Third-party vendor access is the most common way an attacker reaches a plant floor without touching the corporate network. The path is rarely built by your security team. It gets stood up during commissioning, when the equipment supplier needs to reach a press, a filler, or a robot cell to finish the install, and the fastest route wins because the line has to run by Monday. That temporary route becomes permanent. Our team finds these tunnels years later, still open, still carrying a shared login, still invisible to the access reviews the plant runs every quarter. The six risks below are the ones we see most often in small and midsize manufacturers, and each one has a control that closes it without slowing down the vendors who keep your equipment running.
What Plant Leaders Get Wrong About Vendor Connections
Manufacturers rarely underestimate cyber risk in general. They underestimate this path in particular, because it was created by people they trust to solve a production problem. Five principles frame the rest of this piece for plant managers, controls engineers, and operations leaders at facilities without a dedicated OT security team.
- The vendor path was built for commissioning, not for years of use. Its defaults were chosen under deadline pressure, and nobody revisited them once the line ran.
- Trusting the vendor is not the same as trusting their network. A supplier with good intentions can still be breached, and their access becomes the attacker’s access.
- Availability is a security requirement here, not a competing one. A control that blocks a 3am emergency repair will be bypassed, so the fix has to keep the vendor working.
- You cannot review what you cannot see. Most plant access reviews cover Active Directory accounts and miss the connections that terminate on the OT side entirely.
- Attribution matters more than authentication. Knowing a vendor connected is worth little if you cannot say which person did what, on which machine, at what time.
Why Third-Party Vendor Access Fails in Manufacturing
Third-party vendor access fails in manufacturing because the connection is designed around equipment uptime and then inherited by a security team that never saw it get built. In an office environment, remote access is provisioned by IT through one reviewed channel. On a plant floor, each machine supplier arrives with its own preferred method, and the plant ends up with six different paths in, each maintained by a different company.
Commissioning Defaults Outlive the Project
A supplier finishing an install needs reliable access, so they ask for a firewall rule, a jump box, or a cellular modem attached directly to the machine. The request is reasonable and the plant approves it, because the alternative is a delayed startup. What follows is the actual problem: no one owns the cleanup. The counter-argument has real weight, since ripping out vendor access after commissioning can leave a plant unable to get warranty support at 2am on a holiday weekend. That risk is genuine and it is why blanket removal usually backfires. The workable middle is conversion rather than removal, moving each supplier from their own private path onto one brokered path the plant controls, with the same or better response time. Our guidance on managing third-party vendor access to your systems covers that conversion in more detail.
The Access Review Never Sees the OT Side
Quarterly access reviews at most manufacturers list user accounts in the corporate directory. A cellular modem bolted to a packaging machine has no account in that directory, so it appears nowhere in the review and passes every audit by being invisible. We ask plants to inventory by PATH rather than by account: walk each production cell and ask how the supplier of that machine reaches it, then write the answer down. The exercise usually takes a day and typically surfaces two or three connections nobody on the current team installed. In fairness, a path-based inventory is harder to keep current than an account list, and it goes stale as equipment changes. That is an argument for repeating it annually alongside preventive maintenance, not for skipping it.
The Access Risks Hiding in How Vendors Connect
Connection design carries the first three risks, and all three trace back to convenience choices made during installation rather than to any failure by the vendor.
Risk 1: Always-On Tunnels That Nobody Turns Off
A persistent VPN tunnel to a supplier is open whether or not anyone is working. If that supplier is compromised on a Tuesday afternoon, the attacker inherits a live path into your plant with no additional effort. Just-in-time access reverses the default: the tunnel stays closed until someone on your side opens it for a named maintenance window, then closes automatically. The honest objection from maintenance teams is that JIT adds a step during an emergency, and a line down at 3am cannot wait for an approval chain. That is a real cost, and the answer is a documented break-glass procedure with a named on-call approver, not an always-on tunnel. A tunnel that is open all year to save four minutes twice a year is a poor trade.
