A mid-size food processor we know of had a ransomware event last year that took three days of production offline. The root cause analysis identified the initial access vector pretty quickly. An engineer at their MES (Manufacturing Execution System) integrator had a laptop compromise. The laptop had a saved VPN profile into the manufacturer’s plant network, with cached credentials. The attackers rode the integrator’s access straight past the plant’s perimeter firewall and into the production environment.
The integrator was not negligent in any colorful way. They were a competent firm that employed dozens of engineers supporting hundreds of clients. But they were also, from the manufacturer’s perspective, a completely trusted entity with permanent remote access to systems that ran the plant floor. When that trust became a liability, the impact landed on the manufacturer, not the integrator.
This pattern is now one of the most common ways manufacturers get breached. The CISA 2024 year-in-review and a series of joint advisories have highlighted third-party and supply chain access as a major attack vector against industrial targets. If your plant has vendor remote access set up the way most plants do, you are exposed in a way you can actually fix.
The Problem: Vendor Access Evolved Haphazardly
In most manufacturing environments, vendor remote access developed one vendor at a time, over years, with very little central design. A typical environment looks like this:
- The MES integrator has a VPN account and connects whenever needed
- The PLC programming firm has a separate VPN account with different permissions
- The ERP vendor connects through a different remote access tool (TeamViewer, ScreenConnect, or similar)
- The HVAC controls contractor uses yet another method
- The OEM for the packaging line uses a cellular-based remote access appliance they installed themselves, which the manufacturer has no visibility into
- Several people who do not work at the vendors anymore may still have accounts because offboarding was never a documented process
Nobody has a full list of vendor accesses. The firewall rules that support them have grown over time. Some accounts have been unused for a year but still exist. Some vendors have given their credentials to subcontractors. Some connections bypass the corporate firewall entirely through vendor-installed cellular gateways.
This is the environment attackers now specifically target.
Why It Matters to You Specifically
For plant leadership and the IT team supporting the plant, uncontrolled vendor access creates four distinct problems:
You Are Only As Secure As Your Least Secure Vendor
A compromise at any of your vendors can reach your environment. You inherit their security posture. A vendor running old remote access software with no MFA (multi-factor authentication, requiring something more than just a password for login) has extended their weak posture into your plant.
The Compromise Path Goes Straight to OT
Vendor access is usually set up specifically to reach OT systems, because that is what vendors need to support. This means a compromise of vendor credentials gets an attacker directly into SCADA, PLCs, or the MES, bypassing the layers of defense you spent time building on the IT side.
Incident Scoping Becomes Very Hard
When an incident hits, your IR team has to figure out which vendor accesses were involved, which credentials may have been stolen, and which systems each vendor can reach. If the vendor access inventory is incomplete, this work is slow. Slow scoping means slow recovery.
Your Insurance and Compliance Posture Suffers
Cyber insurance underwriters are now asking specific questions about third-party access controls. For defense-adjacent manufacturers subject to CMMC or NIST SP 800-171, controlled third-party access is explicitly in scope. “We have vendor VPNs” is not a compliant answer.
What Good Looks Like
A plant with mature vendor remote access management has a clear architecture and clear operational discipline.
A Single Controlled Remote Access Platform
Every vendor connects through the same platform, not through a patchwork of tools. The platform is usually one of two models:
- A jump host in a DMZ (a controlled network zone between the internet and the OT environment) that vendors connect to, with session recording and monitoring, and from which they access specific OT systems
- A zero trust network access (ZTNA) platform that authenticates vendor identity, checks device posture, and grants just-in-time access to specific systems for specific durations
Either approach is a major improvement over general-purpose VPNs.
MFA Required for Every Vendor Account
Every vendor login requires MFA. No exceptions. Vendors whose tooling does not support MFA are not getting direct access; they connect through a jump host that adds the MFA step at the boundary.
Time-Bounded, Task-Specific Access
Vendor access is not permanent. A vendor requests access for a specific window to accomplish a specific task. The access is granted for that window and revoked automatically when it closes. Support tickets are matched to access sessions, so you can audit who did what and why.
Session Recording for High-Sensitivity Systems
Access to critical systems (core SCADA servers, historian, MES core services) is recorded in full. Recordings are retained and reviewable. Vendors know the recording is happening, which has a useful effect on behavior.
Inventory and Review
A current inventory of every vendor with access to every system exists and is reviewed quarterly. Access that is no longer needed is removed. Vendor personnel changes (someone leaves a vendor firm) trigger credential updates on the manufacturer’s side.
Vendor Security Requirements in Contracts
New vendor agreements include security requirements: MFA use, prompt notification of personnel changes, prompt notification of security incidents at the vendor, and right-to-audit. Existing vendor agreements are updated at renewal.
Cellular and Out-of-Band Connections Under Control
Vendor-installed cellular gateways on production equipment are inventoried, secured, and either brought under the main remote access platform or explicitly accepted with compensating controls. CISA’s guidance on securing industrial control systems reinforces that these out-of-band connections are a critical attack surface.
Practical Takeaways
- Inventory every vendor with access to your plant today. Include cellular gateways, remote access tools, VPN accounts, and any direct internet access to production equipment. The list is usually longer than expected.
- Identify any vendor without MFA and prioritize fixing that. This is the single highest-impact control to add.
- Consolidate on one remote access platform. The operational benefit (easier vendor management) usually matches or exceeds the security benefit.
- Add vendor security requirements to your standard contract template. Future vendors inherit the expectations. Existing vendors get them at renewal.
- Schedule quarterly access reviews. A vendor account that has not been used in 90 days is a vendor account that can probably be deleted.
Getting control of vendor remote access does not mean making life harder for your vendors. Done well, it actually simplifies their experience (one platform, clear process) while dramatically reducing your attack surface. The integrators and OEMs who work with security-mature manufacturers usually appreciate the clarity.
If you want a conversation about assessing and modernizing vendor remote access at your plant, the HVR Cloud team works with manufacturers on exactly this kind of engagement. Get in touch and we can walk through your environment.
