Default Passwords and Vendor Accounts in Control Systems

Factory-default logins and forgotten vendor accounts are among the easiest ways into industrial systems. Here is how to find and fix them safely.

3 min readBy Ironfield Cyber Team

Industrial and field equipment often ships with a default username and password, and plenty of those credentials stay in place for years after installation. Integrators leave behind their own support accounts. Operators share a single login because it is convenient. Over time, nobody can say who knows which passwords or whether those accounts still need to exist.

These weak credentials are not exotic. Government cybersecurity agencies have repeatedly warned that default and weak passwords on internet-reachable control devices are a common way attackers get in. Fixing them is one of the highest-value steps a small operator can take, provided it is done carefully.

Why this is harder in operational environments

On an office computer, changing a password is routine. On a control system, it can interrupt production or break a connection between devices. Some older equipment hardcodes credentials or has no way to change them. A password change that is not coordinated with operations may disconnect a monitoring system at the worst possible moment.

That is why a measured approach beats a rushed one.

Step one: build a credential inventory

For each device and system, record:

  • The type of account: operator, engineer, administrator, vendor support
  • Who uses it and whether it is shared
  • Whether the password is still the default
  • Whether the account is protected by multifactor authentication or limited by network location
  • Whether it is actually still needed

Look beyond the obvious. Check programmable controllers, human-machine interfaces, historians, engineering workstations, network switches, wireless access points, cameras, and remote access gateways. Each often has its own administrative login.

Step two: prioritize by exposure and impact

You will rarely fix everything at once. Order the work by two questions.

  1. Is the device reachable from outside the control network, especially from the internet? Those come first.
  2. What happens if the device is misused? Devices that control critical processes or safety functions deserve careful, early attention.

Step three: change credentials safely

  • Schedule changes during planned maintenance windows with operations involved.
  • Document the existing configuration and have a rollback plan before touching anything.
  • Test on a spare device or in a lab if you have one.
  • Use long, unique passwords and store them in a controlled password vault, not on a sticky note or a shared spreadsheet.
  • Confirm that dependent systems, such as historians and monitoring tools, are updated with the new credentials.
  • Keep a sealed emergency record of critical credentials according to your internal policy, so operators are not locked out during an incident.

Step four: deal with vendor and integrator accounts

Vendor accounts are a frequent blind spot.

  • Ask each vendor what accounts exist on delivered systems and why.
  • Disable accounts that are not needed, and make remote vendor access time-limited and approved on request rather than always on.
  • Require unique named accounts for each vendor technician rather than a shared company login.
  • Include credential handover and account removal in project closeout for any integration work.
  • Review vendor access on a schedule, and remove it when contracts end.

Step five: reduce reliance on passwords alone

Where possible, add layers around systems that cannot be changed.

  • Place legacy devices behind a firewall that restricts which systems can talk to them.
  • Require remote access through a gateway with multifactor authentication.
  • Segment control networks from business networks.
  • Monitor and log logins to critical systems.

If a device genuinely cannot support better credentials, document the risk, isolate it, and plan its replacement.

Policies that keep it fixed

  • Procurement requirements that devices support unique credentials and password changes.
  • A commissioning checklist that includes changing defaults before a system goes live.
  • Annual review of accounts on critical systems.
  • Prompt removal of accounts for departing staff and contractors.

Where Ironfield Cyber fits

Ironfield Cyber helps operators inventory control system accounts, plan changes around operations, and set up controlled vendor access. We start with awareness-level assessments and coordinate with your operations team. If you would like help finding your default credentials before someone else does, reach out for a review.