
The specific advice they give is to disconnect all PLCs and only access them through a VPN, enable password protection and change the default passwords, and only allow IPs from known engineering laptops and other critical assets.
This is absolutely doable and any IT professional could manage this change. The only barrier that prevented this from happening before is that you need buy-in from someone with access to the purse strings

It usually happens in 2 steps.
First step is that everything gets connected to the LAN and you can only access the PLC network from within the building’s network. Then some time later, management finds out that keeping someone on-call to go out costs a fortune, so they request that access be made so they can make the change from anywhere.
The IT team argues security, but no new hardware can be provisioned and a developing a new process is too hard. Then the magical phrase is uttered: “Just make it work”. So IT punches a hole in the firewall, adds a NAT rule, and job done.