How Should Manufacturers Secure Third-Party and Vendor Remote Access?

Manufacturing technician managing secure vendor remote access to industrial equipment and CNC systems.

A 6-Part Framework for Protecting Vendor Connections to Manufacturing IT and OT Systems

Manufacturers should secure third-party remote access by controlling who can connect, how they authenticate, which systems they can reach, when access is permitted, and what happens after the work is complete.

Outside vendors often need legitimate remote access to CNC machines, industrial equipment, ERP systems, servers, network infrastructure, building systems, and specialized manufacturing applications. The security problem occurs when temporary or narrowly defined access becomes a permanent pathway into a larger portion of the network.

A machinery vendor that needs 2 hours of remote access to diagnose one CNC machine does not necessarily need unrestricted access to the manufacturing network 24 hours a day, 365 days a year.

Manufacturers can use this six-part framework to control vendor access:

IDENTIFY → AUTHENTICATE → RESTRICT → SEGMENT → MONITOR → REMOVE

The goal is not to prevent vendors from supporting critical equipment. It is to give each vendor only the access required to perform the work while reducing unnecessary exposure to the rest of the environment.


Six-part manufacturing vendor remote access framework: identify, authenticate, restrict, segment, monitor and remove.

1. IDENTIFY: Know Every Vendor With Remote Access

Manufacturers cannot effectively secure vendor access until they know who can connect.

Start with an inventory of every third party that currently has remote access to the environment.

That inventory may include:

  • Machinery manufacturers
  • CNC equipment vendors
  • ERP providers
  • Industrial automation companies
  • Controls integrators
  • Software vendors
  • Security and surveillance vendors
  • Building-control vendors
  • Network providers
  • Specialized engineering vendors
  • Managed technology providers

For every vendor, document who has access, why access is required, how the connection is made, which systems can be reached, and who inside the company owns the vendor relationship.

A useful vendor-access inventory can be built around six questions:

Question Example
Who has access? CNC equipment vendor
Why is it needed? Remote diagnostics
How do they connect? Approved remote-access method
What can they reach? Specific CNC system
When is access needed? During maintenance
Who owns the relationship? Plant engineering manager

This process can identify connections that were established years ago for an installation, repair, or project but were never removed afterward.  Manufacturers should be able to produce a current list of outside organizations that can remotely enter the environment. If that list does not exist, creating it is a useful first step.

2. AUTHENTICATE: Verify Who Is Connecting

Remote access should be tied to an identifiable person whenever the technology allows it.

Generic accounts such as VendorSupport create accountability problems when multiple people know the same username and password.

If five vendor technicians share one account, a log showing that VendorSupport connected at 11:43 p.m. does not necessarily identify the person who actually made the connection. Individual accounts provide better visibility.

Manufacturers should also use multi-factor authentication (MFA) for remote access where supported. MFA requires another form of verification beyond a password, reducing reliance on a single credential.

Vendor authentication should address four areas:

Individual identity — Know which person is connecting.

Unique credentials — Avoid unnecessarily shared accounts.

MFA — Add another authentication factor where supported.

Account lifecycle — Disable accounts when they are no longer required.

Legacy manufacturing technology can complicate this process.  A machine installed 10 or 15 years ago may rely on software that was never designed to support modern authentication. In those situations, manufacturers can evaluate whether stronger authentication can be implemented at the remote-access layer before the vendor reaches the legacy equipment.

The inability to add MFA directly to one machine does not necessarily mean the entire remote-access process has to rely only on a password.

3. RESTRICT: Give Vendors Only the Access They Need

Vendor access should follow the principle of least privilege.

A technician troubleshooting one CNC machine does not automatically need access to file servers, employee computers, accounting systems, Microsoft 365, other production equipment, or the rest of the corporate network. Access can be restricted across several dimensions.

Restrict by System

Allow access only to the equipment or application the vendor supports.

Restrict by Permission

Provide only the permissions required to perform the approved work.

