A trusted equipment vendor still needs controlled access. Use this practical protocol to approve, restrict, monitor, and close remote support sessions.
Remote support needs an owner
A vendor connects to fix a machine, production gets moving, and everyone goes back to work. But can the vendor still connect tomorrow—and can that account reach other equipment?
Remote access may use a VPN, support app, cloud portal, engineering computer, or vendor-installed router. It can help keep equipment running, but old accounts, shared passwords, or overly broad permissions can leave more access than the job requires. CISA and partners describe how attackers misuse remote access software in their joint guide.
A short checklist for every support job
Have one person from maintenance or operations approve the job, with your IT provider or administrator handling the access settings. Before the connection starts, confirm:
- Who is connecting? Verify the technician through a known vendor number or support portal—not an unexpected caller’s contact details.
- What is the job? Record the work order, target machine, permitted work, approver, and start and end time. Get approval again if the work or systems change.
- Is the account protected? Use a named account for each person, require multifactor authentication (MFA), and give only the permissions needed. Avoid shared or default passwords.
- Can the connection reach only the approved equipment? Ask your IT provider to show the permitted destinations. A VPN alone does not prove access is restricted. Check with the equipment owner before changing plant connectivity.
- How will you know it is over? Agree who will review available connection and maintenance records. Close the session, remove temporary permissions, and confirm the vendor cannot reconnect through that temporary access.
Write down what happened
Keep a short record with the work order: vendor and technician, verified contact, approver and time window, machine and allowed work, access safeguards, available session records, outcome, and confirmation that temporary access was removed. Keep passwords and recovery codes out of the record.
If standing access is needed for support, name an internal owner, limit its reach, set a review date, and document how to disable it. Logs may show when and where someone connected without showing every action.
Agree responsibilities with the vendor
Ask who at the vendor is allowed to connect, whether subcontractors are involved, who maintains the remote-access software, what activity records you can receive, and whom to contact about a security incident. Agree how access will be removed when staff or contracts change.
CISA and the FBI's September 2026 guidance for critical infrastructure operators discusses vendor access, authorized personnel, patching, and monitoring. Manufacturers can use these as considerations—not as a mandatory checklist. NIST's Cybersecurity Framework also covers supplier oversight and responsibilities.
Know what a review can—and cannot—tell you
If a connection looks unfamiliar, check it with your IT and operations leads and the vendor contact you already trust. Preserve available records and follow your incident plan. Do not disconnect or reboot production equipment without involving the equipment owner; an abrupt change could affect safe operations.
A public exposure review can identify observable services on the internet, but it cannot verify who has an internal vendor account or what that account can reach. Public visibility alone does not prove a system is vulnerable or compromised.
For businesses with up to 25 employees, the $1,995 Business Security Baseline reviews agreed internal safeguards, including Microsoft 365 identity and access. It is not an OT assessment and does not, by itself, verify vendor sessions to production equipment.
Need help reviewing vendor access?
An Independent Security Review can be scoped around agreed systems, vendor responsibilities, and available evidence. Production-system testing or OT engineering is not included unless expressly agreed. The free Exposure Review is limited to public signals; it cannot verify internal vendor permissions.
