
Vendor Remote Access: The OT Risk Most Manufacturers Miss
A precision machining shop in Hialeah spent $280,000 recovering from a ransomware attack last year. The entry point was a remote desktop session left open by a CNC equipment vendor who had finished a service call three weeks earlier. The vendor's technician connected from a personal laptop at home, and the malware sitting on that laptop found its way into the shop's programmable logic controllers.
Two production lines sat idle for nine days. The shop owner had no idea those vendor credentials were still active. He'd handed them out at the start of a maintenance contract two years earlier and never reviewed them again.
South Florida manufacturers, from precision shops in Doral to food processors in Medley, tend to hand out vendor access at the start of a contract and review it never. Every equipment manufacturer, PLC integrator, HVAC contractor, and automation vendor that connects to your production systems is an entry point. The question is whether you control that entry point or leave it open indefinitely.
Key Takeaways
- Third-party vendor access is the most common confirmed entry point for OT network breaches in manufacturing.
- Most manufacturers have no formal process for provisioning, auditing, or revoking vendor credentials.
- Each vendor connection should use time-limited credentials tied to a specific maintenance window, not standing access that persists for years.
- CMMC Level 2 requires access control documentation that covers third-party and remote user access specifically.
- A vendor access audit takes less than one business day and costs nothing but time.
Why Vendor Access Creates Bigger Risk Than Employee Access
Your employees' credentials have at least one thing going for them: when someone leaves, your HR or IT process usually catches it. Not always, but there's a system. Vendor access has no equivalent trigger. A contractor finishes a job, you pay the invoice, and the VPN credentials you issued never get revoked. Three months later, those credentials are still sitting in your system, fully valid.
The 2021 Oldsmar, Florida water treatment incident is the most referenced example in OT security discussions. An attacker used a remote access tool the facility had left open, gained control from a distance, and tried to change chemical levels before an operator caught it. The attack path for a manufacturing plant is the same. The risk shows up as production downtime and intellectual property exposure rather than a public safety event, but the underlying failure is identical: remote access left open with no controls.
OT systems are the most exposed piece of this picture. In most plants, the IT and OT networks share a connection at some point, and the security controls on the OT side are lighter because those systems were designed for reliability rather than security. A vendor who connects to your IT network for billing software support may have a path to your SCADA system if network segmentation is not solid.
The credentials problem
Most manufacturing companies manage vendor access the same way: a VPN account or shared credentials handed out at the start of a contract, used for the job, and left in the system afterward. A 2023 survey of mid-sized manufacturers found that 74% could not provide a complete list of which vendors currently had active remote access to their OT or IT systems. Those credentials sit in the system, valid and unmonitored, long after the work ends.
An attacker who wants access to your plant doesn't need to find a vulnerability in your firewall when they can use a valid vendor credential instead. The connection looks normal from every monitoring angle because the account is legitimate. You'd see it as a normal remote access session from a vendor you trust, until something breaks and the investigation starts.
What attackers look for
Credentials that don't expire, access that doesn't generate alerts, and connections that no one watches in real time: those three conditions make vendor access a preferred target. When they overlap, an attacker can sit inside your network for weeks without triggering a single alert.
Actionable tip: Export every active account in your VPN or remote access software this week. Flag any account that hasn't connected in 90 days. That list is your starting audit, and it takes 15 minutes to run.
What Good Vendor Access Management Looks Like
Managing vendor access means giving vendors what they need for a specific maintenance window and nothing more after that. The vendor gets credentials when the maintenance window opens, and those credentials stop working when the window closes. Everything else is refinement on that baseline.
Time-limited credentials
Every vendor credential should expire. The simplest version is a short-lived password or VPN certificate issued at the start of a maintenance window and disabled when the window closes. More mature approaches use a privileged access management (PAM) tool that generates session-specific credentials automatically and terminates the session after a set period, with a full session log attached.
