When a production line stops, the pressure reaches well beyond the control room. Maintenance needs the right specialist working quickly, while operations and leadership need to know that a remote connection will not grant access beyond the task at hand.
Third-party vendor remote access manufacturing is the controlled delivery of remote support for external equipment providers and specialists, limited to the approved industrial asset, maintenance purpose, and work window. It relies on named identities, multi-factor authentication (MFA), narrow permissions, session oversight, retained records, and prompt revocation so support remains available without leaving standing routes into operational technology (OT).
The difficulty often starts with a legitimate request: an original equipment manufacturer engineer needs to diagnose a controller issue or apply an approved update. Shared virtual private network credentials and standing administrator accounts make it harder to show who reached which system, what they did, and whether access ended when the work did. In a plant environment, a connection intended for one engineering workstation must not become wider network reach.
Think of each supplier session as a temporary visitor pass for a restricted plant area. It names the person, opens the required door for a defined job, expires when work ends, and leaves a record that security and operations can review.
This article sets out how manufacturers can replace persistent, network-level supplier connections with individually authenticated, time-bound sessions routed through an operational technology demilitarized zone (DMZ). It covers asset scope, approval controls, monitoring, recorded evidence, revocation readiness, and the operating decisions that keep remote maintenance accountable.
How does vendor access change manufacturing risk?
Supplier access changes manufacturing risk because it connects external identities and devices to operational technology (OT) assets where availability and safety carry direct production consequences. The right response is controlled trust, not blanket denial: give an original equipment manufacturer (OEM) engineer or integrator a defined route to the approved system for the approved task, then remove that route when work ends.
That distinction has become more pressing as third-party involvement rises. Verizon’s 2025 Data Breach Investigations Report: Executive Summary found that 30% of breaches involved a third party in 2025, compared with 15% in the prior year. For a manufacturer, the question is not whether a supplier is valued; it is whether their connection is governed at the same level as other privileged activity.
A production network was often built for reliable, deterministic communications rather than strict separation between every user and asset. Broad virtual private network (VPN) routes, shared jump-host accounts, and persistent remote-control connections can join a supplier laptop to more of that environment than a maintenance task requires. CISA’s remote-access guidance recommends demilitarized zones (DMZs) to separate business and control architectures.
Which conditions turn supplier access into exposure?
Consider a controlled maintenance work order. It names the technician, production cell, permitted task, and finish time. A governed remote session should work the same way, rather than functioning as an open-ended network pass.
- Shared identity: A team credential removes individual accountability and makes offboarding difficult when a contract or role changes.
- Broad route: Network-level reach exceeds the particular asset or application required for maintenance.
- Persistent entitlement: Access remains active between scheduled work windows and contract milestones.
- Unobserved session: Teams know a connection occurred but cannot reconstruct meaningful activity.
CISA’s Guide to Securing Remote Access Software notes that threat actors use externally facing remote services, including VPNs, to gain initial access and maintain remote presence. An industrial DMZ changes the decision model by placing a controlled boundary between the vendor and the target environment. It makes the approved connection route visible, reviewable, and easier to end.
| Access assumption | Legacy operating model | Governed OT access model |
|---|---|---|
| Identity | Shared supplier or administrator account | Named external user with accountable internal sponsor |
| Network reach | Routed connectivity to a network segment | Brokered route to a defined asset and protocol |
| Approval duration | Access persists after support work | Approval aligns to a maintenance window |
| Evidence and revocation | Connection record only; manual account changes | Session record and an owned process to end access |
Which controls define secure vendor access to OT?
Secure remote maintenance depends on five controls operating together: Asset Scope, Individual Identity, Time-Bounded Approval, Brokered Delivery, and Session Evidence. Multi-factor authentication (MFA) proves who is requesting access, but it does not define what that person can reach or whether the activity can be reviewed afterward.
The framework joins architecture to operating policy. ENISA’s NIS Investments 2025: Main Report found that 48% of surveyed entities identified supplier-contract security requirements as their most common supply-chain security measure. Contract language matters, yet a requirement has little operational value unless the access path enforces it during each support event.
- Asset Scope: Define the specific systems, applications, and protocols a supplier needs for the maintenance purpose.
- Individual Identity: Require a named vendor user and an internal sponsor who remains accountable for the relationship.
- Time-Bounded Approval: Link access to a defined work order and expiry time rather than a continuing entitlement.
- Brokered Delivery: Route the session through a controlled industrial boundary instead of providing direct vendor-device access to OT.
- Session Evidence: Retain records that show activity, scope, timing, and how the connection ended.
