When a compressor stops behaving or a drive faults at two in the morning, the fastest fix is often a call to the equipment vendor, who logs in remotely and sorts it out. That convenience has a cost. Every vendor connection is a door into a process network that was never designed with attackers in mind, and many of those doors were opened years ago and never reviewed.
CISA guidance on operational technology repeatedly highlights remote access as a key exposure, and it shows up in the structure of ISA/IEC 62443 as well, which treats connections between zones as something to control carefully. This post offers a practical approach for energy services firms, contractors with industrial equipment and small utilities.
How vendor access usually grows
- A technician installs a cellular modem during commissioning and leaves it on
- A remote desktop tool is installed on an engineering workstation "temporarily"
- A shared vendor account with a simple password is never changed
- A VPN is set up to the entire process network rather than one device
- Support contracts renew while nobody asks what access they require
Each choice made sense at the time. Together they create an unmanaged perimeter.
Step 1: Find every connection
Start with your asset inventory and the cabinet walkdown. Look for cellular gateways, modems, vendor-owned routers, remote support software and cloud connectivity features on equipment. Ask each vendor directly: "How do you reach our equipment today?" The answers are often surprising.
Step 2: Decide who truly needs access
For each vendor, document why they need access, which devices, how often and who at your company approves it. Remove anything without a current business reason.
Step 3: Route access through one controlled path
Instead of many separate connections, aim for a single managed entry point. Common features of a good design include:
- A dedicated remote access gateway or jump host in a protected zone between IT and OT
- Multifactor authentication for every user
- Individual accounts for each vendor technician, not shared logins
- Access limited to the specific devices needed
- Session logging, and recording where practical
Step 4: Make access time-limited
Keep the door closed by default. A practical model is that the vendor requests access, an operator approves it, access is enabled for a defined window and then it closes automatically. This approach cuts exposure from constant to occasional, and it gives operations visibility into what is being done to their equipment.
Step 5: Require operator awareness
Operators should know when someone is connected and what they are doing. Agree on a simple procedure, such as a phone call before a session begins and confirmation afterward. For safety-critical systems, require an operator or engineer to be present.
Step 6: Put expectations in the contract
Vendor agreements are a good place to formalize expectations. Consider including:
- Use of your approved remote access method only
- Individual accounts and multifactor authentication
- Prompt notice of personnel changes and security incidents
- Rules on the software and removable media technicians may bring
- Patching and update practices for their remote tools
- Right to review logs of sessions
Step 7: Monitor and review
Log remote sessions centrally. Review them monthly at first, and ask basic questions. Who connected? When? To what? Was it expected? Review the vendor list at least once a year and whenever a contract changes.
Special cases
Cellular modems left by vendors
If you find one, do not simply unplug it without checking with operations, since it may support alarms or monitoring. Confirm its function, then replace it with a managed solution or secure its configuration.
Legacy equipment with no authentication
Some older devices cannot support modern sign-in. Place them behind a firewall, restrict who can reach them and treat the gateway as the control point.
Emergency access
Write a break-glass procedure for urgent fixes that still includes approval and logging. When emergency access has no process, people invent one.
What not to do
- Do not allow direct internet exposure of controllers or HMIs
- Do not use one shared vendor password across sites
- Do not treat a VPN alone as security if it lands on a flat network
How Ironfield Cyber helps
Ironfield Cyber helps energy and industrial clients map remote access paths, design a controlled entry point and write vendor access requirements into agreements. If you are unsure how many vendors can reach your equipment today, we can help you find out.