RealVNC logomark

RealVNC Viewer

Productivity

icon close circle

Zero Trust in Manufacturing: Securing Industrial Access

Contents

A supplier needs to diagnose a controller, an engineering workstation needs production data, and an older device still keeps a line running. When access is broader than the task requires, an unexpected connection can delay output while operations, suppliers, and customers deal with the consequences.

Zero trust in manufacturing is an access model that verifies each user, device, application, and connection before approving it for a defined task. It applies least-privilege access and segmentation, while accounting for plant uptime, timing requirements, safety constraints, and legacy equipment. The goal is controlled access that limits unnecessary connections without interrupting production.

That requires different decisions from conventional enterprise security. A programmable logic controller (PLC) may not support modern authentication or installed software, while intensive inspection can interfere with time-sensitive communications. Teams need to govern the paths around those assets, confirm human and service identities, and investigate unusual activity before taking action that affects operations.

This article sets out a staged approach for operational technology (OT) leaders. It covers mapping assets and normal communication flows, defining identity controls for employees and vendors, applying segmentation safely, protecting industrial internet of things (IIoT) connections, and retaining evidence from remote sessions. It also explains how IT, OT, engineering, and compliance teams can focus first on the access paths where a poor decision would interrupt production.

Why Is Zero Trust in Manufacturing Urgent?

Plant access decisions now cross far more boundaries than a traditional control-room network. A maintenance engineer may connect through corporate IT, a vendor may enter through a managed remote session, and an HMI may exchange data with a production service. Zero trust in manufacturing makes each connection an explicit decision, based on identity, context, intended function, and operational risk.

This matters because the plant cannot treat every internal connection as trusted once supplier access, cloud services, and engineering workflows cross established zones. The Joint OT Zero Trust Working Group defines the approach as continuous validation based on identity, context, and risk rather than implicit trust. Existing firewalls and Purdue-aligned zones still provide useful structure, but location alone no longer explains whether access is appropriate.

The scale of industrial targeting gives that decision urgency. IBM’s X-Force 2025 Threat Intelligence Index reported that manufacturing represented 26% of incidents among the 10 most targeted industries and ranked as the most-targeted sector for the fourth consecutive year. For leadership, that turns access governance into a production-resilience issue.

Legacy assumption Connected-factory reality Executive implication
Internal network location signals trust Corporate, supplier, cloud, and plant connections intersect Approve access by role and purpose
Vendor access is a maintenance convenience Each session crosses business and production zones Govern third-party sessions as controlled exceptions
Network zones remain static Devices, services, and data flows change over time Review permitted communications continuously
Security action always means blocking traffic A block may affect availability or safety Match enforcement to operational consequence

Which pressures raise the stakes for plant access?

The risk is not limited to the loss of business data. NIST SP 800-82 Rev. 3 describes OT environments as a distinct setting where specialized protocols, legacy systems, and availability requirements shape control choices. A connection that seems ordinary to IT may carry a different consequence on the plant floor.

  • Connected operations: Cloud analytics and production systems create new paths that need clear ownership.
  • Supplier access: Vendors need task-specific entry, not broad persistent connectivity.
  • Legacy exposure: Older equipment often requires controls around the asset rather than software installed on it.
  • Business interruption: A production delay can affect shipments, suppliers, and customer commitments.

Verizon’s 2024 manufacturing snapshot also notes that incidents can disrupt production and downstream supply-chain commitments. The leadership test is simple: if nobody can explain why a connection exists, who owns it, and how it is reviewed, it is not a dependable production access path.

Which Zero-Trust Model Fits Factory OT?

A manufacturing model needs to assess more than network segmentation. It must classify asset consequence, establish confidence in identities, define permitted communications, select safe enforcement, and retain evidence of what occurred. The aim is to reduce unnecessary trust without forcing fragile OT assets into controls they cannot safely support.

Purdue Model zones and firewalls remain useful foundations for separating enterprise and operational networks. NIST recommends an industrial demilitarized zone (DMZ) to prevent direct corporate-to-OT traffic, alongside multi-factor authentication (MFA) for remote access into OT systems. Those structural controls become more effective when access decisions also account for the user, device, application, and task.

That broader model addresses a documented exposure pattern. Verizon’s 2024 Data Breach Investigations Report manufacturing snapshot recorded 2,305 security incidents and 849 confirmed data-disclosure breaches in manufacturing; System Intrusion, Social Engineering, and Miscellaneous Errors represented 83% of those breaches. The point is not that every plant has the same exposure. It is that access decisions need evidence beyond a device’s network address.

