TL;DR
Manufacturers are making progress in securing remote access to operational technology systems. However, third-party access governance is still underdeveloped, raising ongoing security concerns. The situation highlights both advancements and vulnerabilities in OT security practices.
Manufacturers are actively improving remote access security for operational technology (OT) systems, but third-party access governance continues to lag behind, according to a recent report by Secomea. This development underscores ongoing efforts to strengthen OT cybersecurity while exposing persistent vulnerabilities in third-party controls that could be exploited by cyber threats.
Secomea’s report highlights that many manufacturers have adopted advanced security measures, such as multi-factor authentication and encrypted VPNs, to protect remote access to OT networks. These steps aim to prevent unauthorized intrusions and improve overall security posture.
However, the report also emphasizes that governance of third-party access remains a significant challenge. Many organizations lack standardized policies or automated controls for managing external vendors and contractors, creating potential security gaps. This is especially critical as third-party access often involves sensitive operational data and controls that could be targeted by cybercriminals or malicious insiders.
Secomea’s findings come amid rising concerns about supply chain security and the increasing sophistication of cyber attacks targeting industrial control systems. While progress has been made in securing direct access points, the management of third-party connections has not kept pace, leaving a weak link in OT security frameworks.
Implications of Improved OT Access but Weak Third-Party Controls
This situation matters because effective governance of third-party access is critical to preventing cyber attacks that could disrupt industrial operations or cause safety incidents. As manufacturers enhance their direct remote access security, neglecting third-party controls could undermine overall security efforts, leaving organizations vulnerable to breaches or sabotage.
The findings highlight a need for comprehensive policies and automated tools to better manage external access, especially as OT environments become more interconnected and exposed to external threats. Strengthening third-party governance is essential to closing security gaps and ensuring resilience against evolving cyber risks.

EDR-8010-2GSFP-T – 2 GbE SFP multiport and 8 FE Copper Industrial Secure Router, with Firewall/NAT, 12/24/48 VDC Input Voltage, -40 to 75°C (Moxa)
Certified by IACS UR E27 Rev.1 and IEC 61162-460 Edition 3.0 marine cybersecurity standard
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Recent Trends in OT Security and Third-Party Risks
Over the past few years, there has been a significant shift toward securing remote access to operational technology systems. Industry standards and best practices have promoted measures like VPNs, multi-factor authentication, and network segmentation. Despite these advances, the management of third-party access remains inconsistent across organizations.
Historically, third-party vendors and contractors have been a weak point, often granted broad or unmanaged access, increasing the risk of insider threats and external cyberattacks. The rise in cyber incidents targeting critical infrastructure has intensified focus on improving third-party access controls, but progress has been uneven.
Secomea’s report reflects this ongoing challenge, emphasizing that while direct access security has improved, governance frameworks for external entities are still underdeveloped, leaving a critical gap in OT cybersecurity.
“While manufacturers are making strides in securing remote access, third-party access governance remains a weak link that needs urgent attention.”
— Secomea Security Report

Teltonika RUT301 Industrial Ethernet Router, 5 x Ethernet ports, Compact and Durable Design, Secure VPN, USB
5 x Ethernet ports (10/100 Mbps), Digital I/Os, and USB 2.0
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Unresolved Challenges in Third-Party Access Management
It is not yet clear how widespread the adoption of automated third-party access controls is across different industries or whether new regulatory frameworks will be introduced to address this gap. Details on specific best practices or standards being implemented remain limited, and the pace of progress varies among organizations.
Furthermore, the long-term effectiveness of current security measures and governance policies in preventing breaches involving third-party access is still under evaluation, with no definitive data available yet.
multi-factor authentication hardware for industrial systems
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Next Steps for Enhancing OT Third-Party Security
Industry experts and security vendors are expected to focus on developing and promoting standardized, automated governance solutions for third-party access management. Regulatory bodies may also introduce stricter compliance requirements to ensure better oversight.
Organizations will likely need to conduct comprehensive audits of third-party access policies and implement continuous monitoring tools to detect and respond to potential vulnerabilities. The upcoming months could see increased adoption of zero-trust architectures tailored for OT environments.
third-party access governance tools
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What specific security measures are manufacturers implementing for remote access?
Manufacturers are adopting measures such as multi-factor authentication, encrypted VPNs, network segmentation, and intrusion detection systems to secure remote access to OT systems.
Why is third-party access governance still a concern?
Many organizations lack standardized policies or automated controls for managing external vendors and contractors, creating potential security gaps that could be exploited by cyber threats.
What risks are associated with poor third-party access management?
Risks include cyberattacks leading to operational disruptions, safety incidents, data breaches, and potential sabotage of critical infrastructure.
Are there any regulations addressing third-party OT access?
While some industry standards exist, comprehensive regulations specifically targeting third-party access governance in OT are still evolving and vary by region and sector.
What should organizations do next to improve their third-party access controls?
Organizations should conduct audits, adopt automated governance tools, enforce strict access policies, and implement continuous monitoring to mitigate risks associated with third-party connections.
Source: primary