Risk 2: Flat Reach From the Jump Point
Vendor access is often scoped to a jump host and then stops being scoped at all. From that jump host, the supplier can frequently reach every device on the plant network, including cells built by their competitors. Segmentation fixes this by allowing the supplier’s session to reach only the addresses their own equipment uses. Most plants can implement a workable version with VLANs and firewall rules they already own, without buying anything. The practical starting point is a written list of which IP ranges belong to which supplier, which sounds trivial and is usually the piece nobody has. Once that list exists, the firewall work is an afternoon. Where it gets harder is shared infrastructure, since a historian or an HMI server that several suppliers legitimately touch cannot be carved cleanly into one supplier’s zone. Those shared systems deserve their own tighter treatment rather than being used as the reason to leave the whole network flat. We pair segmentation work with network security monitoring so that a session reaching outside its allowed range raises an alert rather than passing silently.
Risk 3: No Multifactor Because the Equipment Cannot Support It
Older machine controllers frequently cannot handle modern authentication, and that limitation gets used to justify leaving the whole vendor path without multifactor. The reasoning is backwards. Multifactor belongs at the broker, not at the controller: the vendor authenticates with MFA to reach the access gateway, and the gateway makes the legacy connection onward. The controller never has to support anything new. Where a plant genuinely cannot place a broker in the path, the fallback is compensating control, meaning tighter time windows, session recording, and alerting on every connection. What is not defensible is treating the controller’s age as a reason to skip the control entirely.
The Access Risks Hiding in Credentials and Oversight
The remaining three risks appear after the connection is established, and they are the ones that make an incident hard to investigate.
Risk 4: Shared Logins With No Attribution
Most vendor accounts we find are shared across the supplier’s whole service team. When something changes on a machine at 11pm, the log shows the vendor account, which tells you almost nothing. Individual named accounts for each supplier technician solve attribution, and suppliers usually agree once asked. Some genuinely cannot, particularly smaller integrators rotating contractors through, and pushing a requirement they cannot meet just moves the work off the books. In those cases the practical substitute is a brokered session tied to a ticket number, so the identity lives in your system even when it does not live in theirs.
Risk 5: Sessions Nobody Records
Without session recording, a plant investigating an unplanned stop has to ask the vendor what they did and accept the answer. Recording changes the conversation from recollection to evidence, and it protects the supplier as much as the plant, since it shows clearly when a fault was not caused by their work. Recording every session does carry storage cost and raises reasonable questions about monitoring an outside firm’s staff, which is why the scope should be written into the contract rather than switched on quietly. Firms formalizing this should fold it into their vendor agreements alongside the broader controls in our overview of how to manage third-party cyber security risks.
Risk 6: Access That Outlives the Relationship
When a supplier contract ends or a machine is decommissioned, the access almost never gets revoked, because offboarding a vendor is nobody’s named job. Our team has found live credentials for integrators a plant stopped using years earlier. Tie every vendor account to a contract end date at creation so it expires by default and has to be renewed deliberately. That pattern shows up across supply chains generally, and manufacturers supporting defense work should also read our note on defense supply chain security mistakes, where an expired-but-live account carries contractual consequences on top of the security ones.
What Third-Party Vendor Access Should Look Like in a Plant
Third-party vendor access in a well-run plant runs through one brokered path where the plant controls identity, timing, scope, and recording, while the supplier keeps the response speed they need. That single sentence covers all six risks, and most facilities can reach it in stages rather than as one project.
Start With an Inventory, Not a Purchase
Before evaluating any product, walk the floor and write down every way an outside party can reach a machine, including cellular modems, supplier laptops left on site, and rules in the firewall nobody recognizes. Plants routinely find the count is higher than expected and that two or three paths can be closed immediately because the equipment they served is gone. That alone reduces exposure at no cost. Buying a broker first and inventorying afterward is the common sequence and the expensive one, because the tool gets sized against a guess. We handle this discovery inside a cyber security audit when a plant wants an outside pair of eyes on it.