ENISA’s Technical Implementation Guidance on Cybersecurity Risk-Management Measures calls for a supply-chain security policy governing relationships with direct suppliers and service providers. That policy must assign decision rights across procurement, OT engineering, security, and the plant asset owner.
How should the Purdue model shape access scope?
The Purdue Reference Model helps leaders match access rights to the consequence of the target asset. It separates enterprise and business systems at Levels 4–5 from operations management at Level 3, supervisory systems at Level 2, control systems at Level 1, and field devices at Level 0.
Most support sessions target Level 3 historians, manufacturing execution system (MES) platforms, or engineering workstations. Selected supervisory control and data acquisition (SCADA) and human-machine interface (HMI) systems at Level 2 may also require vendor work. Level 1 programmable logic controller (PLC), distributed control system (DCS), and safety-system access needs a higher approval standard because a change can directly affect physical operations.
A plant does not need to treat every connection identically. It needs to make asset criticality visible before approval, then require scheduled, dual-authorized, fully recorded sessions for Level 1 work where operational context warrants it.
What makes an access session defensible?
A defensible session produces three forms of proof: authentication proof identifies the person, authorization proof shows what they were allowed to do, and activity evidence records what occurred. A maintenance ticket alone is not authorization; it must activate a narrow entitlement tied to the target, protocol, technician, purpose, and time window.
ENISA’s Threat Landscape 2023 advises organizations to securely configure remote-access technology and enforce, audit, and manage MFA and strong password policies. Session evidence then gives operations and security teams a shared record for incident review, supplier accountability, insurance discussions, and audit requests.
| Framework control | Executive purpose | Required evidence | Primary owner | Common misread |
|---|---|---|---|---|
| Asset Scope | Limit operational consequence | Approved target and protocol | Asset owner | A network segment is a meaningful scope |
| Individual Identity | Establish accountability | Named user and sponsor | Security | A supplier company name identifies a person |
| Time-Bounded Approval | Limit standing privilege | Ticket, approver, expiry | Operations | An open ticket grants continuing access |
| Brokered Delivery | Control the session route | DMZ route and target record | OT architecture | A jump host alone defines least privilege |
| Session Evidence | Support review and intervention | Activity record and end event | Security | VPN logs explain session activity |
What proves a manufacturing vendor session is controlled?
)
A controlled supplier session produces proof of who connected, why access was granted, which assets and protocols were available, when permission expired, what activity occurred, and how the session ended. Leadership should be able to request that record during a monthly review or immediately after an anomalous maintenance event.
This evidence matters because OT asset scope cannot be treated as a paper exercise. IBM X-Force’s 2025 Operational Technology Threat Landscape reported that 49% of 670 OT-impacting vulnerabilities disclosed in the first half of 2025 had Critical or High Common Vulnerability Scoring System (CVSS) severity ratings. Prioritization starts with knowing which supplier sessions reach the systems that require the strongest controls.
- Named identity and sponsor: Confirm the accountable vendor user, internal sponsor, contract relationship, and current business purpose. Do not accept a shared mailbox or shared administrator account as equivalent evidence.
- MFA event and credential control: Confirm that each session uses enforced authentication suited to privileged work. A strong password does not provide multi-factor assurance.
- Asset and protocol scope: Confirm that the technician could reach only approved systems and protocols. “Connected to OT” is not a useful access description for an executive review.
- Time-bound authorization: Confirm that access began and ended within the approved maintenance window. An open work order must not become indefinite authorization.
- Recorded activity and termination record: Confirm a reviewable session record, relevant logs, and the ability to end active access. VPN connection logs alone stop at the network edge.
FedRAMP’s Identification and Authentication guidance requires organizations to uniquely identify and authenticate users and associate identity with processes acting on their behalf. That principle gives a CISO a clear test: if the record cannot identify the individual and their permitted activity, it does not establish accountable vendor access.
| Evidence criterion | What it demonstrates | Leadership decision enabled | Common error |
|---|---|---|---|
| Named identity | Accountable external user and sponsor | Retain or remove vendor access | Accepting a shared account |
| MFA event | Verified session authentication | Assess identity-control coverage | Treating passwords as MFA |
| Approved scope | Restricted systems and protocols | Approve asset-level access | Recording only network connection |
| Access-window adherence | Permission matched approved timing | Identify standing-access drift | Treating a ticket as perpetual approval |
| Activity record and termination | Reviewable activity and intervention | Investigate and improve controls | Assuming logs prove activity |
Trend lines carry more value than a universal maturity score. Repeated out-of-window requests, denied attempts against unapproved assets, and recordings without a review owner point to an operating gap that needs a named decision.
