Optimizing Remote Access to Operational Technology
In the wake of increased ransomware attacks, manufacturers are ramping up their cybersecurity efforts, particularly regarding remote access to Operational Technology (OT) systems. Secomea, a leading provider of secure remote access solutions, highlights that while significant strides have been made to secure these connections, managing third-party access remains a pressing challenge.
Overview of Current Cybersecurity Landscape
Recent events have made it clear that manufacturers must continuously adapt their cybersecurity strategies to safeguard their operations. The increasing complexity of digital ecosystems, combined with a growing number of external service providers, puts pressure on companies to ensure that not only is remote access secure but also well-governed. This situation points to an evolving landscape where accessibility must balance with security needs.
Knud Kegel, the Chief Technology and Product Officer at Secomea, emphasizes the necessity for better governance around third-party access. He argues that businesses have substantially invested in enhancing remote access security over the past years. However, the next vital step is to ensure uniform regulation of who accesses these systems, why, for how long, and to have a clear audit trail of activities during every remote session.
Survey Findings: The State of Remote Access
The latest report from Secomea, titled
State of Industrial Remote Access 2026, reveals notable insights into these governance challenges. In North America, 57% of companies manage at least six external providers with access to their OT environments. However, only 46% of these sessions are completely trackable; shockingly, just a mere 23% conduct frequent reviews of supplier access credentials. This lack of transparency raises critical concerns about security and accountability in operational settings.
Moreover, the report suggests that firms where both IT and OT departments share responsibility for remote access report fewer incidents compared to those where one segment solely manages it. This indicates that governance needs to be viewed alongside technological solutions in preventing cyber threats.
The Imperative for Stronger Governance
Secomea posits that effective governance transcends technical connectivity. It incorporates several best practices, including:
- - Identity Verification: Ensuring that every access is clearly associated with verified identities.
- - Just-in-Time Access: Allowing contractors to access systems only at necessary times, rather than maintaining all-time access.
- - Centralized Approval Workflows: Streamlining the authorization process across IT and OT departments to enhance efficiency.
- - Comprehensive Audit Trails: Maintaining detailed records of who accessed what and when.
- - Regular Credential Reviews: Conducting frequent checks on access credentials to ensure their relevance and correctness.
- - Rapid Access Revocation: Ability to quickly suspend access, especially in the event of a cybersecurity incident.
Kegel states, “Manufacturers do not necessarily need fewer suppliers; rather, they need improved governance over supplier access.” The necessity for connecting third-party providers in modern manufacturing cannot be overstated, as these partnerships are crucial for operational success. The most resilient companies are those that can facilitate these connections while maintaining control, transparency, and accountability.
Trends in Third-Party Access Management
The report also indicates a clear trend within the industry towards adopting centralized governance systems. Over three-quarters of surveyed companies in North America either currently use or prefer standardized platforms for managing supplier access, moving away from fragmented VPNs and proprietary remote access tools.
Secomea advises manufacturers to evaluate their current remote access strategies and ensure inclusion of improved governance practices. By implementing the recommendations detailed in the
State of Industrial Remote Access 2026, companies can enhance their operational resilience while securing their OT environments against emerging threats.
Ultimately, by prioritizing transparency and accountability in remote access governance, manufacturers can truly harness the benefits of a connected, digitalized operational environment without compromising their security.