Securing Vendor Remote Access to Field and Plant Equipment

Equipment vendors often need remote access to controllers and monitoring systems. Here is how to allow it safely, with controls operators can actually manage.

3 min readBy Ironfield Cyber Team

Equipment vendors, integrators, and service technicians often need to connect remotely to your systems: a compressor skid, a SCADA historian, a building automation controller, a pump station. That access saves truck rolls, but it is also one of the most common ways attackers reach operational networks. CISA and other agencies have repeatedly warned about unmanaged remote access into industrial environments.

The goal is not to ban vendor access. It is to make it deliberate, limited, and visible.

Why vendor access goes wrong

Remote access paths tend to grow without anyone planning them. A technician installs a cellular modem to monitor a site. A vendor asks for a remote desktop tool on a workstation. A shared password is emailed and never changed. Years later, no one knows which connections exist or who can use them.

Typical problems include:

  • Always-on connections that stay open between service visits.
  • Shared vendor accounts with passwords that never change.
  • Remote tools installed directly on control-network machines.
  • Cellular modems or routers connected straight to the operations network, bypassing your firewall.
  • No record of who connected, when, or what they did.

Step 1: Find every remote path

Before you fix anything, inventory what exists. Ask each vendor and your own operations staff what remote access is configured. Then check physically and on the network:

  1. Look for cellular routers and modems in panels and cabinets.
  2. Review firewall rules for inbound connections and VPN accounts.
  3. List remote-access software on engineering workstations and servers.
  4. Ask your vendors directly whether they have a connection you have not documented.

Write down each path: which system, which vendor, what protocol, who approves it.

Step 2: Route access through one controlled door

Aim for a single, managed entry point rather than a dozen. A common approach is a jump host, a hardened server in a separate network zone where vendors log in first, and from which they can reach only the specific systems they support.

Key features of a good setup:

  • Multi-factor authentication for every vendor account.
  • Named accounts per individual, never shared logins.
  • Limited reach: the vendor sees only their equipment, not the whole network.
  • Session logging, and where practical, recording.

Step 3: Make access time-limited

Treat vendor access like a work order. The connection is enabled when a service visit is scheduled and disabled when it ends. Options range from simple to sophisticated:

  • A policy that vendors call or email to request access, with an operator enabling the account.
  • Accounts that are disabled by default and switched on for a defined window.
  • Automatic expiration on temporary credentials.

Even a manual process, enable on request and disable afterward, is a major improvement over permanent open access.

Step 4: Put it in the contract

Security expectations belong in your service agreements and purchase orders. Ask vendors to:

  • Use individual accounts and MFA.
  • Notify you of personnel changes on their side.
  • Keep their own laptops patched and protected.
  • Report any security incident that could affect your systems.
  • Not install remote software or modems without your approval.

Vendors who handle other customers professionally will not be surprised by these requests.

Step 5: Watch and review

Log every remote session, and have someone look at the list. Quarterly is a reasonable rhythm for a small operator. Ask simple questions: Was this connection expected? Is the account still needed? Did anything unusual happen outside business hours?

Special cases

Some equipment ships with a vendor-managed cellular connection you cannot change. In that case, ask the vendor how it is secured, place the device in an isolated network zone, and restrict what it can reach. If a vendor will not explain their remote connection, treat that device as untrusted.

Where Ironfield Cyber fits

Ironfield Cyber can help inventory remote-access paths, design a jump-host approach, and write vendor access requirements into your agreements. If you suspect there are connections nobody has documented, a short assessment is a sensible first step.