Field Note • Remote Access Governance
Governing Remote Vendor Access in Battery Storage Environments
In virtually every grid-scale battery storage facility operating today, third-party remote access represents the single largest cyber exposure vector. Battery OEMs, inverter manufacturers, and cooling system suppliers routinely require 24/7 network connectivity to honor capacity warranties and performance guarantees. The standard industry response—handing out permanent site-to-site VPN tunnels—creates catastrophic systemic risk.
The Warranty Paradox in Modern Energy Storage
Unlike conventional thermal power plants where equipment is purchased outright and maintained by on-site utility personnel, battery storage economics depend on 10- to 20-year Long-Term Service Agreements (LTSAs) and Capacity Maintenance Agreements (CMAs).
To validate battery degradation rates, monitor state of health (SoH), and perform predictive cell balancing, OEMs contractually mandate continuous remote access to the site's Battery Management System (BMS) and Energy Management System (EMS). If the asset owner disconnects or restricts this access, the OEM may void the multimillion-dollar capacity warranty.
Asset owners are caught in a false dilemma: maintain an unmonitored remote access backdoor to preserve the warranty, or sever connectivity and assume unhedged financial liability for battery degradation.
The Failure of Legacy Remote Access Approaches
When reviewing operating BESS sites, our engineering team consistently observes four critical remote-access anti-patterns:
1. Unmanaged Cellular Backdoors
When corporate IT or site firewalls delay access during commissioning, vendor technicians frequently install unmanaged 4G/5G cellular modems directly into inverter skids or battery containers. These modems bypass all corporate firewalls, IDS systems, and authentication controls, providing direct, unmonitored ingress from the public internet into Level 1/Level 2 OT subnets.
2. Static, Persistent Site-to-Site VPN Tunnels
Where formal access exists, it typically consists of an IPsec or OpenVPN tunnel established between the vendor's corporate network and the site's industrial switch. This creates a bridge between two enterprise networks. If a phishing attacker compromises an employee workstation at the vendor's corporate headquarters, they can traverse the persistent VPN directly into high-voltage battery control networks.
3. Shared, Unattributed Credentials
Service accounts are frequently shared among dozens of vendor field engineers, contractors, and offshore diagnostic teams (e.g., admin or service_tech). When an incident or parameter change occurs, the asset owner cannot attribute the action to a specific individual or verify whether the session was authorized.
4. Lack of Protocol-Level Command Visibility
Standard VPNs provide packet transport, not application governance. Once connected via VPN, a vendor technician can issue any command to any reachable controller. A technician ostensibly connecting to inspect an HVAC chiller fan can simultaneously write Modbus registers to the battery master BMS without detection.
The Zero-Standing-Access Architecture for BESS
Battery Cyber Control resolves the warranty paradox by establishing a Zero-Standing-Access Governance Framework specifically designed for OT environments:
A. Just-In-Time (JIT) Ephemeral Credentials
Eliminate all permanent, static VPN connections. When an OEM or maintenance provider needs to perform diagnostics, they submit an access request specifying:
- The technician's verified individual identity (MFA-authenticated)
- The specific work order or maintenance ticket
- The exact physical devices requiring access (e.g., Inverter Skid 04 only)
- The approved maintenance window duration (e.g., 2 hours)
Upon dual authorization by the site operator, the access gateway generates ephemeral credentials that automatically expire when the window closes.
B. Micro-Segmented Protocol Proxying
The remote technician never receives Layer 3 network routing into the site switch. Instead, all traffic terminates at a hardened access gateway. The gateway proxies only the specific protocols and ports required for the authorized task (e.g., HTTPS for an inverter web console or Modbus TCP for a specific slave ID), completely blocking lateral movement to adjacent controllers.
C. Dual-Layer Session Auditing (Visual & Protocol)
Every session is recorded at both levels:
- Visual / Terminal Recording: Complete video playback of graphical RDP sessions and full keystroke logs of SSH terminals.
- Protocol Command Decapsulation: Every Modbus, DNP3, or proprietary API command sent through the proxy is decoded, logged, and timestamped. Any attempt to write to critical safety registers outside the work order scope triggers instant alerts or automated session termination.
Conclusion
Protecting critical energy storage assets does not require terminating OEM vendor relationships or voiding capacity warranties. By transitioning from persistent, unmonitored VPN tunnels to Just-In-Time, protocol-aware access governance, asset owners can satisfy warranty monitoring obligations while maintaining total control over their operational cyber boundary.
Audit your third-party and OEM remote access footprint
Battery Cyber conducts comprehensive remote-access exposure reviews for utility and data center power installations.
Discuss an environment