Monthly Buzz - September - Privileged Remote Access
How to Strengthen Your Microsoft Defenses in 2026: Security Recommendations
Relying entirely on patching or simple fixes is an inadequate defense strategy. Remediation must be paired with proactive architectural guardrails. Implement a multilayered defense-in-depth model built on these key report recommendations:
-
Tailor vulnerability management to your environment and move away from a one-size-fits-all approach. Prioritize security updates based on your unique environment, ensure your operating system and third-party software are up-to-date, and avoid using end-of-life software.
-
Implement least privilege and zero trust controls across the stack. Restricting privilege across network, identity, account, cloud, and application layers provides a safety net that limits lateral movement and the blast radius of zero day exploits.
-
Secure remote access pathways by replacing common entry points such as RDP and VPNs. Enforce authentication and session monitoring to detect misuse early.
-
Implement identity threat detection and response (ITDR) to gain a complete understanding of each human and non-human identity’s effective privileges, enabling you to see the attack paths within your environment and identify which steps are needed to improve identity security posture.
-
Prepare for the next frontier of threats by taking a holistic look at your hybrid environment and understanding the possible privilege escalation pathways that could be exposed if a vulnerability were exploited or an identity compromised.
Continue Reading HERE
Securing Remote Access to Water and Wastewater OT Systems
Water and wastewater utilities need remote access to operate and maintain distributed OT infrastructure, but that access shouldn’t require exposing critical systems to the public internet. Learn how utilities can identify risky attack paths and build a secure remote access model around individual identity, MFA, protected credentials, time-bound access, and complete session accountability.
Remote Access Is Necessary. Internet Exposure Isn't.
Recent attacks on water and wastewater systems have highlighted a longstanding risk associated with internet-exposed PLCs and other operational technology (see Water and Wastewater Cyberattacks Are Escalating: What State and Local Leaders Should Do Now for the full incident details and immediate remediation steps). Removing those systems from the public internet is an important first step, but it doesn't eliminate the need for remote access. Operators, vendors, and integrators still need a secure way to reach and manage them.
Water and wastewater utilities and other critical infrastructure depend on remote access to operate and maintain distributed systems. Operators, engineers, equipment manufacturers, and third-party integrators need to access PLCs, HMIs, and other systems that may be located miles from the nearest staffed facility.
That operational need isn't going away, but the same connectivity that enables remote maintenance can also create a path into critical OT systems. The challenge is to provide that access without exposing device login pages to the internet, relying on shared passwords, or giving users broader access to the OT network than they need.
In this blog, I look at what a secure remote access model can look like for water and wastewater OT, and how individual utilities or states can put that model into practice.
The Remote Access Problem
Water and wastewater systems are distributed by design. Pump stations, remote wells, treatment facilities, and other infrastructure may be spread across large geographic areas, and utilities can't have an operator or technician physically present at every location. Remote access allows utility personnel, equipment manufacturers, and third-party integrators to maintain and troubleshoot PLCs, HMIs, gateways, and other operational systems when on-site access isn't practical.
The challenge is that many utilities are managing this access with aging technology, limited funding, and small workforces. As GAO testified to Congress in May 2026, these constraints can make it difficult for utilities to address cybersecurity risks across distributed environments.
Adding more staff isn't a realistic answer for many utilities. Remote access needs to be designed so the people responsible for operating and maintaining these systems can reach what they need without requiring the systems themselves to be directly exposed to the internet.
Get a closer look at the threats facing water and wastewater systems and GAO's finding
Continue Reading HERE
Customer Case Study
Karma Automotive Strengthens Support and Saves $600,000 in Labor Costs with BeyondTrust
Latest Available Version:
Privileged Remote Access 26.2.3 – September, 2026
Privileged Remote Access 26.2.2 - August, 2026
Beekeepers Hot Topics:
Cimplicity Webspace in PRA
We have Cimplicity Webspace in our environment, which is web based. The main dashboard does not have a login screen, but each page off of the main page is an embedded IDE object that has its own authentication. We are trying right now to run the application as a Web Jump, but Web Jump does not see the authentication fields because they are in the embedded IDE and not HTML fields.
Has anyone found a way to use Cimplicity Webspace with PRA?
Click here for the most popular articles In our Beekeepers Community
Upcoming and In Case You Missed It Webinars
Road Map: Privileged Remote Access Road Map - September, 2026
User Group: 2026-Q3-Privileged Remote Access
Podcast: The Adventures of Alice & Bob: Cyber Security and the Art of story Telling
Webinars:
The Fastest Path to Administrative Control (Part 2)
Privileged Access, Mapped to the Frameworks Behind Your Audit
Monitoring, Threat Hunting and Detection of Privilege Abuse (Part 3)
Understanding Entra Privileged Identity Management, What PIM Covers and Where It Stops -October 1, 2026
Identity Visibility & Intelligence: The Missing Layer in Modern Identity Security – October 21, 2026
Battling Identity Security Blind Spots – November 10, 2026





