Strengthening Remote Access Governance in Manufacturing Amid Cybersecurity Challenges
As manufacturing companies focus on improving their cybersecurity postures due to a surge in ransomware attacks, attention is increasingly turning towards an often-overlooked aspect: third-party access governance. A recent study by Secomea sheds light on this issue, revealing a significant gap in how organizations manage vendor access within their operational technology (OT) environments.
The Current Landscape
In an era where machine builders, system integrators, and equipment suppliers are essential to maintaining production, the necessity for remote access has become more pronounced. However, enabling this access poses challenges, especially in light of evolving regulations and the complexities of managing relationships with multiple vendors.
Knud Kegel, Chief Technology and Product Officer at Secomea, points out, "Manufacturers have substantially enhanced their remote access security over the past few years. Now, the critical next step is ensuring that access is managed and governed effectively. Organizations need to understand who is accessing their systems, the reasons for such access, its duration, and have the ability to trace every action taken during remote sessions."
The stakes are high as cybercriminals are increasingly exploiting trusted identities, underscoring the importance of enhancing visibility and control over vendor access without disrupting operational activities. Currently, about
57% of North American manufacturing organizations manage six or more external vendors with remote access to their OT environments, yet only
46% possess full audit capabilities of these sessions. Alarmingly, just
23% routinely review vendor credentials, creating potential blind spots in access governance.
Bridging the Gap
Research indicates that organizations with a shared responsibility for OT and IT related to remote access witness fewer security incidents than those that segregate these responsibilities. This finding underscores the necessity of implementing robust governance frameworks alongside technological solutions.
Effective third-party access governance involves more than just ensuring secure connectivity; it encompasses the adoption of comprehensive identity verification processes, applying principles of least privilege, granting just-in-time access, implementing centralized approval workflows, establishing thorough audit trails, and rapidly revoking access once a vendor's work is completed. Kegel highlights, "Manufacturers don't need to reduce their number of vendors; they require superior governance over vendor access. Third-party connectivity is integral to modern manufacturing, and organizations that can achieve this while maintaining a clear view and control will emerge more resilient."
The future looks promising, according to the report, which shows a significant shift in preference among manufacturers in North America. More than
75% of respondents favor a standardized platform for managing vendor access, moving away from disconnected VPNs and tailored remote access tools towards unified governance models that can streamline oversight and enhance security.
Recommendations for Manufacturers
Secomea advises organizations to evaluate their remote access strategy by incorporating several best practices:
- - Identity-based access for every vendor: Ensure that every contractor and vendor has their access tied explicitly to their identity.
- - Just-in-time access policies: Replace persistent remote connections with temporary access that is granted when required.
- - Centralized approval workflows: Develop structured processes that facilitate oversight from both IT and OT perspectives.
- - Comprehensive audit trails: Maintain detailed logs of every remote session to bolster accountability and traceability.
- - Regular review of credentials: Conduct frequent checks on vendor credentials to ensure their continued appropriateness.
- - Emergency suspension capabilities: Equip your systems to quickly limit remote access during any cybersecurity incident.
Secomea’s comprehensive findings are detailed within the
State of Industrial Remote Access 2026 report, analyzing how manufacturers and critical infrastructure sectors manage remote vendor access, governance, visibility, Zero Trust adaptations, and resilience in operations across North America and Europe.
About Secomea
Secomea is a secure remote access solution tailored for industrial networks and OT equipment, empowering over
8000 manufacturers and machine builders globally to maintain secure connections that uphold operational integrity. By aiding businesses in refining vendor access governance and implementing Zero Trust principles, Secomea enhances visibility into OT remote access activities, thereby fostering safe collaboration within the manufacturing ecosystem. Secomea was recently recognized as a Representative Vendor in the CPS Secure Remote Access category within the
Gartner® Hype Cycle™ for CPS Security, 2026.
As organizations grapple with managing remote access in a cybersecurity-conscious world, the blend of effective governance and cutting-edge technology will be pivotal in navigating these challenges successfully.