If a PAM tool isn't in your budget right now, a manual process still works: the ticket, the approved maintenance window, the account creation, and the account deletion all documented in writing. It's more work than an automated system, but it gives you a paper trail and a process instead of standing credentials that no one tracks. The discipline of documenting each step matters more than the tool you use to do it.
Session recording
Session recording is the backup that protects you after something goes wrong. When you can show exactly what a vendor's technician did during a remote session, from the commands they ran to the files they opened, you have evidence. Without it, you have a dispute and no way to resolve it cleanly.
Several mid-market tools record OT vendor sessions specifically, including CyberArk, BeyondTrust, and Delinea. Each logs keystrokes, commands, and screen activity during vendor sessions and ties the record to a ticket or work order. Those logs are also what a CMMC assessor or cyber insurance adjuster will request first if there's an incident.
Network segmentation for vendor connections
The best access management setup still assumes a vendor's device might be compromised. That's why network segmentation matters even after you've improved how you manage credentials. Vendors should connect to a dedicated network zone that gives them access only to the specific systems they're managing, with no path to payroll, ERP, or production databases outside that scope.
I worked with a manufacturer in Medley last quarter whose OT vendor had full access to the entire plant network because the VPN terminated on a flat network segment. One compromised laptop from that vendor could have touched the inventory system, the SCADA layer, and timekeeping at the same time. The exposure had been live for two years. We fixed it in a day.
For an overview of how manufacturers in South Florida approach OT cybersecurity as an operations discipline rather than an IT checkbox, see what we cover with our manufacturing clients. Our manufacturing IT services page outlines the specific areas we work on for plants and production environments.
Actionable tip: Ask whoever manages your network to show you where vendor VPN connections terminate on a current network diagram. If there's no diagram, or the vendor connections land on the same segment as your production systems, those are two separate problems to fix before your next audit.
What CMMC Requires About Third-Party Remote Access
CMMC Level 2 applies to any manufacturer in the Department of Defense supply chain, either as a prime contractor or a sub. As of 2024, companies pursuing Level 2 certification must be assessed by a third-party organization (C3PAO), and several access control practices in the framework directly cover vendor management.
AC.L2-3.1.12 requires that organizations control remote access sessions, including who can connect remotely, what they can access, and how those sessions are tracked. Vendor connections are fully in scope under this control.
AC.L2-3.1.14 requires that remote access be routed through managed access control points, not open ports or unmanaged VPN endpoints sitting outside your security monitoring.
AC.L2-3.1.6 requires that access to systems containing Controlled Unclassified Information be limited to people or roles with a specific need. A vendor whose contract ended six months ago has no continuing need. Keeping their credentials active is a documented finding under this control.
What an assessor will request
A C3PAO assessor reviewing your access control practices will ask for a list of all active accounts with remote access permissions, documentation showing how vendor access is provisioned and revoked, and evidence of a regular access review schedule. If you can't produce that documentation, you get a finding. Findings delay certification and require a remediation timeline before the assessment closes.
Cyber insurance underwriters ask the same questions. Most carrier applications now include a direct question about whether you have a formal vendor access management policy. Answering no doesn't automatically disqualify you, but it affects your premium and your coverage limit. Carriers have tightened this since 2021, and the gap between a documented policy and no policy translates to a real dollar difference at renewal.
Our compliance management services cover CMMC preparation for manufacturers, including access control documentation and the evidence you'll need for a C3PAO assessment. For a step-by-step breakdown of what Level 2 requires, see our post on the six-month CMMC preparation timeline for manufacturers.
Actionable tip: Pull your cyber insurance renewal paperwork and find the vendor access question. If you can't answer it confidently with documentation to back it up, that's the starting point for your access management policy.
How to Audit Who Has Access to Your OT Systems Right Now
An access audit doesn't require a consultant or a specialized tool. It requires a few hours, a spreadsheet, and the ability to export user lists from your VPN, firewall, and any remote access software you use.
Build your inventory
Start with three questions: Who has credentials to connect remotely to your network? When did they last connect? Do they still have an active contract or support relationship with your company?