Build a vendor-access operating program
A vendor-access program works when it treats remote maintenance as an owned service rather than a collection of exceptions. The operating model must preserve rapid specialist support while keeping procurement, OT operations, security, IT, and the supplier engagement lead accountable for distinct decisions.
- Inventory vendors and OT dependencies – Goal: identify each supplier, named user, plant, asset class, protocol, and business dependency. Inputs: configuration management database (CMDB), OT inventory, supplier register, and support contracts. Decision rights: plant and asset owners validate criticality. Pitfall: treating procurement records as a complete access inventory. Success check: every access relationship has an accountable internal sponsor.
- Set onboarding and contractual conditions – Goal: establish endpoint hygiene, named identities, MFA, non-shared devices, recording acceptance, incident-notification duties, and approved contacts. Inputs: third-party risk assessment and contract clauses. Decision rights: procurement and security approve baseline obligations. Pitfall: adding requirements after an outage. Success check: contract controls map directly to access policy.
- Design the approved session path – Goal: route access through an industrial DMZ and approved broker or jump environment with explicit asset scope. Inputs: Purdue zoning, protocol needs, and safety constraints. Decision rights: OT architecture and plant engineering approve. Pitfall: creating a convenience exception around segmentation. Success check: no direct vendor-device route reaches production assets.
- Authorize work just in time – Goal: link maintenance work to a narrow time, asset, protocol, and approval chain. Inputs: approved ticket, work order, and operations schedule. Decision rights: the asset owner and operations approve higher-consequence work. Pitfall: confusing a standing identity with standing permission. Success check: expired tickets remove access through an owned process.
- Review evidence and rehearse revocation – Goal: assess session records, unusual events, and emergency termination readiness. Inputs: audit logs, recordings, access exceptions, and incident findings. Decision rights: security owns the review cadence while operations validates plant impact. Pitfall: collecting logs without a review owner. Success check: annual exercises show that an active session can be stopped and investigated.
The industrial boundary is the architectural anchor for this program. CISA’s industrial-control-system remote-access guidance recommends a DMZ to separate business and control architectures, giving teams a defined place to apply access policy and observe sessions.
| Operating context | Control emphasis | Implication |
|---|---|---|
| Single-site manufacturer | Asset ownership and support continuity | Keep approvals close to the plant owner |
| Multi-plant enterprise | Common policy with local asset context | Centralize standards; retain site approval rights |
| Highly regulated operator | Evidence retention and formal approval | Map session records to contractual and regulatory duties |
| Contract-manufacturing ecosystem | Supplier concentration and shared dependencies | Review access across customer, plant, and supplier boundaries |
The program changes by operating context, but the core decision remains stable: retain the vendor identity for a recurring contract if needed, while enabling its access only during approved maintenance windows.
Which access failures threaten manufacturing uptime?
The most persistent access failures are often familiar controls used without enough scope, ownership, or evidence. VPNs, jump hosts, and remote-support tools may remain necessary during a transition, yet each needs compensating controls when it reaches plant systems.
- Shared administrative paths: Multiple suppliers use the same VPN credential, local administrator account, or jump-host identity. Attribution and offboarding then become unreliable, which conflicts with FedRAMP’s 2025 identity guidance.
- Network reach that exceeds work scope: A technician needs one engineering workstation but receives routable access to a wider OT segment. The issue is not the connection alone; it is the gap between the approved task and reachable systems.
- Emergency exceptions that become permanent: Temporary access survives an outage, project completion, or contract change. Exception registers need expiry dates, owner review, and a clear removal process.
- Evidence that stops at the network edge: Teams retain connection logs but cannot identify the target system or activity inside the session. That leaves incident review dependent on recollection rather than records.
Containment decisions show why these gaps matter operationally. WisdiaM’s 2024 account of Varta reports that the company halted production at all five global production sites after disconnecting systems from the internet during a cyberattack. The case does not establish a vendor-access cause, but it illustrates the production trade-off when teams need to contain uncertainty quickly.
A realistic remediation roadmap starts with tabletop exercises and access-review findings. Rank the connections that combine broad reach, persistent entitlement, weak attribution, and production consequence, then assign an owner and deadline for each correction.
RealVNC and the Manufacturing Vendor Access Problem
)
A vendor onboarding workflow and industrial DMZ architecture still leave a practical gap when remote support relies on shared credentials, permanent access, or records that do not explain the session. Plant teams need an OEM or integrator to connect promptly during a maintenance event, while IT and OT security need named identity, just-in-time approval, defined scope, active-session revocation, and retained audit evidence.
