What Can We Do After the Industrial Control Security Incident at a Polish CHP Plant?
Recently, Polish authorities released details of a cyber intrusion at a combined heat and power (CHP) plant, which has sparked heated discussions across the industrial control sector.
According to the disclosed information, the attack disrupted the entire CHP production process using only native device functions, common industrial control protocols, and configuration oversights in daily operations and maintenance.

The incident has triggered widespread debate precisely because the attack methods are far from uncommon. The root causes — exposed VPNs, unisolated private networks, and long-term use of default device passwords — represent configurations prevalent at most domestic stations.
As one industry peer put it: "This attack path would work in eight out of ten of our domestic sites."
Looking through public discussions and comments, some share their own past security pitfalls, while others express frustration at the industry status quo. The comments clearly reflect the sector's genuine attitudes toward this incident.
For example, some argue that "physical isolation is the only foolproof security measure", and even go so far as to say "remote networking is inherently unsafe and should be avoided entirely".
But reality offers no such option. Wind and photovoltaic power stations often have hundreds of units scattered across dozens of kilometers. Relying solely on on-site O&M is unsustainable in terms of both cost and time, making remote networked O&M the industry standard.
So, how can enterprises prevent incidents like the Polish CHP plant breach from happening to their own projects? In response to the problems and challenges exposed by this incident, Remonde's AMP remote access solution provides clear answers:
Exposed VPN ports on the public network? — Only port 443 is open
Many sites map ports for RDP, SSH and industrial control software one by one for remote O&M. The more ports are open, the higher the risk of being targeted by scanners. The Remonde solution carries all remote access traffic through only port 443, reducing the risk of network scanning and probing at the entry point.
Easily cracked login credentials? — Mandatory multi-factor authentication
Addressing the issue of core devices using factory default credentials for extended periods at the affected Polish plant, the Remonde solution implements centralized system hosting of remote access passwords, eliminating login operations with weak or default credentials. It also enforces multi-factor authentication to block the most basic entry points for attackers.
Unisolated private networks with unrestricted lateral movement? — Granular permission control
The Remonde solution breaks the conventional assumption that private networks are inherently trusted. Following the principle of least privilege, it implements granular access control, ensuring each account can only access its authorized devices and remains invisible to other internal network resources. Even if a single node is compromised, the breach will not spread across the entire station.
Persistent private network connections for convenience? — Built-in physical remote switch
The remote access device comes with a built-in physical remote switch, which connects during O&M operations and disconnects upon completion. This preserves the convenience of remote O&M while physically eliminating the lateral penetration risk caused by persistent private network connections, solving the common oversight of "forgetting to disconnect after debugging".
Closing Remarks
All too often, enterprises do not fail to recognize the importance of security — they compromise for convenience and succumb to misplaced confidence.
The biggest warning from the Polish incident is not that networking is dangerous, but that poorly managed networking is far more dangerous. Remote O&M should never require sacrificing security for convenience, nor should security mean abandoning connectivity entirely. When physical isolation is not feasible, enterprises should implement rigorous remote access security management — making remote access both convenient to use and firmly secure.
Don't let someone else's accident become your own lesson.