Export your VPN active user list. Export any shared passwords stored in your IT ticketing system or password manager. Pull the remote desktop accounts if you use Windows Remote Desktop. Put every account in a spreadsheet with the date it was created, the date of the last login, and the name of the vendor or employee it belongs to.
Most manufacturers who run this audit for the first time find between 10 and 30 accounts they can't immediately explain. Some are former employees from several years ago. Some are vendor techs who completed a single installation and were never removed. Some are shared accounts with passwords that haven't been changed since the vendor first connected.
Decide what to do with each account
Every account on your list falls into one of three categories: active and needed, inactive and due for removal, or unclear. Remove the inactive ones immediately. For the unclear ones, contact the vendor and ask whether they still have an active support need. If they don't respond within a week, disable the account and document the decision.
This review should repeat on a schedule. Quarterly works for most manufacturers. If you're pursuing CMMC or you have contracts with a DoD prime, monthly is more appropriate. The important thing is that someone owns the process and it doesn't depend on an incident to trigger it.
Document the audit
The audit only matters if you can show you did it. Keep a simple log: the date, who ran the audit, the number of accounts reviewed, the number removed, and any accounts that needed follow-up. One page in a shared drive is enough. That log is what an assessor, an insurance carrier, or an incident response team will ask to see first.
For manufacturers who want a more durable setup, our managed IT services for manufacturers include vendor access management as a standard service item. Our related post on OT security fundamentals for manufacturers covers the broader framework this fits into.
Actionable tip: Create a recurring calendar invite for the first Monday of every quarter: "Vendor Access Audit." Assign it to whoever manages IT credentials in your company. The 20 minutes it takes to run the export and review the list is worth more than most security tools you could add to your stack.
If you want a second set of eyes on your current vendor access setup before you start a formal audit, schedule a free assessment and we'll walk through your network access configuration in a single session.
Frequently Asked Questions
Does every manufacturer need a vendor access management policy?
If you have any vendor who connects remotely to your systems, even once a year, you need a policy. It doesn't need to be long. Cover how credentials are issued, what access is granted, how long credentials stay active, and how access gets revoked when a contract ends. Two pages is enough to satisfy most insurance and compliance audits.
What's the difference between IT access and OT access for vendor purposes?
A vendor with IT access can exfiltrate data. A vendor with OT access can stop production, damage equipment, or create safety hazards. The same policy framework applies to both, but OT access should carry shorter windows and more monitoring because the consequences of a compromise show up faster.
How much does vendor access management tooling cost?
Basic privileged access management starts around $15 to $20 per user per month. For a manufacturer with five to ten vendors, that's $75 to $200 per month. Compare that to the average incident response engagement for a mid-sized plant, which typically runs $25,000 to $150,000. If a formal PAM tool isn't in the budget, a manual process with documented procedures costs only the time to run it.
Do cyber insurance rates change if we implement vendor access controls?
Yes. Carriers have tightened their questionnaires since 2021, and vendor access management is now a direct question on most applications. A company that can document a formal policy, a quarterly audit, and time-limited credentials is underwritten differently than one with standing vendor access and no monitoring. The premium difference can run 15 to 25 percent for a manufacturer in the $5M to $25M revenue range.
We're a small shop with one IT person. Is this realistic to manage?
A manual process works. One spreadsheet with active vendor accounts, a rule that credentials expire after each service window, and a quarterly calendar reminder: that's the baseline. If you work with a managed IT provider, ask them to own this process as part of your service agreement.
Ready to Know Who Has Access to Your Plant?
Vendor remote access is one of the fastest things to audit and one of the slowest things most manufacturers get to. If you're not sure who currently has standing access to your OT network, our team can help you find out and build a process that keeps it managed. We work with manufacturers across South Florida, from precision machining shops to food processing plants, and we've found this gap in operations of every size.
Schedule your free assessment and let's look at your current vendor access setup together.