RealVNC Connect supports a controlled third-party workflow through four outcome-focused capabilities. Code Connect uses 9-digit, time-bound session codes, allowing a team to initiate a specific external support interaction without leaving the connection permanently available. Multi-factor authentication and single sign-on (SSO) support identity verification, with Account SSO for Microsoft Entra ID and Okta on Enterprise plans. Role-based access controls (RBAC) and granular action-based permissions let teams separately control keyboard, mouse, and file-transfer activity, so the supplier’s available functions match the approved support purpose. Session monitoring, recording, and detailed audit logs provide active oversight, post-session review, and evidence for audit or incident investigation.
This does not replace the manufacturer’s wider OT security program, supplier due diligence, or industrial architecture decisions. It gives the remote-support interaction a clearer control point. For third-party vendor remote access manufacturing, RealVNC Connect is most relevant where support must remain rapid for operations while staying accountable to IT, OT security, and audit stakeholders.
Final Words
Every remote maintenance request forces a practical decision: give the right specialist access quickly without leaving a shared, network-level route into plant systems. Third-party vendor remote access manufacturing works best as an accountable service, where Asset Scope defines the target, Individual Identity establishes responsibility, and Time-Bounded Approval limits when access exists. Brokered Delivery places the session behind a controlled industrial boundary, while Session Evidence gives operations and security a record they can review when questions arise.
Leaving those controls disconnected turns routine supplier support into a recurring exception that is hard to review, revoke, or explain after an incident. RealVNC Connect provides a practical control point for these sessions: Code Connect initiates time-bound external support, role-based access controls limit available actions, and session recording with detailed audit logs retains evidence for operational review. Your wider OT architecture, supplier obligations, and approval process still set the policy; the remote-support workflow needs to enforce it consistently. Start a free trial of RealVNC Connect to evaluate controlled, auditable vendor access for your manufacturing support workflows.
FAQs
What is the five-control framework for supplier OT access?
Third-party vendor remote access manufacturing is best governed through five connected controls: Asset Scope, Individual Identity, Time-Bounded Approval, Brokered Delivery, and Session Evidence. Together, they define what a supplier can reach, who connects, when permission exists, how the session crosses network boundaries, and what evidence remains. The model gives leadership a way to review architecture and ownership in the same decision.
What is the difference between VPN access and brokered OT sessions?
VPN access commonly establishes network connectivity that routing and firewall policy then governs, while a brokered OT session delivers access to a defined target and protocol. VPNs may remain part of an enterprise architecture, but each manufacturer must assess whether a maintenance task requires network-level reach or a targeted session through a controlled boundary. CISA’s Guide to Securing Remote Access Software (2023) notes that externally facing remote services, including VPNs, are used for initial access and persistence.
Which standards and regulations shape remote maintenance policy?
Remote maintenance policy is shaped by the organization’s jurisdiction, entity type, contractual duties, and role in the supply chain. ENISA’s Technical Implementation Guidance on Cybersecurity Risk-Management Measures (2025) supports a supply-chain security policy for direct suppliers and service providers, while IEC 62443-2-1:2024 provides an asset-owner security-program reference. NIS2 and IEC 62443 requirements must be checked against the applicable Member State, organization, and licensed standard text.
What third-party vendors can access my manufacturing data?
Third-party vendors should access only the systems and information required for their approved maintenance purpose. Depending on the work order, that may include an engineering workstation, historian, manufacturing execution system, supervisory control and data acquisition system, or human-machine interface. Asset scope, protocol restrictions, individual identity, and session evidence must show what was available and what the technician actually used.
Which providers offer third-party risk management solutions?
Third-party risk management (TPRM) solutions help organizations assess suppliers, track contracts, record obligations, and review vendor relationships. They do not automatically define the OT session boundary or enforce asset-level remote permissions, so procurement, plant operations, security, and OT architecture must connect the TPRM process to the access workflow. A useful evaluation asks whether supplier records identify the internal sponsor, approved assets, contract conditions, review owner, and removal process.
How does RealVNC support manufacturing vendor-access workflows?
RealVNC Connect supports controlled vendor sessions through Code Connect, multi-factor authentication (MFA), single sign-on (SSO), role-based access controls, session monitoring, session recording, and detailed audit logs. Code Connect provides time-bound session codes, while granular permissions help control keyboard, mouse, and file-transfer actions during support. These controls give plant and security teams attributable access, active oversight, and reviewable evidence without replacing the manufacturer’s wider OT security program.

