Technical Guide

Reducing on-site travel by 60% through industrial remote access

Reduce maintenance trips with secure remote access to PLCs, HMIs, and OT equipment: VPN, logs, ROI, and best practices.

Reducing industrial maintenance travel does not mean replacing all on-site visits with remote diagnostics. Certain operations still require a physical presence: part replacement, lockout/tagout, mechanical inspections, on-site measurements, or safety-related work. However, a large portion of diagnostics, acknowledgments, verifications, parameter adjustments, alarm analyses, and manufacturer support can be performed remotely when technicians have secure access to the site’s PLCs, HMIs, SCADA systems, and IP-based equipment.

The Problem

In industry, maintaining automated equipment involves a great deal of travel: alarms to address, faults to diagnose, parameters to adjust, PLC programs to check, logs to review, restart procedures to oversee, or supplier support to coordinate. Each site visit represents a direct cost, but also an opportunity cost: the technician is unavailable for other sites, the diagnosis begins later, and production sometimes remains in degraded mode.

The challenges are very real.

  • A nighttime on-call response may tie up a technician for several hours for a task that takes only a few minutes once connected to the HMI or PLC.

  • Travel time significantly reduces actual efficiency: a two-hour drive for a twenty-minute diagnosis creates an invisible burden on schedules.

  • Long response times prolong downtime or reduced operational capacity: the site has to wait for the right person to physically arrive.

  • Remote sites are less well served, because a technician cannot effectively maintain a dispersed fleet solely by traveling to each location.

  • Rare experts—such as automation engineers specializing in Siemens, Schneider, or Rockwell—become bottlenecks.

  • Emergency calls increase fatigue, stress, and travel-related risks.

  • External service providers sometimes have to travel to the site, even though temporary, monitored access would have allowed for a quick diagnosis.

  • The carbon footprint of maintenance-related travel is becoming a key management issue for organizations with multiple locations.

Industrial remote access makes it possible to change the approach: diagnose first, and only travel to the site if physical intervention is truly necessary.

Which Trips Can Be Avoided

Not all travel can be avoided. The best approach is to categorize activities by type.

Type of procedureCan be performed remotelyExample
PLC diagnosticsYesRead CPU, module, and communication faults
HMI or SCADA monitoringYesView alarms, trends, and statuses
Parameter adjustmentYes, depending on procedureModify thresholds, timeouts, and setpoints
Manufacturer supportYesGrant temporary access to an expert
Software restartYes, if authorizedRestart service, IP equipment, or tunnel
Hardware replacementNoSensor, drive, power supply, contactor
Mechanical inspectionNoBearings, alignment, leaks, wear
Electrical lockoutNoOn-site safety intervention
Critical process validationPartiallyPrepare and assist, but validate locally

The benefit often comes from the initial diagnosis. Even when an on-site visit is still necessary, remote access ensures that we arrive with the right part, the right expert, and the right procedure.

Our Approach

Eziwan establishes a secure remote connection between the technician and authorized equipment at the industrial site. Through a gateway, the technician can access PLCs, HMIs, SCADA systems, managed switches, IP surveillance cameras, network analyzers, or data loggers, depending on the defined permissions.

Access is not an open VPN available to the entire network. It is designed to be controlled, logged, and revocable.

  • Access to PLCs using industry-specific tools: TIA Portal, STEP 7, EcoStruxure Control Expert, Unity Pro, Studio 5000, GX Works, or other software depending on the system.

  • HMI and SCADA access: View alarms, trends, statuses, logs, and real-time values.

  • Access to IP equipment useful for diagnostics: managed switches, monitoring cameras, data loggers, network analyzers, Modbus or OPC UA gateways.

  • Registered accounts: Each technician or service provider is identified.

  • Fees by site, zone, equipment, and duration.

  • Encrypted connections via an industrial VPN or a secure tunnel.

  • Service logs: user identity, time, duration, affected resource, and access events.

  • Temporary access for an external expert, with automatic expiration.

This approach integrates with the Eziwan gateway, industrial connectivity architectures, and monitoring via the Eziwan cloud.

Architecture of an Industrial Remote Access System

A robust architecture separates the remote user, the access platform, and the site’s OT network. The gateway enforces access rules and logs connections.

The OT network is not directly exposed to the Internet. Data flows pass through a control point that restricts access to only what is strictly necessary.

Access to Functional PLCs

The value of a remote access solution is measured by its compatibility with the tools used by automation engineers. Technicians must be able to work with the software already available in their environment.

Examples of usage:

  • Read the status of a Siemens S7-1200 or S7-1500 PLC using TIA Portal.

  • Diagnose a PROFINET communication issue.

  • View a Schneider M340 or M580 program using Control Expert.

  • Monitor a Rockwell ControlLogix or CompactLogix controller using Studio 5000.