Think of the model as a factory visitor register that also checks which room someone needs, when they need it, and what work they are approved to perform. A badge at the gate does not authorize access to every production area.

  • Asset criticality: Identify the operational consequence if the asset or flow becomes unavailable or changes unexpectedly.
  • Identity confidence: Judge how reliably a person, device, or service can be identified.
  • Permitted communications: Document the systems, protocols, and paths required for normal work.
  • Enforcement safety: Decide whether blocking, limiting, or observing traffic is safe for that function.
  • Evidence quality: Retain records that show who connected, what was allowed, and what changed.
Framework dimension Leadership question Signal to assess Primary data source Common misread
Asset criticality What fails if access changes? Safety and production consequence Asset inventory and operations input Treating all devices alike
Identity confidence Who or what is connecting? Strength of user, device, or service identification Identity records and network telemetry Assuming an IP address proves identity
Permitted communications Which flows are required? Documented normal paths Traffic baselines and application owners Allowing broad zones by default
Enforcement safety What action is safe? Latency, maintenance, and process constraints Engineering and OT review Blocking first and assessing later
Evidence quality Can the decision be reviewed? Attributable access records Session and change records Equating policy documents with proof

How should leaders define trust by operational role?

Reliable OT identity means identifying an asset well enough to apply a predictable policy for its operational role. A PLC, engineering workstation, historian, and industrial internet of things (IIoT) gateway do not need identical controls because they create different consequences and support different technical capabilities.

Cloud Security Alliance guidance separates OT identity into human, non-human, and application or service identities. For older assets, identity may depend on fixed IP or MAC-address bindings, switch-port profiles, traffic fingerprints, or hardware roots of trust. These are indirect signals, so teams must pair them with communication baselines and change review.

  • Human identity: A named employee, contractor, or vendor authenticated for an approved task.
  • Non-human identity: A PLC, HMI, sensor, camera, workstation, or gateway identified by its expected behavior and connection context.
  • Service identity: An application connection between systems such as manufacturing execution systems (MES), historians, and cloud services.

Which enforcement choices preserve production continuity?

Enforcement must reflect what the asset can tolerate. ISA Global Cybersecurity Alliance guidance cautions against introducing zero-trust controls for essential functions where safety and availability constraints would be affected. Unexpected traffic is often an investigation signal first, particularly when an automatic block could interrupt a critical process.

  • Inline enforcement: Apply direct control to assets such as engineering laptops, HMIs, and Windows servers when testing confirms that policy enforcement will not affect required operations.
  • Indirect enforcement: Use monitoring, gateway controls, segmentation, and out-of-band response around fragile legacy systems that cannot safely accept agents or intensive inspection.

This distinction keeps security teams focused on the right decision: whether the control produces a safer operating condition, not whether it appears more restrictive on a dashboard.

How Do Leaders Assess Factory Trust Controls?

Leaders should assess whether access decisions are visible, attributable, and enforceable in production conditions. A meaningful scorecard tracks coverage of assets and flows, identity assurance, segmentation fidelity, remote-session accountability, and safe response capability. A maturity label has little value if teams cannot show how a supplier reached an HMI or why that connection was permitted.

Visibility is the starting point, not the outcome. In a sample of more than 125,000 OT assets, Claroty Team82’s 2024 An Open Door report found that 13% of engineering workstations and HMIs were insecurely connected to the internet; 36% of those assets had at least one Known Exploited Vulnerability. That finding directs attention to management paths and internet-facing systems before a broad architecture refresh.

  1. Asset and flow coverage – Maintain an inventory and document the normal communications required by critical assets.
  2. Identity assurance – Use unique human, device, and service identities that match each asset’s technical capability.
  3. Segmentation fidelity – Confirm that high-consequence flows remain limited to approved zones and conduits.
  4. Remote-access accountability – Require attributable, time-bound, monitored access for suppliers and technicians.
  5. Safe response capability – Show how teams investigate or contain anomalies without creating uncontrolled production interruption.
Control criterion Leadership signal Decision supported Common interpretation error
Asset visibility Critical devices and connections have accountable owners Where to focus assessment Assuming discovery equals control
Identity assurance Shared accounts are reduced and exceptions are recorded Which access paths need redesign Treating login success as authorization
Segmentation fidelity Approved flows align with documented operational need Whether zones constrain movement Measuring zone count alone
Session accountability Vendor activity is attributable and reviewable Whether remote access meets policy Retaining records without reviewing them
Safe response Teams know when to observe, limit, or isolate Whether response protects uptime Using automatic blocking as the default

Remote access often reveals the gap between a written policy and daily operations. SANS Institute’s 2023 ICS/OT Cybersecurity Survey found that only 25% of surveyed industrial facilities collected and correlated remote-access event data, remote security-access logs, and data transfers over remote connections. Reviewable session evidence gives leaders a practical way to test whether least-privilege production access is working.

