Interview with Felix Wirthmann from TeamViewer
What advantages agentless access offers in OT
Why is agentless access becoming relevant for OT systems? In the interview, Felix Wirthmann, Director Product Management at TeamViewer, explains how secure remote access to OT systems works without software installation on the endpoint.
Why is secure remote access to OT systems so relevant for industry right now?
Felix Wirthmann: The current main drivers, especially in mechanical engineering, are the NIS-2 regulations and the EU Cyber Resilience Act. Added to this is the massive increase in cyberattacks. According to an analysis by the European Union Agency for Cybersecurity ENISA, attacks are currently shifting significantly toward Operational Technology (OT) and Industrial Control Systems (ICS), in other words, industrial and critical systems.
With increasing automation, connected machines and globally distributed service teams, the need is also growing to make systems quickly and specifically accessible remotely. The shortage of skilled workers also plays a role here. Remote access in OT networks must therefore today function quickly, reliably, securely and in a controlled manner. Agentless solutions address exactly this.
Which typical service or maintenance cases can be solved remotely with agentless solutions?
Wirthmann: Agentless means that no installation is necessary on the endpoint in a company network that I want to access, for example via TeamViewer. Access instead runs through an upstream gateway that enables secure, “zero trust”-based remote access.
Typical use cases are access to OT endpoints such as PLCs, HMIs and legacy systems such as Windows XP for commissioning, conversions, reconfigurations, troubleshooting and troubleshooting as well as retrofitting.
For which typical production environments were the agentless solutions developed and how do you deal with brownfield environments, for example with old PLCs, HMIs or outdated operating systems?
Wirthmann: Agentless access is designed for complex and heterogeneous OT infrastructures, from highly automated production environments to evolved brownfield landscapes. This is particularly important for the latter, because existing installations may not be changed, for example due to warranty agreements with suppliers. The agentless approach does not intervene in the endpoints and thus preserves the integrity of older or proprietary systems. The solution is specialized for use in micro-segmented networks and thus enables isolation of the OT environment.
A standardized access platform also helps to reduce single points of failure. In practice, teams can thus access networked components, all through one platform. TeamViewer's Agentless Access currently supports protocols such as VNC and SSH; additional protocols will follow.
How does the solution help companies meet requirements from NIS‑2?
Wirthmann: Agentless Access supports segmented networks for isolating OT environments, as well as protocol isolation and termination as cybersecurity “best practices.” The solution is based on “Zero Trust” and supports strong mechanisms for authentication and role-based access control.
What distinguishes Agentless Access from classic remote maintenance or VPN solutions?
Wirthmann: Classic VPN solutions operate on the third network layer and often grant external users broad network access after authentication, which must only then be restricted afterward.
With Agentless Access, we establish point-to-point connections on the fourth layer. Individual endpoints are specifically enabled, time-limited, and controlled based on roles. This is a better fit for segmented OT networks and allows, for example, the temporary access of external service providers to individual components during a maintenance window.
At the same time, the approach helps to consolidate isolated individual solutions. IT teams have a central place to manage access, security rules, and identities consistently. This reduces the administrative effort and lowers the risk of misconfigurations.
How does agentless access work technically when no software is installed on the target systems?
Wirthmann: Access takes place through an upstream gateway as the central access point into the production network. It brokers and controls the connections to the end devices. For authorized users, access feels like a normal TeamViewer connection.
This is particularly relevant in production because machines are often tied to the manufacturer's guarantee or warranty conditions and operators therefore want to avoid changes to the end devices as much as possible.
The gateway can be implemented on a local server or as a preconfigured hardware gateway. The latter can be installed via plug-and-play in the corporate network. It is the result of a cooperation between Bechtle, Kontron and TeamViewer.
Why did TeamViewer, Bechtle and Kontron join forces for this cooperation?
Wirthmann: The cooperation combines three complementary competencies. TeamViewer provides the software platform, Kontron supplies the industrial hardware and the hardened industrial operating system “KontronOS,” Bechtle handles provisioning, integration as well as lifecycle management as a managed service.
The result is a solution ready for immediate use from a single source that combines hardware, software and services. For companies, in practice this means faster implementation, less maintenance effort, simpler patch management and lower complexity in ongoing operations.
What requirements must be met in a production environment for Agentless Access to be used?
Wirthmann: For all endpoints that can be addressed from the gateway via an IP, corresponding access can be configured.
What further developments are planned for Gateway Agentless Access?
Wirthmann: We are currently working on natively supporting additional frequently used protocols. In addition, we are currently in the certification process according to the international IEC62443 standard for industrial cybersecurity.
In general, we want to make our OT solutions even more powerful and tailor them better to the realities of our target groups in this segment, for example automation teams or technical customer service.
And where are the limits of Agentless Access?
Wirthmann: It is crucial that the solution is embedded in a higher-level security and governance concept. Only in interaction with clearly defined processes, roles and access controls can secure remote access in production function sustainably. Customers must secure their network environment accordingly and restrict network-side access options and protocols.