Restrict by User

Authorize specific vendor personnel instead of everyone employed by the vendor.

Restrict by Time

Where practical, make access available during an approved maintenance or support period rather than leaving it continuously available.

Consider a machinery vendor scheduled to troubleshoot equipment between 1:00 p.m. and 3:00 p.m.

The business requirement is approximately 2 hours of access to a particular system.  That is different from a business requirement for unrestricted access to the production network every day of the year.

Time-limited access can be particularly useful for vendors that connect only occasionally for maintenance or troubleshooting.

4. SEGMENT: Separate Vendor Access From Unrelated Systems

Manufacturing networks can contain a combination of traditional information technology, operational technology, and specialized production systems.

Traditional IT may include:

  • Employee workstations
  • Servers
  • Microsoft 365
  • Business applications
  • File storage
  • Email
  • ERP systems

Production-related and OT environments may include:

  • CNC equipment
  • Industrial control systems
  • PLCs
  • HMIs
  • Production machinery
  • Industrial IoT devices
  • Specialized manufacturing systems

Not every device needs unrestricted communication with every other device.

Network segmentation can create boundaries based on the systems’ functions and communication requirements.

For example, a vendor supporting a CNC machine may need a controlled path to that equipment without needing a path to the accounting network.

Segmentation becomes especially important when dealing with legacy equipment.  Manufacturing equipment can remain productive much longer than a typical office computer. A machine may continue producing parts reliably even though its underlying operating system or software no longer receives modern security updates.  Replacing the computer may also be difficult if proprietary software, controllers, drivers, or the machinery itself depends on the existing configuration.

When those systems cannot be modernized immediately, manufacturers can consider additional controls around them, so a good model to use is:

Legacy System + Segmentation + Restricted Access + Monitoring

The appropriate design depends on the equipment and production requirements, but an older system does not have to be given unrestricted access to the rest of the environment simply because it cannot be upgraded.

5. MONITOR: Maintain Visibility Into Vendor Connections

Manufacturers should have visibility into third-party remote access where their technology supports it.

Useful connection information can include:

  • Which vendor connected
  • Which individual account was used
  • When the connection started
  • When the connection ended
  • Which system was accessed
  • Whether authentication attempts failed
  • Whether unusual activity occurred

Logging becomes valuable when investigating suspicious activity.

For example, if an organization detects unusual activity at 2:15 a.m., remote-access logs can help determine whether a vendor account was active during that period.  Monitoring should also reflect the manufacturer’s operating environment.  Activity at midnight is not automatically suspicious for a manufacturer operating three shifts. The same activity may deserve additional attention if the vendor normally connects only during scheduled daytime maintenance.

The objective is to establish enough visibility to distinguish expected vendor activity from activity that deserves investigation.

Manufacturers with 24-hour operations should also consider whether their cybersecurity monitoring continues outside normal office hours.

6. REMOVE: Revoke Access When It Is No Longer Needed

Vendor access should have an end point.

Remote access can remain active long after the original reason for creating it disappears. Equipment gets replaced. Projects end. Support contracts change. Vendor employees leave. Companies switch suppliers. Access should change with those events.

Manufacturers should review vendor access after events such as:

  • Contract termination
  • Equipment replacement
  • Project completion
  • Vendor changes
  • Vendor employee departures
  • Security incidents
  • Major network changes

Periodic reviews can identify accounts and connections that no longer have a legitimate business purpose.

No current business requirement = no current remote access.

Manufacturers should also consider the removal process when access is first approved.  If a vendor receives temporary access for a project scheduled to finish on Friday, determining on Monday who will eventually remove that access is better than discovering six months later that the account is still active.


Example: Securing Remote Access to a CNC Machine

A manufacturer experienced an error on a CNC machine.  The equipment manufacturer determines that a technician needs remote access for approximately 2 hours, from 1:00 p.m. to 3:00 p.m.

Using the six-part framework, the manufacturer can structure the connection as follows.

IDENTIFY

The manufacturer identifies the equipment vendor and the specific technician performing the work.