  • Test a Modbus/TCP, EtherNet/IP, or OPC UA communication session.

  • Read alarms from an HMI.

  • Check the status of a drive, gateway, or I/O module.

Access must remain controlled: an automation engineer does not need to view the entire industrial network if the task involves a single line or a single machine.

Real-time Alarm Monitoring

Many service calls begin with a vague report: “The line won’t start,” “The HMI is displaying an error,” “The pump is in safety mode,” “The drive is unresponsive.” Remote access allows you to quickly check the HMI, SCADA system, or PLC data to assess the severity of the issue.

Remotely, the technician can often:

  • Identify the specific alarm.

  • Check whether the defect is still active.

  • View recent history.

  • Check the process values.

  • Compare the status of the sensors.

  • Confirm whether a restart is permitted.

  • Determine whether a part or an on-site visit is necessary.

This initial analysis reduces unnecessary travel and improves the trips that are still necessary.

Simultaneous Multi-Device Access

Industrial diagnostics rarely involve a single piece of equipment. A PLC malfunction can be caused by a switch, a drive, a network sensor, an HMI, a local server, or a camera. A secure tunnel to the site allows simultaneous access to authorized resources.

EquipmentDiagnostic use
PLCFaults, program status, modules, variables
HMIAlarms, acknowledgments, operator status
SCADATrends, events, history
Managed switchPorts, errors, topology, VLAN
IP CameraVisual inspection without leaving the site
Network AnalyzerVoltage, current, power quality
Data LoggerLocal history and measurements
Modbus GatewayField communication status

This comprehensive approach reduces the number of incomplete diagnoses. It also prevents sending a technician without knowing whether the problem is electrical, network-related, PLC-related, or process-related.

Mobile Access for Rapid Diagnostics

An on-call technician isn’t always at their workstation. Mobile access can help them quickly assess an alert: view a dashboard, check the status of a site, review an alarm, or initiate the appropriate response.

Mobile usage must remain appropriate.

  • Viewing alerts.

  • Condition check.

  • Access to a web-based user interface, if it is designed for that purpose.

  • Escalate to an expert.

  • Confirmation that travel is necessary.

Sensitive operations, such as modifying a PLC program, must be carried out in accordance with company procedures and performed from a designated workstation.

Automatic Service Logs

Remote access logs provide a level of traceability that manual on-site interventions do not always offer. They make it possible to determine who logged in, when, for how long, and to which resource.

A useful log should contain:

  • Technician’s identity.

  • Organization or role.

  • Site in question.

  • Start and end times.

  • Resources reached.

  • Access rule used.

  • Attempts rejected.

  • Temporary access granted to an expert.

  • Events leading to revocation or expiration.

These logs are useful for maintenance contracts, internal audits, NIS2 or IEC 62443 compliance efforts, and the analysis of recurring failures.

Session Sharing with a Remote Expert

When a problem goes beyond the local level, it is often necessary to bring in a construction expert, a senior automation engineer, or a process specialist. Without remote access, that expert must travel to the site or guide the team without being there in person.

With temporary access:

  • The expert is granted access limited to the site and the duration of the assignment.

  • The site or maintenance manager may be notified.

  • Actions are logged.

  • Access expires automatically.

  • The local team can monitor the diagnosis at the same time.

This model makes it possible to tap into the right expertise without creating permanent access.

Proactive Alerts and Preventive Maintenance

Reducing travel doesn’t just mean handling issues remotely. It also means preventing emergencies. Proactive alerts help detect deviations before they require immediate action.

Examples of useful alerts:

  • Loss of communication with a PLC.

  • Weak 4G signal in a remote location.

  • Temperature, vibration, or current above a threshold.

  • Recurring fault in a drive.

  • Loss of a Modbus device.

  • Unusual reboot of a gateway.

  • High network error rate on a switch.

  • Unstable VPN tunnel.

These alerts make it possible to plan actions: remote diagnostics, adjustments, part preparation, batch maintenance, or targeted on-site visits.

Calculating the ROI of Industrial Remote Maintenance

The ROI of remote access depends on the number of sites, the frequency of on-site visits, the average travel cost, the downtime avoided, and the remote resolution rate. Generic promises should be avoided; calculations should be based on the organization’s specific data.

Simple formula:

gain_annuel = interventions_evitees * cout_moyen_deplacement
+ heures_arret_evitees * cout_horaire_arret
- cout_solution

Example of parameters to enter:

ParameterExample to be adapted
Number of sites50
Service calls per site per year6
Percentage of calls that can be resolved remotely30%
Average travel cost€450
Downtime avoided per intervention0.5 h
Hourly downtime costVaries by line or process
Solution costSubscription, gateway, deployment

An ROI dashboard must distinguish between interventions that were actually avoided, those that were better prepared, and those that remained physical. It is this distinction that makes the calculation credible.

