Resource Hub

Manufacturing Security

How to Secure Remote Vendor Access to a Factory

Most manufacturers, when asked, cannot produce a complete list of every vendor with remote access into their network, what systems each one can reach, or when they last connected.

By Ahmed HegaziFounder & Principal Security Consultant|2 min read

The Problem

Most manufacturers, when asked, cannot produce a complete list of every vendor with remote access into their network, what systems each one can reach, or when they last connected. Equipment vendors, systems integrators, and IT contractors all need remote access to do legitimate work, but that access is frequently granted once and left standing indefinitely, unmonitored, and unreviewed.

Why it Matters Operationally

Vendors are trusted by default and rarely monitored as closely as employees, which makes third-party access one of the most common paths attackers use to reach manufacturing environments. A vendor's laptop infected from an unrelated customer can carry that infection straight into the plant the moment it connects. Vendor credentials reused across multiple customer sites, once stolen, can be used to reach dozens of plants at once, including yours.

The Simple Explanation

Securing vendor access does not mean eliminating it; manufacturers depend on outside vendors to keep equipment running. It means replacing standing, always-on access with something controlled and time-boxed: connections routed through a dedicated gateway rather than a direct line into the general network, access scoped tightly to the specific machine or system a vendor actually needs, and every session logged so there is a clear record of what happened.

Practical Checklist

  • Is there a complete inventory of every vendor with remote access and what they can reach
  • Does vendor access route through a dedicated gateway or jump host rather than a direct VPN
  • Is access granted for a specific, limited window rather than left standing between visits
  • Is multi-factor authentication required on every vendor account without exception
  • Is each vendor session logged, and ideally recorded
  • Is a vendor's access scoped to one machine or cell rather than the entire OT network
  • Do vendor contracts specify baseline security requirements and breach notification obligations
  • Is vendor access reviewed on a recurring schedule, not set up once and forgotten

What You Can Do Now

Build the vendor access inventory this month if one does not already exist; it usually surfaces forgotten access that should have been revoked long ago. Turn on multi-factor authentication for every vendor account immediately, since this closes off the most common way stolen vendor credentials get used.

When Outside Help Makes Sense

Designing a proper remote access gateway with scoped, time-boxed vendor sessions is a meaningful network architecture project, not a quick configuration change, and it benefits from expertise in both IT and OT environments. If vendor access has grown organically over the years without a clear review process, a security partner can help design and monitor it correctly.