AUTHENTICATE

The technician connects using an individual identity and MFA at the appropriate remote-access layer where supported.

RESTRICT

The technician receives only the permissions and system access necessary to diagnose the CNC machine.

SEGMENT

The connection provides a controlled path to the required production system without providing unnecessary access to employee workstations, financial systems, or unrelated equipment.

MONITOR

The connection is logged, providing a record of when the technician connected and which system was accessed.

REMOVE

When troubleshooting is complete, temporary access is disabled or returned to its approved restricted state.

The equipment vendor still receives the access needed to perform its work, but the manufacturer avoids turning a 2-hour maintenance requirement into an unnecessary permanent remote-access pathway.


How Should Manufacturers Handle Legacy Equipment?

Legacy equipment deserves special attention because replacing it is often neither simple nor inexpensive.

A production machine may have a useful life measured in decades, while the computer or operating system associated with it can become outdated much sooner. That creates a practical cybersecurity problem. The manufacturer may not be able to patch the system, install modern endpoint protection, or enable MFA directly on the equipment.

Manufacturers should distinguish between:

“We cannot modernize this system today.”

and

“We cannot protect this system.”

Additional protections can often be placed around legacy technology, so depending on the environment, those protections may include:

  • Network segmentation
  • Restricted inbound communication
  • Restricted outbound communication
  • Controlled remote-access gateways
  • Stronger authentication before reaching the legacy environment
  • Limited vendor permissions
  • Monitoring
  • Backup and recovery
  • Removal of unnecessary internet connectivity

The objective is to reduce exposure while maintaining the availability of equipment the manufacturer still needs for production.


How Does Vendor Remote Access Affect NIST 800-171 and CMMC?

Vendor access can become particularly important for manufacturers working in defense or other regulated supply chains.

NIST SP 800-171 and CMMC place significant emphasis on areas that can intersect with remote third-party access, including access control, authentication, system boundaries, monitoring, and accountability. Manufacturers should understand whether outside vendors can access systems that store, process, or provide pathways to sensitive information.

Think about:

  • Which vendors can reach systems containing controlled information?
  • Are third-party identities individually managed?
  • Is remote access appropriately authenticated?
  • Are connections logged?
  • Are permissions limited?
  • Is third-party access documented?
  • Are unnecessary accounts removed?
  • Can vendor connections cross between systems that should be separated?

Vendor access should therefore be considered when defining the organization’s cybersecurity environment rather than treated solely as a maintenance issue handled by an equipment vendor.


What Are the Most Common Vendor Remote Access Problems?

Manufacturers reviewing existing vendor connections should look for several recurring problems.

One is permanent access created for temporary work. A vendor receives remote connectivity during installation and retains it indefinitely.

Another is shared credentials. Multiple vendor employees use the same account, reducing accountability.

A third is excessive network access. A vendor needs one system but can reach a much larger portion of the network.

Legacy remote-access software can also remain in production long after better alternatives become available.

Finally, organizations may simply lose track of who has access. When machinery vendors, software providers, contractors, integrators, and IT companies have accumulated over many years, nobody may have a complete inventory.  These problems are exactly what the six-part framework is intended to uncover.


10 Questions to Ask About Your Current Vendor Access

Manufacturers can use these questions as a quick assessment:

  1. How many outside vendors currently have remote access?
  2. Can we identify every individual who can connect?
  3. Are any vendors using shared accounts?
  4. Is MFA required where technically possible?
  5. Can each vendor reach only the systems it needs?
  6. Can vendors unnecessarily cross between IT and OT environments?
  7. Are remote connections logged or monitored?
  8. Do vendors have permanent access when temporary access would be sufficient?
  9. How quickly can we disable vendor access?
  10. When did we last review every third-party connection?

If several of these questions cannot be answered, an inventory and access review can provide a useful starting point.


Frequently Asked Questions About Vendor Remote Access Security

Should manufacturing vendors have permanent remote access?