Example of an ROI Dashboard

IndicatorWhat it measures
Remote interventionsNumber of actions performed without on-site visits
Avoided on-site visitsInterventions that would have required an on-site presence
Better-prepared on-site visitsOn-site interventions with prior diagnosis
Average diagnosis timeTime between alert and assessment
Avoided downtimeEstimate validated with production
Avoided travel costsTransportation, on-call fees, technician time
Most active sitesPrioritization of improvements
Experts called uponMeasurement of temporary access
Remote resolution rateEffectiveness of remote maintenance
Emissions avoidedEstimate based on trips not taken

These metrics help justify the investment to management and also help improve the maintenance organization.

Safety: An Essential Requirement

Poorly designed industrial remote access can increase cyber risk. Reducing travel should never result in exposing a PLC, HMI, or RDP directly to the Internet.

The best practices are as follows.

  • No OT services are publicly exposed.

  • Individual accounts for each technician.

  • Strong authentication for remote access.

  • Rights are limited by location, equipment, and duration.

  • Temporary windows for service providers.

  • Connection logging.

  • Quick revocation of access.

  • Segmentation between IT, DMZ, and OT.

  • Notifications to the site manager.

  • Periodic review of rights.

This approach aligns with zero-trust principles and the traceability requirements expected in modern industrial environments.

Phased Rollout

An industrial remote access project should start with the sites and use cases that provide the most value, without trying to cover everything right away.

StepObjectiveExpected Result
InventoryIdentify existing sites, PLCs, HMIs, and access pointsInitial mapping
PilotTest a few representative sitesTechnical and security validation
ProfilesDefine permissions by roleControlled access
LogsEnable logging and notificationsTraceability
ExpansionDeploy by region or machine familyProgressive coverage
ROIMeasure travel avoidedQuantified justification
OptimizationAdjust permissions, alerts, and proceduresSustainable operation

The pilot must include the actual industry tools: TIA Portal, Control Expert, Studio 5000, web HMI, monitoring, and network diagnostics.

Pre-Production Checklist

ControlQuestionPriority
InventoryIs accessible equipment listed?High
PermissionsDo users have named accounts?High
MFAIs strong authentication enabled?High
SegmentationIs access limited to necessary resources?High
LogsAre connections logged?High
NotificationIs the site notified of external access?Medium
RevocationCan access be revoked immediately?High
Business TestsDo automated software tools work remotely?High
ProceduresAre authorized remote actions defined?High
ROIAre avoided travel costs measured?Medium

This checklist helps avoid the pitfall of an overly broad VPN, which works technically but unnecessarily exposes the OT network.

Common Mistakes to Avoid

Set up a VPN to the entire OT network

A general-purpose VPN may provide access to far more devices than necessary. Access rights should be restricted by site, zone, PLC, HMI, and duration.

Removing field operations too quickly

Remote access is a diagnostic and optimization tool. It does not replace physical inspections, safety procedures, lockout/tagout procedures, or mechanical work.

Do not track contractor access

A service provider can work remotely effectively, but their access must be personalized, temporary, limited, and logged.

Neglecting business tools

Remote access must be tested using the actual software. A simple network connection does not guarantee that TIA Portal, Studio 5000, or a web-based HMI will function properly in the field environment.

Do not measure the gain

Without proper metrics, remote access is still viewed as merely a technical convenience. By tracking the trips it helps avoid, it becomes an economic and operational driver.

How Eziwan Reduces Field Trips

NeedEziwan’s ResponseBenefit
Quick diagnosisRemote access to PLCs, HMIs, and SCADAShorter wait times before troubleshooting
Avoid unnecessary travelView alarms and statusesFewer business trips
Call in an expertTemporary external accessExpertise without travel
Secure accessVPN, MFA, limited permissionsNo direct exposure of the OT
Track interventionsAccess logsAudits and maintenance contracts
Prevent emergenciesProactive alertsBetter-planned interventions
Measure ROIIntervention dashboardEconomic justification
Deploy across multiple sitesEziwan gateway and cloudScalable maintenance

Eziwan transforms remote access into a business tool: diagnostics, security, traceability, collaboration, and cost management.

Conclusion

Reducing on-site travel through industrial remote access does not mean performing maintenance “remotely at any cost.” It means diagnosing issues faster, mobilizing the right expertise, avoiding unnecessary trips, better preparing for on-site interventions, and securing access to OT equipment.

With an Eziwan gateway, encrypted tunnels, named accounts, restricted access rights, intervention logs, temporary expert access, and an ROI dashboard, maintenance teams can significantly reduce travel while improving responsiveness. For multi-site fleets, OEMs, and industrial operators, this is a practical way to save time, reduce costs, and ensure reliable operations.

Further Reading

Frequently Asked Questions

You might also like