Earlier quoted context omitted.
I'd agree partially with you. However, once a remote agent is compromised, it will be chained with some privilege escalation vulnerability and this same argument will be repeated with the twist that now every foreign executable with remote connection is an attack surface. Having hundreds of people in each location whose only task is to do a boring monitoring an very occasional management tasks is a waste of your reso…
IMO, a big issue is conflating monitoring with management. Management is always going to have access, so maybe you should not enable remote management access of everything to a centralized system? Make it lean and secure, possibly segmented, dual-factor, use HSM etc. Monitoring - there is no good reason why it should have access to anything. Make it ingest only (use firewalls and reasonable protocols), and you've cut…
At the same time, you don't have a way to solve a problem that your monitor has alerted you for. Every solution proposed includes either a person at the location who does the job manually or a way to connect to the network from the outside which is vulnerable to similar attacks as before with added costs and possibilities to mismanage keys and passwords.
Security vs convenience is a well-known dilemma that people very often love to solve in the most absolutist way.