Convert One Supplier at a Time
Moving every vendor onto a brokered path at once creates exactly the disruption that gets a security project cancelled after the first bad night. Pick the supplier with the most frequent access, convert them, and run it for a month before touching the next. Frequency matters more than criticality for the first move, because a supplier who connects weekly will surface friction fast, while one who connects twice a year will not tell you anything for six months. Plant staff also need to know what changed, which is why we include the maintenance team in security awareness training rather than limiting it to office users, and why ongoing coverage usually sits with our managed security services team. The full control set is laid out in our piece on securing third-party vendor access.
Measure the Program With Four Numbers
A vendor access program is judged on four figures that a plant manager can read in a minute: how many distinct paths exist into the plant, how many of those run through the broker, how many vendor accounts carry an expiry date, and how many sessions in the last quarter were recorded. Those four cover reach, control, lifecycle, and evidence, and each one moves in a direction anyone can see. Plants that track them quarterly find the conversation with leadership gets easier, because the numbers show progress between projects rather than only at the end of one. There is a fair objection that counting paths rewards consolidation for its own sake, and a plant could shrink the number by routing everything through a single point that then becomes fragile. That is why the second figure matters alongside the first, since a brokered path is monitored and a consolidated one is not automatically either. Track them together, review them with the same cadence as your safety metrics, and the program stops depending on whoever happened to champion it.
Frequently Asked Questions
Is a VPN enough to secure third-party vendor access?
No. A VPN authenticates the connection and then usually grants broad network reach, which is the opposite of what vendor access needs. Pair it with segmentation that limits the session to the supplier’s own equipment, multifactor at the gateway, and time-limited access tied to a maintenance window.
How do we require multifactor when the machine controller cannot support it?
Place multifactor at the access broker rather than at the controller. The vendor authenticates to the gateway with MFA, and the gateway makes the legacy connection onward, so the controller needs no changes at all. Equipment age is not a valid reason to leave the whole path unprotected.
Should we record third-party vendor sessions?
Yes, and write it into the contract rather than enabling it quietly. Recording gives you evidence instead of recollection after an unplanned stop, and it protects the supplier by showing when a fault was not theirs. Define retention and scope in the agreement up front.
How often should a plant review vendor access paths?
Review by path at least annually, ideally alongside preventive maintenance, and re-check whenever equipment is added or retired. Account-based quarterly reviews miss cellular modems and supplier-installed connections entirely, which is why those paths survive audits for years.
What is the fastest risk to close this week?
Expired access. Pull the vendor list, mark every supplier whose contract has ended or whose equipment is gone, and revoke those first. It requires no new tooling, breaks nothing in production, and removes the accounts an attacker is most likely to find unmonitored.
Who Is Behind This Advice
Mindcore has worked with manufacturers and industrial operations for over two decades, and most of what appears above came from walking plant floors and finding connections that predated the current team. We approach OT security with production reality in front of it, because a control that stops a line at 3am will be removed by the people who have to keep that line running.
Matt Rosenthal, Mindcore’s chief executive, focuses on how security decisions translate into operational and business risk for owner-led firms, which is the lens behind every recommendation in this piece.
Close the Quietest Path Into Your Plant
Every risk above shares one root: the vendor path was designed to solve a production problem and never got revisited as a security control. Always-on tunnels, flat reach from a jump host, and missing multifactor are connection-design problems. Shared logins, unrecorded sessions, and access that outlives the contract are oversight problems. Both sets are fixable with tooling most plants already own, and neither requires slowing the suppliers who keep your equipment running.
The sequence matters more than the spending. Inventory the paths first, revoke what is expired, then convert your most frequent supplier onto one brokered route and let it settle before moving to the next. Plants that buy a product before doing the inventory usually size it against a guess and end up with an expensive tool sitting beside three connections it never covered.
If you want an outside read on how outside parties reach your plant floor today, our team will walk the paths with you and tell you plainly which ones to close first. Book a free strategy call and bring your firewall rules, your supplier list, and your maintenance contracts. You will leave knowing which of the six risks apply to your facility and what closing each one actually costs.

