Join our Newsletter — 33% off our NHI Course

How should manufacturers implement zero trust when legacy systems and new connectivity are expanding the attack surface?

Manufacturers should start by treating connectivity as a security decision, not a convenience choice. Zero trust works best when access is granular, time-bound, and continuously verified across users, devices, and sessions. That means combining MFA, session controls, and credential management so older systems are not exposed through broad network access or static trust assumptions.

How zero trust changes the way manufacturers think about legacy and connected environments

Manufacturing environments usually contain a mix of long-lived operational technology, modern IT services, remote access paths, and newer connectivity layers. zero trust is useful here because it shifts the question from “what network is this on?” to “what is this system, who or what is asking, and what is it allowed to do right now?” That matters most when old systems cannot easily be rebuilt but still need controlled access.

The practical goal is not to turn every plant asset into a modern platform. It is to place hard boundaries around trust, so legacy systems are reached through narrow, verified paths rather than broad internal network access. In a manufacturing setting, that usually means identity-aware access, device checks, segmented connections, and per-session policy decisions that reduce the blast radius of a compromise.

For connected plants, zero trust also has to cope with the fact that the attack surface is expanding through suppliers, remote support, IIoT devices, and production integrations. Zero Trust Identity Guide is a useful reference for this because it frames zero trust as an identity-centric model rather than a pure network redesign. That is the right lens when access must be tightened without disrupting production flows.

Where legacy systems create the hardest zero trust decisions

Legacy systems are difficult because they often depend on static credentials, flat network trust, weak protocol support, or vendors that cannot support modern authentication. If those systems are simply left on the internal network, they become easy lateral movement targets. If they are isolated too aggressively, operators may break essential workflows or maintenance access.

The best zero trust pattern is usually to wrap the legacy asset with compensating controls instead of trying to modernize it first. That can include gateway-mediated access, strong authentication at the entry point, session recording, short-lived access windows, and explicit allow lists for users, devices, and services. The point is to replace ambient trust with deliberate, inspectable access.

This is also where IAM and IGA Basics helps because the real problem is not only authentication, but also entitlement creep, access reviews, and ownership of machine and human access. Manufacturers often discover that the legacy system is not the only issue, the surrounding access model is what quietly turns one old asset into a broad enterprise risk.

For workload-to-workload or service-to-service access, Guide to SPIFFE and SPIRE is relevant because it shows how to move from shared secrets and implicit trust to verifiable workload identity. That approach is especially valuable where factory applications, brokers, or automation services need to talk to each other without exposing reusable credentials across the environment.

How to sequence the rollout without disrupting production

Manufacturers usually get better results when they start at the access edge rather than inside the oldest asset itself. First, identify the most sensitive legacy systems and the most exposed connectivity paths, then place policy enforcement around those paths. Next, require stronger identity checks for remote users, privileged operators, vendors, and service connections that can reach production assets.

From there, reduce standing access. Time-bound approvals, session controls, and limited privileges are far more practical than trying to trust a legacy host to enforce modern authorization on its own. If the system cannot support modern controls internally, enforce them in the surrounding control plane and make the gateway the point of decision.

NIST SP 800-207 Zero Trust Architecture is the clearest external anchor for this approach because it supports continuous verification, least privilege, and segmentation as architecture principles. That matters in manufacturing because the rollout is usually incremental, not a single replacement project, and the architecture has to work while old and new systems coexist.

Remote Access Identity Guide is also practical here because remote vendors and maintenance engineers are often the first path attackers try. Tight MFA, device posture checks, and dormant-account cleanup can remove easy entry points without redesigning the plant.

Risk and Threat Considerations

Manufacturing zero trust projects fail when teams leave legacy reachability intact in the name of uptime. The risk is that broad internal connectivity, reused credentials, and weak segmentation let one compromised account or device move from office IT into production systems, maintenance interfaces, or supplier links.

Failure mechanism: Attackers and opportunistic malware exploit static trust assumptions, such as flat VLAN access, shared accounts, long-lived credentials, or direct remote administration paths, then pivot laterally until they reach higher-value operational assets.

Impact: The result can be production disruption, unsafe control exposure, unauthorized recipe or configuration changes, and wider business interruption because the old system is still connected to the rest of the environment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST Zero Trust (SP 800-207), NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST Zero Trust (SP 800-207) PR.AA-05 — Asset Identity Authentication and Authorization Zero trust access decisions and least privilege are central to the question.
Recommendation — Enforce identity-based access decisions and segment legacy systems behind policy-controlled gateways.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management The answer relies on managing credentials and time-bound access for connected manufacturing systems.
AC-6 — Least Privilege The question is about shrinking broad access to legacy systems as attack surface expands.
Recommendation — Rotate and control authenticators used to reach legacy and connected plant systems. Limit each user, device, and service to the minimum access needed for the production task.
CSA Cloud Controls Matrix IAM — Identity and Access Management Connected manufacturing environments need governed identity and access across people and services.
Recommendation — Apply identity governance to operator, vendor, and machine access paths.
ISO/IEC 27001:2022 A.5.15 — Access Control Manufacturers need formal access control around legacy and newly connected environments.
Recommendation — Define and enforce access control rules for all production and remote pathways.

Practitioner Guidance

What to prioritise: Start with the highest-consequence pathways, not the oldest assets. In most factories that means remote vendor access, operator jump paths, engineering workstations, and any service account that can reach production control systems.

What to verify: Confirm that every path into a legacy system is mediated by an identity-aware control point, and that the access granted is narrower than what the network would otherwise allow. If a user or service can still reach the asset without a fresh decision, the zero trust model is incomplete.

Common mistake: Treating MFA alone as zero trust. MFA helps, but the real control is the combination of identity, device, session, and privilege boundaries, especially where older systems cannot enforce those rules themselves.

Practitioner takeaway: In manufacturing, zero trust succeeds when access is engineered around production reality, meaning legacy systems stay usable while their trust boundaries become narrow, explicit, and continuously enforced.