Equipment manufacturers, integrators, and service providers regularly need remote access to troubleshoot controllers, update software, or monitor performance. It saves travel costs and speeds repairs, and for many operators it is a practical necessity. It is also one of the most common ways attackers reach industrial environments, because remote connections are built to bypass the walls you put up.
The answer is not to ban vendor access. It is to control it so that each connection is deliberate, limited, and recorded.
Why vendor access is risky
Typical weak patterns include a shared vendor password used by many technicians, a remote tool left running permanently on an operator station, a cellular modem attached to a machine and forgotten, and direct connections from the internet to a controller. Each of these means that anyone who obtains one credential, or discovers one exposed service, has a path into your process.
Vendors are also targets themselves. A compromise at a vendor can reach every customer using the same remote access method and credentials.
Principles for safe access
Least privilege
Give vendors access only to the systems they support, and only the level they need. A technician servicing a compressor controller does not need reach into your entire control network.
Time-limited and approved
Access should be turned on when needed and off afterward. Ideal practice is to require your approval for each session, with a defined window and a purpose.
Individual accountability
Each vendor technician should have a named account. Shared accounts make it impossible to tell who did what and difficult to remove one person's access when they leave the vendor.
Strong authentication
Require multi-factor authentication for all remote access. Make sure it applies to vendors, not only to your own employees.
Recording and logging
Log each session, including who connected, when, and to which system. Where feasible, record the session so you can review what was changed. This helps with troubleshooting and with incident investigation.
A recommended architecture
Rather than allowing vendors to connect directly to control devices, have them connect to a hardened gateway placed in a DMZ between the business network and the control network. From there, the gateway permits only approved connections to specific systems, and only when a session has been authorized.
Avoid exposing control devices directly to the internet, and never rely on port forwarding or default credentials for convenience. Public scans routinely discover exposed industrial devices, and attackers do not need special skill to find them.
Procedures to put in place
- Inventory all remote access paths. Include vendor tools, cellular modems, VPNs, and anything else that connects from outside. You will probably find paths nobody remembers.
- Review vendor contracts. Define security expectations, notification of incidents, and the right to audit or revoke access.
- Create an access request process. The vendor requests access, an internal owner approves, and the session is logged and closed out.
- Disable and remove unused connections. If a path has not been used in months, switch it off.
- Rotate credentials. Change passwords after each major service event or when technicians leave.
- Watch for unusual activity. Alert on access outside approved windows.
Questions for your vendors
- How do your technicians authenticate, and do you use MFA?
- What remote access tool do you use, and how is it secured and updated?
- Can we control when sessions start and end?
- How do you handle credentials for our environment?
- What is your process if one of your employees' accounts is compromised?
Vendors who take security seriously will have clear answers. Hesitation or vague responses are worth noting.
When the vendor insists on a permanent connection
Sometimes a vendor monitors equipment continuously. In that case, limit the connection to outbound data where possible, put it behind a firewall rule restricted to the specific destination, and document the exception, owner, and review date.
Where Ironfield Cyber helps
Ironfield Cyber helps energy and construction-related operators design secure remote access, review vendor arrangements, and monitor connections to control environments. If you have a handful of vendor tools and no clear picture of how they connect, we can map them with you and propose a safer approach.