Not necessarily. Access should reflect the legitimate support requirement. If a vendor needs approximately 2 hours to perform occasional remote maintenance, that does not automatically require unrestricted 24/7/365 access. Some systems may require persistent connectivity, but the business and technical requirement should be documented.

Should every vendor remote-access account use MFA?

MFA should be used for remote access where the systems and architecture support it. When legacy manufacturing equipment cannot support MFA directly, manufacturers can evaluate whether stronger authentication can be implemented at a remote-access gateway or another layer before the vendor reaches the legacy system.

What is least-privilege vendor access?

Least privilege means providing only the systems and permissions necessary for the vendor’s work. A technician supporting one CNC machine should not automatically receive access to file servers, employee computers, financial applications, or unrelated production equipment.

How can manufacturers secure remote access to legacy equipment?

Legacy systems can be protected with compensating controls such as network segmentation, restricted connectivity, secure remote-access methods, stronger authentication, limited permissions, monitoring, and backup and recovery. The appropriate controls depend on the equipment and production requirements.

Should manufacturing IT and OT networks be segmented?

Segmentation can reduce unnecessary communication between IT, OT, and other systems and limit what a compromised account or device can reach. The appropriate architecture depends on legitimate communication requirements between production and business systems.

What should happen when a vendor no longer needs access?

The associated remote-access accounts, permissions, and connections should be disabled when there is no longer a legitimate business requirement. Manufacturers should include access removal when contracts end, equipment is replaced, projects finish, or vendor personnel change.


Final Thoughts

Manufacturers can manage third-party remote access through six repeatable controls:

IDENTIFY → AUTHENTICATE → RESTRICT → SEGMENT → MONITOR → REMOVE

The framework addresses the complete lifecycle of a vendor connection—from determining who needs access through removing that access when the business requirement ends.

It also accommodates the realities of manufacturing. Vendors need to support specialized equipment. Legacy systems cannot always be modernized immediately. Production schedules can limit maintenance windows. Some machinery may remain operational for decades.

Those realities make controlled access more important, not less.

A vendor that needs access to one machine for two hours should receive the access necessary to complete that work without automatically receiving a permanent pathway into unrelated systems.

About AT-NET

AT-NET provides managed IT, cybersecurity, infrastructure, cloud, backup and disaster recovery, and strategic technology services for manufacturers.

We support more than 75 manufacturing clients and have served businesses since 1999. Managed IT clients receive an internally staffed 24/7/365 help desk with less than 60-second response, along with dedicated Technical Alignment Managers and dedicated vCIOs.

AT-NET works with manufacturers to identify technology risks, strengthen cybersecurity, manage infrastructure, and improve visibility across connected IT and manufacturing environments.

Need to Review Your Manufacturing Vendor Access?

AT-NET can help evaluate how third-party vendors connect to your IT and production-related systems, identify unnecessary access, and determine where stronger authentication, segmentation, monitoring, or access controls may be appropriate.

Request a Manufacturing Cybersecurity Assessment

Picture of Jeffrey King
Jeffrey King

President of AT-NET | Managed Technology Solutions Expert | Cybersecurity Specialist

Jeffrey King is an experienced leader in managed technology solutions with more than 20 years of expertise. As President of AT-NET, he oversees a wide range of services including IT support, cloud solutions, cybersecurity, and business risk management.

His work focuses on cybersecurity and network architecture, with hands-on skills across Unix, VMware, Linux, Cisco, and Microsoft systems. Under his leadership, AT-NET delivers solutions in areas such as compliance (HIPAA, CMMC, PCI, SEC, FINRA), vulnerability management, data backup and recovery, email and endpoint security, and IT project management.

Jeffrey also guides initiatives in co-managed IT services, structured cabling, VoIP systems, and integrated security technologies such as cameras and access control.

Get in touch with our experts and get a free consultation

Recent Posts:
To safeguard your business against the unexpected, contact us for a free consultation.

Together, we can build a resilient future for your business.