Introduction
In today's rapidly evolving industrial landscape, manufacturers are increasingly focused on securing remote access to operational technology (OT) networks, driven by a surge in ransomware attacks. Despite significant investments in cybersecurity measures to fortify these connections, new challenges arise, particularly regarding third-party access governance.
The Current Industrial Landscape
Recent findings from the research conducted by Secomea highlight a critical gap between operational speed and the governance of third-party access in the manufacturing industry. As machine builders and system integrators rely on remote access for operational continuity, the growth of supplier ecosystems intensifies the need for structured governance.
"Manufacturers have significantly invested in securing remote access over the past few years," said Knud Kegel, Chief Technology and Product Officer at Secomea. He emphasized the necessity for reliable access management, ranging from identification to tracking session histories.
The Evolution of Cyber Threats
The evolution of cyber threats is shifting away from exploiting perimeter vulnerabilities towards attacking trusted identities and legitimate remote access channels. This necessitates greater accountability from manufacturers to enhance visibility and control over third-party access without hampering maintenance operations or production efficiency.
According to Secomea’s recent report,
The State of Industrial Remote Access 2026, many organizations are addressing these emerging challenges. In North America, for instance, 57% of companies manage at least six external vendors with remote access to their OT environments, reflecting an increased reliance on third-party support services. However, a mere 46% fully verify vendor sessions, and only 23% conduct monthly checks on vendor credentials. This discrepancy indicates limited visibility into who accesses their systems and the relevance of that access.
The Importance of Shared Responsibility
Moreover, organizations that share responsibility for remote access between IT and OT departments reportedly experience fewer incidents. This underscores the significance of collaborative governance alongside technical safeguards. Secomea asserts that effective third-party access governance involves more than just secure connectivity; it includes rigorous identity verification, applying the principle of least privilege, and establishing comprehensive audit trails.
Moving Towards a Centralized Governance Model
An enlightening trend emerging from the findings includes the preference among over three-quarters of North American organizations for a standardized platform to manage vendor access. This indicates a transition from fragmented VPN networks and vendor-specific remote access tools towards centralized governance models.
Secomea advocates for manufacturers to ensure their remote access strategies include:
- - Identity-based access for each vendor and contractor
- - Just-in-time access instead of permanent remote connections
- - Centralized approval processes for IT and OT systems
- - Comprehensive audit trails for every remote session
- - Regular credential checks and automated revocation of access rights
- - The ability to swiftly suspend or restrict remote access in response to cybersecurity incidents
Conclusion
The complete insights from Secomea’s research are available in the
State of Industrial Remote Access 2026 report, examining how manufacturers and organizations managing critical infrastructure are navigating supplier access, governance, visibility, and operational resilience in the face of evolving cyber threats.
About Secomea
Secomea specializes in secure remote access solutions, tailored for industrial networks and operational technology equipment. Trusted by over 8,000 manufacturers and machine builders worldwide, Secomea provides safe connectivity for people, systems, and machines while ensuring operational continuity and control. The company also implements robust vendor management practices, enhancing visibility into remote access activities, thereby promoting secure collaboration within the industrial ecosystem. Recently, Secomea was recognized as a representative vendor in the category of
Secure Remote Access to Cyber-Physical Systems in the Gartner® Hype Cycle™ 2026 report on CPS security.