What's Happening?
Manufacturers are increasingly focusing on improving cybersecurity measures for operational technology (OT) environments, particularly in the wake of numerous ransomware attacks targeting industrial organizations. A recent report by Secomea highlights
a significant shift towards better governance of third-party access, which is crucial for maintaining operational continuity. The report indicates that while manufacturers have made strides in securing remote access, the governance of third-party access remains a challenge. Many organizations are now prioritizing identity verification, least-privilege access, and comprehensive audit trails to enhance security. The study reveals that 57% of North American organizations manage six or more external vendors with remote access to OT environments, yet only 46% have full auditability of vendor sessions. This gap underscores the need for improved visibility and control over vendor access.
Why It's Important?
The focus on third-party access governance is critical as cyberattacks increasingly exploit trusted identities and legitimate remote access. For manufacturers, ensuring secure and well-governed remote access is essential to prevent disruptions in production and maintain operational resilience. The findings suggest that organizations with shared IT and OT ownership of remote access experience lower incident rates, highlighting the importance of integrated governance. As manufacturers rely more on third-party support, the ability to manage vendor access effectively becomes a competitive advantage, reducing the risk of cyber incidents and ensuring compliance with regulatory requirements. This shift towards centralized governance models reflects a broader industry trend towards enhancing cybersecurity frameworks to protect critical infrastructure.
What's Next?
Manufacturers are expected to continue investing in technologies and strategies that enhance third-party access governance. This includes adopting standardized platforms for managing vendor access, moving away from fragmented VPNs and vendor-specific tools. Organizations are likely to implement more robust identity-based access controls, just-in-time access, and centralized approval workflows. As the industry evolves, manufacturers will need to balance the need for secure connectivity with the operational demands of maintaining production efficiency. The ongoing development of governance frameworks will be crucial in addressing these challenges and ensuring that manufacturers can respond effectively to emerging cybersecurity threats.













