Let’s Talk About Vendor Access Hiccups in Manufacturing
Manufacturers have been beefing up their cybersecurity like they're preparing for battle—courtesy of ransomware attacks that hit like a freight train. But as much as they're focused on locking the digital door, a new boogeyman’s revealed itself: the riddle of governing third-party access in operational technology (OT) environments.
Where the Challenges Lie
I mean, it's one thing to secure remote access like a well-fortified bunker, but governing who gets in and out with a golden ticket is another ballgame entirely. Manufacturers, machine builders, and everyone in between are beginning to realize that. Enable remote access? Check. But there's still this scuffle over the control knobs for third-party entry.
"Manufacturers don't need fewer vendors, they need better governance of vendor access," says Knud Kegel, CTPO at Secomea.
Digging into the latest research by Secomea, a whopping 57% of outfits on this side of the Atlantic are juggling six or more external players with their OT environments. And don’t you know it? Only 46% have got their audit game tight, meaning they can track everything those vendors do. Few—just 23%—bother peeking monthly at credentials. That leaves a whole lot of blind spots, folks.
Where Governance Needs a Breakthrough
Now, why should we care? Because when cyber threats get cunning, exploiting trusted identities becomes fair game. This isn’t just about plugging leaks; it’s about knowing when and why those leaks occur and nipping ’em in the bud without grinding production to a halt.
- Audit every session and who gets access
- Review vendor credentials more than twice a year
- Centralize approval workflows—IT and OT, shake hands
- Switch to just-in-time access, scrap the endless open invites
It seems like the ones who lead in locking down vendor access are also the ones seeing fewer incidents. They're closing the gap by blending ownership—shared by IT and OT—leading to better results. So, the smart money might hedge on the companies following suit.
The Pathway to Resilience
Secomea’s workhorse report highlights the trend toward a standardized platform for vendor access. Many North American companies say they’re either in on it or wish to be. The days of fragmented VPNs could be numbered. Central governance is your friend when trust gets tested.
Secomea’s playbook—worth a gander—involves some next-gen flexibility folks will need if they want in on secure OT benefits without parkas full of pain. And who doesn’t want less pain these days?
What's the Bigger Picture?
You keep hearing about Zero Trust—essentially trust no one until verified. It’s still a new chapter, but a vital one where Secomea shines as a useful ally amidst this seismic shift. They're carving out their turf as a Secure Remote Access solution geared for industrial networks. Don’t sleep on it if you’ve got your chips down in manufacturing.
With over 8,000 manufacturers using Secomea's services to safeguard operations, the importance of bolstering accountability and control in this sector can't be overstated. Now, that’s something even the crustiest stock vet like me can appreciate.