Manufacturers Bolster OT Remote Access—Yet Third-Party Governance Lags

Manufacturers Bolster OT Remote Access—Yet Third-Party Governance Lags

Why it matters now: The rapid expansion of remote vendor access into industrial control systems—spanning PLCs, HMIs, and SCADA environments—has created a dangerous asymmetry. While manufacturers accelerate toward Zero Trust architectures in response to mounting ransomware threats, the governance frameworks required to manage third-party access at scale remain critically underdeveloped. Secomea's newly released State of Industrial Remote Access 2026 report, published July 20 from Copenhagen, reveals that 57% of North American organizations now manage six or more external vendors with direct remote access into operational technology (OT) environments—yet the controls governing those connections lag far behind operational demands.

Analyst Insight: The structural problem is not that vendors are malicious—it is that organizations are architecting access without architecting governance. When six or more third parties can reach your PLCs and engineering workstations, every unmonitored session becomes a potential vector for lateral movement.

The Vendor Sprawl Reality: Six-Plus Third Parties, One Attack Surface

Based on a global survey of 400 senior OT, IT, compliance, and operations leaders across manufacturing and critical infrastructure, Secomea's findings expose a sprawling vendor ecosystem that most organizations are ill-equipped to govern. The 57% figure for North America—organizations managing six or more external vendors with OT remote access—represents a structural dependency that has outpaced security maturity.

Each vendor connection touches sensitive industrial assets: PLCs running production lines, HMI panels controlling batch processes, SCADA servers managing entire plant floors. The attack surface has expanded proportionally, yet the governance layer has not kept pace.

Key Findings from the Secomea 2026 Report
  • 57% of North American organizations manage six or more external vendors with remote OT access
  • Only 43% of industrial organizations globally have full vendor session auditability
  • Just 17% operate with a unified remote access platform
  • Survey base: 400 senior leaders across manufacturing and critical infrastructure in North America and Europe
  • Vendor sprawl, weak credential practices, and fragmented tooling identified as the top three structural gaps

The Confidence-to-Evidence Gap: Perception vs. Reality

Perhaps the most unsettling finding in the report is what Secomea terms the "confidence-to-evidence gap." Most organizations rate their session visibility and regulatory readiness as "good"—yet deeper analysis reveals that full vendor session auditability remains uncommon. Confidence, the data suggests, is being mistaken for actual security posture.

Only 43% of industrial organizations globally can fully audit vendor remote access sessions. That means 57% of plants and critical infrastructure facilities cannot reconstruct exactly what an external vendor did during a remote maintenance session on their PLCs or SCADA systems. In a post-incident forensic scenario, this gap becomes catastrophic.

Market Trend: Gartner published its first-ever Market Guide for Cyber-Physical Systems (CPS) Secure Remote Access in 2026—signaling that secure OT remote access has matured into a standalone market category. Organizations that treat remote access as a tactical IT function rather than a strategic OT control layer will face mounting regulatory and operational risk.

Zero Trust Momentum Meets Governance Inertia

The report confirms that manufacturers are moving beyond basic VPN-based connectivity toward Zero Trust architectures. Following successive waves of ransomware attacks targeting industrial organizations—from automotive suppliers to water treatment facilities—the operational case for least-privilege access, continuous verification, and micro-segmentation has become undeniable.

Yet the governance dimension—the policies, workflows, and audit mechanisms that determine who accesses what and under what conditions—remains conspicuously under-invested. Secomea's research indicates that vendor-related risk is not primarily driven by vendor behavior, but by how organizations structure and govern vendor access.

The Credential Hygiene Crisis

Weak credential practices cut across the entire survey population. Shared credentials, non-expiring passwords, and the absence of multi-factor authentication for vendor access persist even in organizations that have otherwise adopted advanced OT security tools. A single compromised vendor credential—used across multiple customer sites—can cascade into simultaneous disruptions at multiple facilities.

Why Credential Hygiene Remains the Weakest Link in OT

Industrial environments present unique credential management challenges that IT-centric identity solutions do not address:

  • Legacy PLCs and RTUs often lack native support for modern authentication protocols
  • Vendor-supplied default credentials frequently remain unchanged years after commissioning
  • Shift-based operations create pressure for shared accounts that bypass individual accountability
  • Air-gapped assumptions lead organizations to deprioritize credential rotation—only to discover remote access paths they did not know existed

What Higher-Performing Organizations Do Differently

Secomea's report identifies a cohort of organizations that have closed the confidence-to-evidence gap. These higher-performing entities share three structural characteristics: they operate unified remote access platforms rather than fragmented toolkits, they enforce role-based access controls tied to specific industrial assets rather than network-level permissions, and they maintain full, immutable audit logs of every vendor session.

Critically, these organizations treat remote access not as a connectivity problem solved by a VPN concentrator, but as a governance function integrated into their broader OT cybersecurity architecture. The difference in outcomes—measured by incident response time, compliance audit readiness, and vendor onboarding efficiency—is substantial.

Analyst Insight: The 17% of organizations operating unified access platforms are not merely more secure—they are more operationally resilient. When a vendor firmware update goes wrong at 2 a.m., the ability to instantly identify which assets were touched, by whom, and for how long transforms a crisis into a manageable incident.

The Path Forward: From Connectivity to Governed Access

The central message of the Secomea 2026 report is unambiguous: industrial remote access has become a strategic control layer for uptime, compliance, and cybersecurity—not a tactical IT capability. Organizations that continue to treat it as the latter will find themselves exposed to regulatory scrutiny, operational disruption, and the cascading consequences of third-party credential compromise.

For plant managers, automation engineers, and OT security leaders, the actionable takeaways are clear. Vendor governance must be embedded into access architecture from day one—not bolted on after an incident. Unified platforms that deliver full session auditability, role-based access control, and enforced multi-factor authentication are no longer optional. They are the baseline for operating safely in an environment where six or more external parties touch your industrial control systems every day.

FAQ: Third-Party OT Remote Access Governance

Q: What is the biggest risk of ungoverned third-party OT access?
Lateral movement. A compromised vendor credential can allow an attacker to move from an administrative workstation to engineering workstations and PLCs—often without detection, because session activity is not being fully audited.

Q: How does Zero Trust apply to OT remote access?
Zero Trust principles in OT mean that every vendor session is continuously verified, access is granted per-asset rather than per-network, and no connection is trusted by default—even if it originates from a known vendor IP address.

Q: What is the "confidence-to-evidence gap" identified in the report?
It is the disconnect between how organizations rate their own security posture (typically "good") and the objective evidence available through session audit logs. Only 43% of organizations have full auditability—meaning most cannot prove their confidence is warranted.

Q: Is this primarily a North American problem?
While the 57% vendor-sprawl figure is specific to North America, the report finds structural governance gaps across both North American and European manufacturing and critical infrastructure sectors.

Related Articles

Tillbaka till blogg