Skip to content

Vendor Access Emerges as a Primary Weak Link in OT Security

As vendor ecosystems expand, industrial firms are still struggling with the basics of secure remote access, oversight and credential control.

Organizations that must protect their OT/ICS, operational technology and industrial control systems still struggle with the basics: asset visibility, network segmentation, and especially secure remote access.

While Fortinet’s recent survey, the 2026 Fortinet State of Operational Technology and Cybersecurity Report, did find progress being made when it comes to OT/ICS security maturity, it also found the number of highly mature organizations decreased, while less mature organizations increased.

Why?

According to Fortinet, a fair reading of the findings suggests this may be because increased investments and executive focus on OT/ICS security mean more organizations have identified the gaps they need to close and more clearly see their actual security posture. 

However, other recent surveys and analysis still point to the long-standing trend in cybersecurity surveys: security and business leaders very often have a higher opinion of their security posture than reality warrants. And this was the exact finding in The State of Industrial Remote Access 2026, a global survey of 400 OT, cybersecurity, compliance and operations leaders.

According to Secomea’s survey, many believe their OT remote-access controls are strong, even as the evidence shows major blind spots in visibility, vendor oversight and auditability. The report finds that confidence in compliance and session visibility often outpaces demonstrable control, creating what it calls a “misalignment gap” between perception and proof.

Consider one of the most important fundamentals in OT/ICS security. Remote access is a critical layer of control for manufacturers and critical infrastructure operators, as it underpins maintenance, troubleshooting, vendor support, and recovery across distributed industrial environments. However, because remote access points create potential entry points for attackers, this access sits at the center of attack risks, regulatory pressure and operational dependency on third parties.

“Think about how many OEMs, contractors or vendors just dial into your plant to monitor something or perform remote maintenance,” Brendon Clemmer, principal OT engineer at Armis said during his presentation at OT.SEC.CON held in Houston earlier this year. “If your policy says all remote maintenance must go through a monitored jump host with MFA, then you must actually be doing it.”

Related:

Accenture-Dragos Deal Signals New OT Security Era
Accenture’s acquisition of a majority stake in Dragos and full ownership of runZero and NetRise reflects growing urgency across the cybersecurity industry to defend critical infrastructure against nation-state threats, particularly those attributed to China.
AI-Generated Code Is Already Running Critical Infrastructure
Embedded systems are already running AI-generated code. Security leaders now face scale, speed, and regulatory risk gaps.

Most organizations apparently do not perform close tracking, despite managing between six and 20 vendors, and the report says incident likelihood rises sharply as vendor ecosystems expand, especially when credential hygiene and session visibility are weak. One finding made that risk abundantly clear: organizations with no vendor session visibility reported universal incident exposure, while organizations with full visibility reported significantly lower incident rates.

A second major finding is that remote-access architecture matters more than many organizations appear willing to admit. VPN-heavy and OEM-tool-heavy environments consistently underperform unified or OT-dedicated access platforms on visibility, audit trails, and operational consistency. OT-dedicated platforms delivered the highest average session visibility in the study, while fragmented stacks with three or four tools produced measurable erosion in control, dropping average visibility from 4.3 in simple environments to 3.9 in complex ones. 

That architectural fragmentation is common. Only 9.1% of organizations rely on a single tool category for remote access, while the rest juggle multiple combinations of VPNs, OEM tools, PAM products and dedicated OT platforms. The result is parallel access paths, inconsistent identity handling, uneven logging and approval workflows that vary by site or vendor. That’s exactly the kind of complexity that undermines both incident investigations and regulatory audits.

Shared IT/OT governance has emerged as dominant globally, used by nearly 70% of organizations, and it consistently produces the most balanced outcomes across visibility, speed and accountability. By contrast, OT-led governance tends to weaken auditability, while IT-led governance improves credential discipline but often slows workflows and struggles with cross-functional execution.

Alignment between IT and OT teams also appears to directly affect risk. The report says misalignment nearly triples exposure compared with fully aligned organizations, while strong alignment eliminates most prolonged vendor-access delays and significantly improves the odds of full audit trails. According to this survey, industrial remote access is not just a tooling problem; it is also an organizational one.

Zero Trust is the clearest maturity accelerator in the data. The report finds a steady, stepwise relationship between deeper Zero Trust adoption and stronger session visibility, better vendor oversight, faster access enablement and lower incident exposure. Even partial adoption delivers gains, but full adoption produces visibility levels “not achieved through tooling alone,” suggesting that identity, least privilege, segmentation and continuous monitoring are becoming operational requirements rather than aspirational controls.

Clemmer stressed the importance of zero trust, stating that organizations can’t allow straight VPN connections to Internet-connected controllers. “That's just bad design all around. All remote sessions must funnel through a heavily monitored jump host with MFA,” he said. “And if you do have the budget, a secure remote access solution using zero trust would be the gold standard here,” he added.

The report says industrial organizations are consolidating toward fewer, more unified and more auditable access, with OT-specific platforms increasingly acting as the control layer over legacy tools. OT platform users reported better session visibility, stronger auditability, faster enablement, better IT/OT alignment and lower incident rates than non-users.

For cybersecurity leaders protecting OT, the takeaway is that the biggest industrial remote-access risks are no longer hidden in shadowy attack paths, but in ordinary vendor workflows, fragmented tools and overestimated control maturity. And for now, the successful playbook appears to be shared governance, federated vendor control, stronger credential discipline and identity-centric remote access.

HOU.SEC.CON CTA

Latest