Use directional improvement rather than universal thresholds. The right question is whether each review produces clearer ownership, fewer unexplained paths, and safer response choices for the assets that matter most.

What Roadmap Protects OT Without Disruption?

A phased OT security program reduces material risk before a plant redesigns every network. It starts with decision rights and evidence, then applies tested controls to the access paths with the greatest operational consequence. Teams build confidence when each phase protects production as well as information.

Paul Smith, co-author of the ISAGCA white paper, described zero trust as a base philosophy for organizing cyber strategy rather than a point product. That framing matters because IT, OT, engineering, and operations leaders need shared ownership of outcomes rather than a handoff to one security team.

  1. Set decision rights and safety guardrails – Agree who approves control changes, which assets need operations sign-off, and what production conditions must remain stable.
  2. Inventory assets and communication flows – Establish a baseline for controllers, engineering workstations, HMIs, MES, suppliers, and cloud connections.
  3. Prioritize high-consequence access paths – Address vendor connectivity, engineering access, safety-adjacent systems, and management assets first.
  4. Pilot segmentation and identity controls – Begin in a controlled area, test failure conditions, and validate operator workflows before wider use.
  5. Monitor, review, and extend – Use session evidence and operational feedback to refine policies before expanding them.
Roadmap phase Primary decision Production-protection check
Guardrails Who owns approval and escalation? Operations confirms safe change boundaries
Baseline Which assets and flows are essential? Critical paths have named owners
Prioritization Which connections create the greatest consequence? Remote and engineering access receive early review
Pilot Which controls work in a contained area? Teams test latency and workflow effects
Extension Where should policy expand next? Evidence supports the next decision

CISA’s remote-access guidance recommends removing direct remote connections to critical operational assets and using DMZs, MFA, role-based authorization, and dedicated remote-access infrastructure. A phased approach makes those principles operational while keeping plant teams in control of each change.

Five Failures That Stall Factory Zero Trust

Programs lose credibility when control design ignores how production work actually happens. The most common failures are governance failures: unclear policy ownership, access exceptions that outlive their purpose, and evidence that never reaches the leaders who need to act on it.

  • Copying IT controls into safety-critical workflows – Validate operational consequences before applying enforcement to assets with strict availability or timing requirements.
  • Treating asset discovery as a one-time project – Update inventory and communication baselines as suppliers, IIoT devices, and cloud connections change.
  • Using shared or standing vendor accountsCISA requires continuous verification and least-privilege access in OT; shared identities remove the attribution needed to enforce both.
  • Segmenting without owning policy exceptions – Assign an owner and review date to every temporary pathway before it becomes permanent practice.
  • Measuring compliance instead of operational evidence – Use connection records, change history, and observed behavior to test whether policy matches reality.

Cloud Security Alliance advises that vendor and technician access be time-bound and tied to specific tasks rather than broad standing access. When an exception has a named owner, defined purpose, and review point, it stops being an invisible route into production.

RealVNC and the Manufacturing Zero-Trust Access Problem

Defined zones and identity policies weaken when vendor support, engineering maintenance, and incident remediation still rely on shared credentials or persistent connectivity. Those sessions often cross corporate IT, engineering workstations, production-adjacent systems, and supplier networks. A remote-support workflow therefore needs the same decision discipline as other industrial access paths: named users, limited rights, a defined purpose, and evidence for review.

RealVNC Connect Security provides controls for that session layer. MFA and single sign-on (SSO) with Microsoft Entra ID or Okta support attributable authentication for approved personnel. Role-based access controls (RBAC) and granular action-based permissions allow organizations to separate viewing, keyboard and mouse control, and file-transfer rights according to job role. Session monitoring, recording, and detailed audit logs give authorized administrators evidence for reviews and investigations. Code Connect uses single-use nine-digit session codes within a short configurable window, helping teams govern attended third-party access without maintaining broad standing connectivity.

Manufacturing workflow RealVNC Connect control Governance outcome
Engineering support MFA and SSO Named authentication for approved personnel
Role-specific remote work RBAC and action-based permissions Rights match the task being performed
Supplier troubleshooting Code Connect Time-bound attended access without standing credentials
Post-session review Monitoring, recording, and audit logs Reviewable evidence of remote activity

RealVNC Connect does not replace industrial network segmentation, asset inventory, or safety engineering. It provides a controlled and reviewable remote-session path within the wider connected-factory trust architecture, so third-party and support access can meet the same accountability standard as the rest of the OT environment.

