhere
- IIoT Predictive Maintenance — Anticipate failures to plan maintenance and avoid emergencies
- Calculate Your ROI — Estimate the savings achieved by reducing field trips