Securing Vendor Remote Access to Industrial Equipment

Equipment vendors need remote access, but open connections to controllers are a top risk. Learn how to control, monitor and time-limit third-party access.

3 min readBy Ironfield Cyber Team

When a compressor stops behaving or a drive faults at two in the morning, the fastest fix is often a call to the equipment vendor, who logs in remotely and sorts it out. That convenience has a cost. Every vendor connection is a door into a process network that was never designed with attackers in mind, and many of those doors were opened years ago and never reviewed.

CISA guidance on operational technology repeatedly highlights remote access as a key exposure, and it shows up in the structure of ISA/IEC 62443 as well, which treats connections between zones as something to control carefully. This post offers a practical approach for energy services firms, contractors with industrial equipment and small utilities.

How vendor access usually grows

  • A technician installs a cellular modem during commissioning and leaves it on
  • A remote desktop tool is installed on an engineering workstation "temporarily"
  • A shared vendor account with a simple password is never changed
  • A VPN is set up to the entire process network rather than one device
  • Support contracts renew while nobody asks what access they require

Each choice made sense at the time. Together they create an unmanaged perimeter.

Step 1: Find every connection

Start with your asset inventory and the cabinet walkdown. Look for cellular gateways, modems, vendor-owned routers, remote support software and cloud connectivity features on equipment. Ask each vendor directly: "How do you reach our equipment today?" The answers are often surprising.

Step 2: Decide who truly needs access

For each vendor, document why they need access, which devices, how often and who at your company approves it. Remove anything without a current business reason.

Step 3: Route access through one controlled path

Instead of many separate connections, aim for a single managed entry point. Common features of a good design include:

  • A dedicated remote access gateway or jump host in a protected zone between IT and OT
  • Multifactor authentication for every user
  • Individual accounts for each vendor technician, not shared logins
  • Access limited to the specific devices needed
  • Session logging, and recording where practical

Step 4: Make access time-limited

Keep the door closed by default. A practical model is that the vendor requests access, an operator approves it, access is enabled for a defined window and then it closes automatically. This approach cuts exposure from constant to occasional, and it gives operations visibility into what is being done to their equipment.

Step 5: Require operator awareness

Operators should know when someone is connected and what they are doing. Agree on a simple procedure, such as a phone call before a session begins and confirmation afterward. For safety-critical systems, require an operator or engineer to be present.

Step 6: Put expectations in the contract

Vendor agreements are a good place to formalize expectations. Consider including:

  1. Use of your approved remote access method only
  2. Individual accounts and multifactor authentication
  3. Prompt notice of personnel changes and security incidents
  4. Rules on the software and removable media technicians may bring
  5. Patching and update practices for their remote tools
  6. Right to review logs of sessions

Step 7: Monitor and review

Log remote sessions centrally. Review them monthly at first, and ask basic questions. Who connected? When? To what? Was it expected? Review the vendor list at least once a year and whenever a contract changes.

Special cases

Cellular modems left by vendors

If you find one, do not simply unplug it without checking with operations, since it may support alarms or monitoring. Confirm its function, then replace it with a managed solution or secure its configuration.

Legacy equipment with no authentication

Some older devices cannot support modern sign-in. Place them behind a firewall, restrict who can reach them and treat the gateway as the control point.

Emergency access

Write a break-glass procedure for urgent fixes that still includes approval and logging. When emergency access has no process, people invent one.

What not to do

  • Do not allow direct internet exposure of controllers or HMIs
  • Do not use one shared vendor password across sites
  • Do not treat a VPN alone as security if it lands on a flat network

How Ironfield Cyber helps

Ironfield Cyber helps energy and industrial clients map remote access paths, design a controlled entry point and write vendor access requirements into agreements. If you are unsure how many vendors can reach your equipment today, we can help you find out.