Final Words

Zero trust in manufacturing turns factory access into a decision your teams can explain and review. Start with the assets and communication paths where an unsuitable connection would interrupt production, then match identity checks, segmentation, and enforcement to each system’s operational role. A supplier session, engineering workstation, and legacy controller need different treatment because their technical limits and production consequences differ. Keep IT, OT, engineering, and operations accountable for the same access decision. They need to know who connected, why the connection was approved, which rights applied, and whether the response preserved safe operations.

Governed remote access is where that discipline becomes visible in daily work. RealVNC Connect Security (2026) supports multi-factor authentication (MFA) and single sign-on (SSO) with Microsoft Entra ID or Okta, while role-based access controls (RBAC) and granular action-based permissions keep session rights aligned to the task. Session recording and detailed audit logs give leaders reviewable evidence after support work, so they can test whether least-privilege production access holds up outside policy documents. When each session is attributable and reviewable, vendor maintenance no longer depends on a permanent route that nobody revisits. Arrange a meeting to discuss how RealVNC Connect can help make manufacturing remote access more controlled, attributable, and audit-ready.

FAQs

These answers connect the article’s factory-specific access model with broader zero-trust questions from enterprise security discussions.

What framework guides zero trust in manufacturing?

Zero trust in manufacturing is a risk-based access model that continuously validates identity, context, and risk before allowing access to production resources. The model assesses asset criticality, identity confidence, permitted communications, enforcement safety, and evidence quality alongside Purdue-aligned segmentation. CISA’s joint OT guidance (2026) defines continuous validation, while NIST SP 800-82 Rev. 3 (2024) requires OT decisions to account for safety, reliability, and performance.

What is the difference between IT and OT zero trust?

IT zero trust often applies agents, patches, and inline controls more freely, while OT zero trust must preserve deterministic behavior, maintenance windows, and safety functions. The principles remain consistent: verify users and devices, grant least-privilege access, and review activity. ISA Global Cybersecurity Alliance guidance (2024) cautions that controls must not affect essential functions, and CISA guidance (2023) reinforces continuous verification and least privilege.

Which standards shape industrial access governance?

NIST SP 800-82 and ISA/IEC 62443 are two useful anchors for industrial access governance. NIST addresses OT architecture, including industrial demilitarized zones (DMZs) and multi-factor authentication (MFA) for remote access, while ISA/IEC 62443 provides an industrial cybersecurity framework for structuring security outcomes. These standards guide decisions; they do not certify a complete deployment or settle every regional regulatory requirement.

What are the five pillars of Zero Trust?

The five pillars are often framed as asset criticality, identity confidence, permitted communications, enforcement safety, and evidence quality. Together, they help leaders assess who or what is connecting, which flows are required, what action is safe, and whether the decision can be reviewed. This is a practical manufacturing lens rather than a single universal standard.

What are examples of Zero Trust in a factory?

Examples include requiring MFA for remote OT access, placing an industrial DMZ between corporate and production networks, and granting a vendor access only for an approved task. A plant might also monitor a legacy controller indirectly when installing an endpoint agent could affect availability. Each example applies verification and least privilege while respecting the equipment’s operating limits.

Why does Zero Trust fail?

Zero trust fails when teams copy office-IT controls into safety-sensitive workflows, leave shared vendor accounts in place, or measure policy completion instead of actual access behavior. CISA’s OT guidance (2023) requires continuous verification and least-privilege access, while Cloud Security Alliance guidance (2025) recommends task-specific, time-bound vendor access. Without shared decision rights across IT, OT, engineering, and operations, exceptions become permanent routes.

How does RealVNC support OT support workflows?

RealVNC Connect controls the remote-session layer through MFA, single sign-on (SSO), role-based access controls (RBAC), and granular action permissions. Session monitoring, recording, detailed audit logs, and Code Connect time-bound session codes provide accountable access and reviewable activity for supplier or technician support. It complements OT segmentation, asset inventory, industrial monitoring, and safety engineering rather than replacing them.

Learn more on this topic

Need to reach a Windows PC from a Raspberry Pi? Here's how to set up remote access with RealVNC Connect....
Edge computing in manufacturing keeps quality and production decisions moving locally - but what happens when every plant must secure,...
Need to reach a Windows PC from your Mac? Here's how to set up secure, cross-platform remote access using RealVNC...

Try RealVNC® Connect today for free

No credit card required for 14 days of free, secure and fast access to your devices. Upgrade or cancel anytime