Vendor Remote Access Becomes the Weak Point Between IT and OT
- K.R. Samiksha

- 2 hours ago
- 2 min read
A contract integrator opens a laptop hundreds of miles from a production line. An always-on VPN tunnel carries industrial protocols straight from that machine into the control network. Nobody at the plant approved the session. Nobody is watching it. For years this was simply how equipment got serviced. It is now one of the most examined paths in industrial operations, because attackers have learned that the shortest route to a plant floor runs through a trusted supplier.
The Boundary Nobody Fully Mapped
Manufacturers are not merging their IT and OT incident response plans, and the reasoning is operational rather than philosophical. The two environments fail differently, and a response tuned for a compromised email tenant does little for a stalled process line. What is changing is the attention paid to the seams between them. Security teams are auditing where IT and OT actually exchange traffic and isolating those paths so a corporate breach does not become a production one.
Mike Carr, CTO at Xona Systems, which supplies secure remote access technology for industrial environments, replied in writing to The Supply Chainer with a description of what customers are demanding: "There are two key changes happening here, and they're both long overdue. First, we are seeing customers pushing back on the actual location of the software stack being used. Applications running OT protocols over VPN directly from the vendor's laptop to the OT system is a risk that organizations can no longer afford to make. Customers are requesting that those tools be deployed local to the OT environment so that they can be accessed remotely through more secure means."

Standing Access Gives Way to On-Demand
According to the company, customers are also retiring persistent VPN connections in favour of session-based access that requires approval from the plant side, so a breach at an integrator does not propagate instantly downstream. Operators remain cautious about the operational cost of that shift. Approval workflows add friction to emergency maintenance, and plants running thin on engineering staff are the ones most dependent on outside specialists.
The underlying pattern - attackers borrowing legitimate identities rather than building fake ones - is visible elsewhere in the supply chain. Highway's Q2 2026 Freight Fraud Index found that communication-based attacks made up half of all classified freight fraud incidents in the quarter, up from 42.7% in the previous one, with ownership-change fraud accounting for more than a quarter of reported theft cases. Demi Ramon, Vice President of Risk at Highway, told The Supply Chainer in comments published earlier this month: "Almost every successful theft starts with a bad actor exploiting your trust. They're counting on a compromised contact method to appear legitimate."
Resilience Now Has to Assume Intent
Industrial recovery playbooks were built around failed valves and dead sensors, not deliberate sabotage by someone holding valid credentials. Carr argues the process is the same - evaluate risk, build mitigation, execute - but detection is harder and the controls have to sit above the device. Legacy HMIs cannot enforce two-factor authentication or time-boxed access, so a defence-in-depth architecture has to supply them. Session recording tells teams what actually changed. Current documentation of default device values tells them how to put it back.




