
Manufacturers are highly dependent on third-party vendors—not just for convenience, but out of necessity. Factors like commercial agreements, OEM dependencies, and a shortage of skilled internal labor have significantly expanded the scope of third-party involvement in operational technology (OT) environments. Now, with this growing ecosystem of external access, manufacturers are seeking ways to make these interactions more agile and—critically—more secure.
According to a recent survey conducted by Takepoint Research and Cyolo, 88% of manufacturers authorize remote third-party access to OT environments to take care of a wide variety of functions, while 60% permit more than 100 external parties (vendors, contractors, suppliers, OEMs, etc.) to access these environments remotely.
However, this reliance on external vendors raises several critical cybersecurity issues, including the outsized risk that third-party connections pose, and the steps companies need to take to ensure the visibility, management and security of these connections.
An increasing number of attacks on industrial systems have been traced back to the vulnerabilities posed by legacy remote access methods, particularly the shortcomings of VPNs and remote desktop tools. It is increasingly clear that insecure remote-access tools and VPNs are highly susceptible to ransomware breaches.
Given that the industrial sector’s digital revolution shows no signs of slowing and that third-party access remains a critical component of operational efficiency and continuity, here’s what manufacturers need to know to make sure their security posture keeps pace.
Legacy Remote Access Tools are a Security Liability
Legacy remote access systems, including many VPNs, rely on outdated technology that often fails to offer the granular control and visibility needed to secure modern industrial environments. Because VPNs and similar tools do not use identity-based access methods to verify users and devices before granting them access, security teams essentially have no visibility into who is accessing what systems, when, and for how long. Additionally, most of these systems are static and reactive, and lack the ability to monitor and enforce active sessions in real-time. Even manufacturers who recognize the need for identity-based access are sometimes forced to accommodate the remote access methods preferred by their third-party vendors – most commonly, traditional VPNs. This approach places critical areas outside the organization’s direct control – creating blind spots and making it difficult to enforce security policies and monitor sessions, leaving the network exposed and more at risk to supply chain disruption threats.
Modern access systems must address these gaps by offering dynamic monitoring, session access visibility, and identity-based access control. Without these types of solutions, organizations are left vulnerable to both malicious actors and human error.
Closing the Gap – An Action Plan
To address these challenges, companies must shift from traditional perimeter-based defenses to identity-first security models, such as the Zero Trust access framework, and ensure that only authorized users can access specific resources, regardless of their location or network.
Organizations usually apply the following three-pronged strategy for approaching this shift, dubbed the “Crawl-Walk-Run” model:
• Crawl: Establishing Visibility
Companies must first gain complete visibility into their critical environments and create a comprehensive inventory of assets, including IP addresses, third-party integrations, employee access status, and more. By identifying and understanding exactly what their assets are, how they are interconnected, and when and how they are accessed, organizations can monitor their critical systems more skillfully, ensuring they can make informed decisions about who can access what, when and how.
• Walk: Enforcing Control
Once an organization has achieved widespread visibility, it can begin implementing the access controls needed to strictly manage who can access sensitive systems – such as policies restricting access based on user roles, time, location, credentials, and more.
This is when organizations should apply the principle of “Zero Trust / least privileged.” By isolating critical assets and functions, organizations can increase control by giving third-party vendors only the amount of access necessary to do their jobs, and nothing more. Third-party owned VPNs must be integrated into this strategy.
• Run: Scaling with Intelligence
The final step is about scaling securely and efficiently – automating the entire access control process with AI-powered monitoring, conscious risk assessment and intelligent policy enforcement. In line with the principles of Industry 5.0, this approach doesn’t replace humans but augments them. It embraces a Human-in-the-Loop model, where artificial intelligence and human judgement work together to ensure decisions are contextual, ethical and aligned with organizational priorities.
By transitioning from legacy perimeter-based access to modern, identity-based Zero Trust measures, organizations can enable secure access, continuous supervision, and intelligent oversight—ensuring all activity is controlled and protected according to the highest security standards.
Securing Assets Means Securing Access
The threat posed by insecure third-party remote access has never been more acute, particularly within complex operational technology (OT) environments. Accordingly, as industrial organizations expand their digital ecosystems in the quest for control and efficiency, it is essential that they rethink traditional methods of access control and implement a strategy that prioritizes security and visibility at every layer of their infrastructure.
By adopting a Zero Trust framework, investing in real-time monitoring, and leveraging automation, organizations can build a resilient, scalable, and secure environment that guarantees the success of industrial operations well into the future.
Join our LinkedIn group Information Security Community!











