link rel="stylesheet" href="https://unpkg.com/@phosphor-icons/web@2.1.1/src/regular/style.css"

Killing Always-On Vendor Access: A Key to Secure Remote OT

Anthony Mondelli
Alaska OT/ICS Cybersecurity Lead
min. read
July 23, 2026
View on Original Source
min. read
The tunnel your vendor installed in 2019 is still open. So is the question of who else has used it.

Permanent vendor VPN tunnels are among the most common and dangerous access paths in OT environments. They exist because operations needs vendor support, and that need is legitimate. But when those tunnels are left always open, poorly logged, and tied to shared credentials, they stop being a support tool and start being a standing invitation.

Let's show you a practical path from always-on access to brokered, time-bound, attributable, and logged sessions. And let's do it without breaking the vendor relationships your operations depends on.

Why Always-On Access Exists

Always-on vendor access usually starts for understandable reasons. A support contract assumed instant vendor reachability. A project tunnel was created during a startup, and no one ever closed it. Operations feared that cutting a path would mean losing support during a critical outage.

Those fears are not irrational. The problem is that convenience becomes permanent. A tunnel opened for a three-week commissioning project is still open three years later. A VPN account created for a specific technician is still active after that technician left the vendor. Many organizations cannot close paths because they do not know how many they have.

Related: Vendor Risk Is Your Risk: The Harsh Reality and What to Do About It

Why Attackers Love Always-On Vendor Access

Always-on vendor paths are attractive to attackers for several reinforcing reasons. Vendor credentials can be stolen, phished, or reused across multiple customers. Always-on means always exploitable. There is no access window to approve, monitor, or close. Session logging is often absent or inconsistent, which makes dwell time and forensic reconstruction difficult.

This is not a theoretical concern. Vendor remote access is one of the most consistently documented OT attack vectors, appearing across incident reports in energy, manufacturing, water, and maritime sectors. We cover this as a dedicated attack path in our overview of the five most common OT intrusion routes.

Read more: The Five Most Common Attack Paths in Operational Technology and How to Prevent Them

The deeper problem is visibility. When you cannot tell what a vendor session actually did, which systems were touched, which commands were run, which configurations were changed, then you cannot assess the blast radius of a compromised credential. And in OT, configuration changes have physical consequences.

Related: Why OT Change Management Is Your Most Important Cyber Control

What the Target State Looks Like

A defensible vendor access model is not complicated. It has a small number of well-governed components that work together:

  • One brokered entry point. All vendor access flows through a jump host or access broker. There are no direct tunnels to OT assets.
  • MFA for every vendor identity. No exceptions, no shared accounts.
  • Time-bound access grants. Sessions are requested, approved, and automatically expire. There is no always-on.
  • Session recording and logging. Operations can replay any vendor session after a change. If something breaks, you know what the vendor did.
  • Allowlisted destinations. Each vendor can reach only the systems they support — not the entire OT network.
  • Access that is requested, approved, monitored, and closed as a defined workflow.

This model does not make vendor access harder. It makes it governed. There is an important difference. Governed access is faster to audit, easier to defend, and less likely to become the path that creates your next incident.

A Migration That Does Not Break Support

The path to better vendor access should be phased. Ripping out all existing tunnels at once is how you create a production outage and destroy trust with operations.

  • Inventory: Document every vendor access path. Firewall rules, VPN configurations, remote support tools, modems, cloud connectors, and project exceptions. Assign an owner to each one. If there is no owner and no business purpose, treat it as an orphaned path and disable it.
  • Prioritize: Rank remaining paths by criticality and exposure. An always-on tunnel to a critical safety system ranks higher than read-only historian access from a reporting vendor.
  • Pilot: Pick one cooperative vendor and implement brokered, time-bound, recorded access with them first. Tune the approval workflow until it works quickly. Measure time from request to approval — this is the number operations will care about.
  • Scale: Migrate vendors in waves. Decommission legacy tunnels only after the new workflow is validated and trusted.

Handling Vendor Pushback

Some vendors will push back, especially those whose support contracts assumed unconstrained access. The response is to offer a fair trade, not a confrontation.

Put access terms into contract language at renewal. Define emergency access procedures in advance so the 2 a.m. outage objection is already answered before it comes up. Most vendors, when offered a faster approval workflow in exchange for time-bound sessions and session recording, will accept. The ones who refuse to accept any access governance are worth examining closely.

What to Measure

A vendor access program should be measured in terms that operations leadership can read and trust:

  • Count of always-on paths remaining. The target is zero.
  • Percentage of vendor sessions that are time-bound, recorded, and attributable to a named identity.
  • Time from access request to approval. If this number stays low, operations sees that the new model works.

Share these numbers in the same forums where uptime and production metrics are reviewed. When leadership sees both the risk reduction and the operational continuity, support for the program grows.

Related: Exposing Invisible Links — The 6 IT-OT Bridges That Could Compromise Your Operations

30-Day 'Do This Now' Checklist

  1. Inventory every vendor's remote access path. Document the tool, credentials, destination, owner, and last confirmed business purpose for each.
  2. Disable any path with no owner or no confirmed business purpose.
  3. Enforce MFA on all remaining vendor identities.
  4. Pick one vendor and pilot brokered, time-bound, recorded access. Measure time-to-approval and iterate.

The Relationship Gets Stronger

You do not have to choose between vendor support and a defensible perimeter. Broker the access, bound it in time, record it, and both sides benefit. Operations gets a support relationship they can actually audit. Security gets a vendor access posture they can actually defend. And the tunnel that opened in 2019 finally gets closed.

Find the content useful? Subscribe to The Catch, our exclusive weekly LinkedIn newsletter focused on real-life experiences doing cyber right in the most highly regulated industries.

About the resource
What you'll learn
Who is this resource for?
Download Killing Always-On Vendor Access: A Key to Secure Remote OT
Download Resource
Thank you and enjoy the resource
View Resource
Oops! Something went wrong while submitting the form.