Manufacturers want more vendor access—but governance gaps leave OT security exposed, secomea warns

The gist

Manufacturers are racing to expand secure OT vendor access, but glaring governance gaps are leaving critical infrastructure exposed, Secomea warns.

What to know

  • By mid-2026, the OT attack surface ballooned to include field tools and vendor platforms, demanding controlled connectivity with role-based access and multi-factor authentication.
  • Over 75% of North American manufacturers want centralized vendor access platforms, yet only 46% achieve full auditability and just 23% conduct monthly credential reviews.
  • Shared IT-OT governance and just-in-time controls slash cyber risk, but most organizations still lag on audit trails and compliance, making better management—not fewer vendors—the real fix.

Controlled Connectivity Revolution

Manufacturers are transforming remote access from a security risk into a strategic asset by adopting granular controls, auditability, and governance frameworks tailored for OT environments.

By mid-2026, the operational technology (OT) attack surface has dramatically expanded beyond traditional PLC, HMI, and SCADA systems due to the increased connectivity of field tools, historians, vendor platforms, and support systems. Secomea’s CTPO Knud Kegel highlights that this proliferation exposes manufacturers to unmanaged third-party connections, weak authentication, and insufficient visibility, underscoring the urgent need for 'controlled connectivity' rather than simply reducing access. This approach enables faster troubleshooting, safer vendor support, reduced downtime, and enhanced compliance readiness, transforming remote access from a vulnerability into a strategic asset.

Addressing these risks requires robust governance frameworks that incorporate role-based access control, multi-factor authentication, system segmentation, and comprehensive audit logging, as championed by Secomea’s platform. Kegel emphasizes that secure remote access governance is not just a technical necessity but a cornerstone of operational resilience, safety, and customer trust in modern industrial environments. This governance paradigm shifts the focus from merely enabling connectivity to making it an auditable security control that supports compliance and accountability.

The ransomware threat landscape targeting OT environments has sharpened the imperative for manufacturers to rethink remote access governance, moving decisively towards just-in-time access, approval-based workflows, and least-privilege permissions. According to Kegel, ransomware resilience increasingly hinges on how organizations govern remote OT access—reducing standing access, ensuring detailed audit trails for investigations, and enabling rapid containment of suspicious activity are critical controls. This proactive governance model aims to prevent the exploitation of factory VPNs and limit disruption spread, marking a strategic evolution in OT cybersecurity.

Sources
PR Newswire - Business TechnologyPR Newswire

Zero Trust, OT-Style

A new era of OT security prioritizes identity, context, and just-in-time access, driven by regulatory pressure and the limitations of traditional IT-centric zero trust models.

Implementing zero trust in operational technology (OT) demands a tailored approach that prioritizes strong identity verification, role-based access, and context-aware policies specifically designed for OT environments rather than simply transplanting IT-centric models. As outlined in NIST’s SP 800-207 and reinforced by CISA’s OT guidance, the focus shifts from network perimeter defenses to verifying the identity and context of devices and users, ensuring that access decisions are precise and relevant to OT’s unique operational demands. This shift is especially critical in managing vendor remote access, where regulatory mandates like TSA Directive 2021-02C and NERC CIP-013 compel organizations to rigorously govern and attest to network segmentation and access controls, embedding just-in-time access mechanisms to minimize exposure while maintaining compliance.

By early 2026, CISOs advocating zero trust in OT emphasized practical, high-impact controls at IT-OT convergence points such as jump hosts, historian connections, and shared identity stores. These choke points serve as strategic leverage points where stronger authentication, least privilege principles, and detailed logging can be deployed to reduce cyber risk effectively without disrupting critical operations. This pragmatic approach aligns with a phased 90-day action plan that begins with enhancing visibility into who and what currently accesses OT systems—intentionally or accidentally—thereby operationalizing zero trust principles in a manageable, context-sensitive manner as recommended by CISA.

Sources

Third-Party Access Gaps

Despite widespread adoption of centralized platforms, most manufacturers still lack full auditability and regular credential reviews, leaving critical OT systems exposed to vendor-related risks.

Manufacturers face significant governance challenges in managing third-party OT remote access, primarily due to always-on connections, shared credentials, and limited oversight that amplify ransomware risks. Detailed audit trails that reveal who accessed systems, when, and what actions were performed are critical not only for incident response but also for compliance and cyber insurance reporting, underscoring the need for enhanced visibility and accountability in OT environments.

The industry is decisively moving from merely enabling remote access to rigorously governing it through centralized, standardized platforms that enforce least-privilege and just-in-time access, coupled with approval-based workflows. According to Secomea’s 2026 study, over 75% of North American manufacturers either already use or prefer such platforms, reflecting a clear shift away from fragmented VPNs and vendor-specific tools toward unified governance models that improve compliance and reduce cyber risks.

Despite heavy reliance on external vendors—57% of North American manufacturers manage six or more with OT access—a substantial governance gap persists, with only 46% achieving full auditability of vendor sessions and a mere 23% conducting monthly credential reviews. Secomea emphasizes that effective third-party access governance requires identity verification, just-in-time access, centralized approval workflows, comprehensive audit trails, and rapid access revocation to maintain operational continuity while mitigating cyber threats.

Shared ownership of remote access governance between IT and OT teams correlates with notably lower incident rates, highlighting that technology solutions must be complemented by coordinated governance practices. As Knud Kegel, CTPO at Secomea, asserts, manufacturers don’t need fewer vendors but better governance—knowing precisely who has access, why, for how long, and being able to trace every remote session is the next critical step toward securing OT environments.

Sources

Shared Governance, Fewer Incidents

Coordinated IT-OT ownership and centralized approval workflows dramatically reduce cyber incidents and downtime, shifting the focus from limiting vendors to mastering remote access management.

Effective remote access controls in OT environments are pivotal for balancing operational continuity with cybersecurity and compliance, as they enable faster troubleshooting, safer vendor support, and reduced downtime. By focusing on choke points such as jump hosts and shared identity stores, organizations can implement zero trust principles like stronger authentication and least privilege without disrupting production. A phased 90-day plan that starts with mapping who and what can access OT systems—engaging both OT engineers and network staff—lays the groundwork for continuous improvement and regulatory alignment.

Manufacturers increasingly recognize that the challenge is not reducing the number of vendors but improving governance over their remote access to maintain resilience and compliance. Secomea’s 2026 study reveals that 77% of manufacturers seek centralized vendor access platforms, yet third-party governance still lags, with only 46% having fully verifiable vendor sessions and a mere 23% performing monthly credential checks. Knud Kegel of Secomea emphasizes the necessity of knowing who has access, why, for how long, and being able to trace every remote session, underscoring that better management—not fewer vendors—is key to operational continuity.

Coordinated IT and OT ownership of remote access governance significantly reduces incident rates and strengthens compliance, highlighting the importance of shared responsibility. Organizations that integrate identity-based, just-in-time access with centralized approval workflows and comprehensive audit trails not only meet regulatory mandates like TSA Security Directive Pipeline-2021-02C and NERC CIP-013 but also minimize downtime. This collaborative approach shifts the conversation from questioning the need for change to focusing on effective implementation, as evidenced by Secomea’s findings that shared governance correlates with fewer cybersecurity incidents.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.