Interview with Felix Wirthmann from TeamViewer

What advantages agentless access offers in OT

Why is agentless access becoming relevant for OT systems? In the interview, Felix Wirthmann, Director Product Management at TeamViewer, explains how secure remote access to OT systems works without software installation on the endpoint.

Published
Agentenlos bedeutet bei TeamViewer, dass auf dem Endpunkt im Firmennetzwerk keine Installation erforderlich ist. Der Zugriff erfolgt stattdessen über ein vorgeschaltetes Gateway. Dieses ermöglicht den sicheren, „Zero Trust“-basierten Fernzugriff.
Agentless means at TeamViewer that no installation is required on the endpoint in the company network. Access instead takes place via an upstream gateway. This enables secure, “zero trust”-based remote access.

Summary: TeamViewer sees NIS-2, the EU Cyber Resilience Act, and increasing cyberattacks as central drivers for secure OT remote access. Agentless Access is intended to enable targeted, role-based access to PLCs, HMIs, and legacy systems via an upstream gateway. The cooperation with Bechtle and Kontron combines software, industrial hardware, and managed services for production environments.

Why is secure remote access to OT systems so relevant for industry right now? 

Felix Wirthmann: The current main drivers, especially in mechanical engineering, are the NIS-2 regulations and the EU Cyber Resilience Act. Added to this is the massive increase in cyberattacks. According to an analysis by the European Union Agency for Cybersecurity ENISA, attacks are currently shifting significantly toward Operational Technology (OT) and Industrial Control Systems (ICS), in other words, industrial and critical systems.

With increasing automation, connected machines and globally distributed service teams, the need is also growing to make systems quickly and specifically accessible remotely. The shortage of skilled workers also plays a role here. Remote access in OT networks must therefore today function quickly, reliably, securely and in a controlled manner. Agentless solutions address exactly this.

Want to learn more about the German Mechanical Engineering Summit? Click here!

Which typical service or maintenance cases can be solved remotely with agentless solutions? 

Wirthmann: Agentless means that no installation is necessary on the endpoint in a company network that I want to access, for example via TeamViewer. Access instead runs through an upstream gateway that enables secure, “zero trust”-based remote access.

Typical use cases are access to OT endpoints such as PLCs, HMIs and legacy systems such as Windows XP for commissioning, conversions, reconfigurations, troubleshooting and troubleshooting as well as retrofitting.

For which typical production environments were the agentless solutions developed and how do you deal with brownfield environments, for example with old PLCs, HMIs or outdated operating systems?

Felix Wirthmann, Director Product Management bei TeamViewer.
Felix Wirthmann, Director Product Management at TeamViewer.

Wirthmann: Agentless access is designed for complex and heterogeneous OT infrastructures, from highly automated production environments to evolved brownfield landscapes. This is particularly important for the latter, because existing installations may not be changed, for example due to warranty agreements with suppliers. The agentless approach does not intervene in the endpoints and thus preserves the integrity of older or proprietary systems. The solution is specialized for use in micro-segmented networks and thus enables isolation of the OT environment.

A standardized access platform also helps to reduce single points of failure. In practice, teams can thus access networked components, all through one platform. TeamViewer's Agentless Access currently supports protocols such as VNC and SSH; additional protocols will follow.

How does the solution help companies meet requirements from NIS‑2? 

Wirthmann: Agentless Access supports segmented networks for isolating OT environments, as well as protocol isolation and termination as cybersecurity “best practices.” The solution is based on “Zero Trust” and supports strong mechanisms for authentication and role-based access control.

What distinguishes Agentless Access from classic remote maintenance or VPN solutions?

Wirthmann: Classic VPN solutions operate on the third network layer and often grant external users broad network access after authentication, which must only then be restricted afterward.

With Agentless Access, we establish point-to-point connections on the fourth layer. Individual endpoints are specifically enabled, time-limited, and controlled based on roles. This is a better fit for segmented OT networks and allows, for example, the temporary access of external service providers to individual components during a maintenance window.

At the same time, the approach helps to consolidate isolated individual solutions. IT teams have a central place to manage access, security rules, and identities consistently. This reduces the administrative effort and lowers the risk of misconfigurations.

How does agentless access work technically when no software is installed on the target systems?

Wirthmann: Access takes place through an upstream gateway as the central access point into the production network. It brokers and controls the connections to the end devices. For authorized users, access feels like a normal TeamViewer connection.

This is particularly relevant in production because machines are often tied to the manufacturer's guarantee or warranty conditions and operators therefore want to avoid changes to the end devices as much as possible.

The gateway can be implemented on a local server or as a preconfigured hardware gateway. The latter can be installed via plug-and-play in the corporate network. It is the result of a cooperation between Bechtle, Kontron and TeamViewer.

Why did TeamViewer, Bechtle and Kontron join forces for this cooperation? 

Wirthmann: The cooperation combines three complementary competencies. TeamViewer provides the software platform, Kontron supplies the industrial hardware and the hardened industrial operating system “KontronOS,” Bechtle handles provisioning, integration as well as lifecycle management as a managed service.

The result is a solution ready for immediate use from a single source that combines hardware, software and services. For companies, in practice this means faster implementation, less maintenance effort, simpler patch management and lower complexity in ongoing operations.

Sicherer Fernzugriff auf OT-Systeme gewinnt in der Industrie deutlich an Bedeutung. Aus Sicht von TeamViewer treiben vor allem neue regulatorische Anforderungen diese Entwicklung.
Secure remote access to OT systems is becoming significantly more important in industry. From TeamViewer's perspective, new regulatory requirements in particular are driving this development.

What requirements must be met in a production environment for Agentless Access to be used?

Wirthmann: For all endpoints that can be addressed from the gateway via an IP, corresponding access can be configured.

What further developments are planned for Gateway Agentless Access?

Wirthmann: We are currently working on natively supporting additional frequently used protocols. In addition, we are currently in the certification process according to the international IEC62443 standard for industrial cybersecurity.

In general, we want to make our OT solutions even more powerful and tailor them better to the realities of our target groups in this segment, for example automation teams or technical customer service.

And where are the limits of Agentless Access?

Wirthmann: It is crucial that the solution is embedded in a higher-level security and governance concept. Only in interaction with clearly defined processes, roles and access controls can secure remote access in production function sustainably. Customers must secure their network environment accordingly and restrict network-side access options and protocols.

FAQ on Agentless Access

What is Agentless Access? - Agentless Access enables remote access to OT endpoints without software installation on the target system. Access runs via an upstream gateway.

Why is Agentless Access relevant for OT systems? - Drivers are NIS-2, the EU Cyber Resilience Act, more cyberattacks on OT and ICS, as well as the need for fast, controlled remote access.

Which systems does Agentless Access support? - Mentioned are OT endpoints such as PLCs, HMIs, and legacy systems, for example Windows XP, provided they are reachable via IP from the gateway.

How does Agentless Access differ from VPN? - Instead of broad network access, Agentless Access uses targeted point-to-point connections that are time-limited and controlled based on roles.

What role does the gateway play in Agentless Access? - The gateway is the central access point into the production network and mediates and controls the connections to the end devices.

Powered by Labrador CMS