← All articles

· Crossover Software

Remote Plant Operations: Alert Fatigue, OT Security and Limits to Consider

A four-part IIoT World series, concluded on 14 August 2026, reflects on the future of remote work in industry. Parts 3 and 4 offer useful insights on alarms, compliance and security for anyone connecting machines and plants.

IIoTOT securityremote monitoringsmart factoryalert fatigue

Between 11 and 14 August 2026, IIoT World published a four-part series by Paul Viorel on the future of remote work in industrial operations. It is not news in the strict sense, but an analysis and opinion piece built around a framework called "Three Convergences": workforce shortages, AI maturity and IIoT infrastructure. Here we focus on Part 3 (13 August) and Part 4 (14 August), which cover human costs, regulatory compliance and the limits of the remote model. For Part 4 we were only able to read the available excerpt, without the conclusion and FAQ.

The risk of alert fatigue

The central point of Part 3 is simple: if operators receive every anomaly flagged by the AI, with no prioritization, alerts become background noise. The result is the opposite of what was intended, namely less safety. On top of this comes a typical limit of remote work: the physical cues (sounds, vibrations, smells) that people on the floor pick up without thinking are missing.

The countermeasures proposed are concrete:

  • alarm prioritization, so that only actionable anomalies come to the surface;
  • rotation between remote shifts and on-site shifts;
  • structured handovers between shifts;
  • occupational health support.

The article also cites 2026 Gallup data (global employee engagement at 20%; teams with a formal hybrid collaboration plan would be 66% more likely to be engaged and 29% less likely to be at risk of burnout) and Microsoft's 2026 Work Trend Index, according to which 67% of AI's impact depends on organizational factors. However, these studies concern office work in general, not manufacturing: they should be read as indications, not as evidence for the production floor.

Compliance: design it in from the start

On the regulatory front, the author points out that remote access to control systems must comply with the standards of one's own sector, citing NERC CIP, FDA 21 CFR Part 11, OSHA PSM and ISA/IEC 62443. He indicates Security Level 2 of the latter as a practical minimum baseline for remote operations. The underlying message is that access traceability, access controls and training must be planned from day one, because retrofitting compliance costs far more.

For Italian and European plants, it should be noted that most of these references are American: only ISA/IEC 62443 is directly relevant, and the article does not mention NIS2 or other EU rules. The principle of early design nonetheless remains valid.

The limits of remote operations

Part 4 reminds us that physical presence still matters: physical processes require manual intervention, and sensor coverage is never complete. The useful question, the author suggests, is not "remote or on-site?" but which activities benefit from being on-site.

On the security side, weak IT/OT segmentation and remote access by third-party vendors widen the exposure. 35% of organizations reportedly say they have insufficient visibility into their OT/IIoT assets. The article also reports a 64% increase in industrial ransomware incidents in 2025 (around 3,300 organizations) and an average downtime cost of $260,000 per hour in discrete manufacturing; for both figures, no primary source is given in the excerpt we read, so they should be treated with caution.

Finally, an organizational risk: a two-speed workforce, with engineering roles becoming remote-capable while operations and maintenance stay on site.

Key takeaways

Connecting machines only pays off if alarms are filtered and actionable, and if security and access logs are designed in from the start.

For those managing production monitoring or MES projects in an SME, the series offers a common-sense checklist:

  • define which anomalies truly require action and with what priority;
  • set out clear shifts, handovers and responsibilities for those monitoring remotely;
  • segregate IT and OT networks and govern vendor access, with session recording;
  • map connected assets, so as to leave no blind spots;
  • assess the applicable standards (ISA/IEC 62443 and the European regulatory framework) before opening up remote access.

One final caveat: the series' examples come mainly from chemicals, pharma and utilities, and the statistics derive from vendors and third-party surveys. The value lies in the way of reasoning more than in the numbers.