Join our Newsletter — 33% off our NHI Course

What happens when factories add connectivity without rethinking identity and access controls?

When connectivity expands without tighter access governance, a small change can open a much larger attack path. A previously local device may become reachable across the network and then from the internet, creating new opportunities for intrusion. In practice, this can expose critical systems, increase ransomware impact, and make recovery more disruptive and expensive.

How connectivity changes the attack surface in a factory

Adding network reachability changes more than the transport layer. Once a device can be addressed remotely, its identity, trust boundary, and permission model start to matter as much as its physical function. If an operator, engineer, vendor tool, or automated process can reach it, the question becomes who can authenticate, what they can do, and how far that access can spread when the environment is flat or poorly segmented.

That is why connectivity projects fail when they are treated as pure networking upgrades. A factory asset that was previously isolated may now depend on accounts, certificates, shared secrets, service permissions, or remote management channels. If those controls were never redesigned, the new connectivity can bypass the original safety of physical isolation and create a path into systems that were never intended to be reachable from broader enterprise networks.

In practice, the risk grows fastest when connected devices inherit broad trust from adjacent systems. A single exposed remote management interface, weak shared credential, or vendor remote-access path can become the entry point to controllers, historians, engineering workstations, or backup systems. That is why connectivity should be reviewed as an access-design problem, not just a topology change. The IAM and IGA Basics guide is useful here because the core issue is whether every new path has a clear identity, purpose, and approval model.

Why the blast radius expands when identity is not redesigned

Factories often begin with local trust assumptions: a device sits on an internal network, a technician is nearby, and only a small set of people or tools can touch it. Connectivity breaks those assumptions. Once remote access exists, permission scope becomes the real control point, and excessive privilege can turn a convenience feature into a lateral-movement path. If the same credentials or tokens work across multiple zones, one compromise can reach far beyond the original device.

This is especially dangerous in environments where operational uptime is prized over access hygiene. Shared accounts, long-lived secrets, and reusable vendor credentials can persist after the original reason for access has changed. The result is not just a bigger number of endpoints, but a larger trust graph. NHI Lifecycle Management Guide is relevant because the lifecycle problem is often the hidden failure point: access was granted for deployment, never narrowed, and never retired.

When access is redesigned properly, the environment can support remote operations without inheriting blanket trust. That usually means separating human operator access from machine-to-machine access, narrowing authorization by function, and making every remote path explicit. Authorisation Models Guide helps explain why coarse roles are often too blunt for industrial access, where context such as device type, site, zone, and purpose can materially change what should be allowed.

How to connect industrial systems without creating a security debt

The safest pattern is to design the access model before the connectivity rollout, not after incidents force a retrofit. That means inventorying every remotely reachable asset, identifying who or what needs to access it, and deciding whether the access is human, vendor, workload, or automated. In factories, that distinction matters because the same interface may be used by maintenance staff, OEM support, and orchestration tools, each with different privilege needs.

Good practice also includes minimizing standing access, isolating administrative paths, and ensuring remote connectivity is time-bound and observable. If a vendor session can reach a control network, it should be treated as high-risk access with strong approval, logging, and revocation discipline. For many environments, the operational rule is simple: if a connection can change a physical process, it should be governed like privileged access, not ordinary IT access. The Privileged Access Management Guide is a strong companion for this because it focuses on least privilege, just-in-time access, and session control.

Finally, segmentation should reflect process boundaries, not just office-network conventions. A plant floor, engineering network, remote support channel, and backup zone should not all share the same trust posture. Where possible, use explicit service identities, short-lived credentials, and tightly scoped access to limit the damage if one connection path is abused. The SPIFFE workload identity specification is a useful external reference for this principle because it shows how machine and workload identity can be made explicit rather than implicit.

Risk and Threat Considerations

Connectivity increases exposure in two ways: it broadens who can reach the asset and it enlarges the consequences of a credential or remote-access failure. In an operational environment, that can turn a single misconfigured access path into a route for intrusion, ransomware propagation, or disruptive process interference.

Failure mechanism: A device or controller that was previously insulated by physical separation is made remotely reachable, but its identity and authorization controls remain broad, shared, or long-lived. An attacker, contractor account, or compromised management tool can then move from one reachable system into others that were never intended to be in the same trust zone.

Impact: The result is a larger blast radius, higher likelihood of lateral movement, and slower recovery because plant systems, backups, and engineering tools may all be affected at once. Remediation becomes more expensive when access paths are intertwined and ownership of credentials is unclear.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-9 — Identification and Authentication (Non-Organizational Users) Remote vendor and machine access in factories depends on strong authentication controls for non-employee identities.
AC-6 — Least Privilege Expanded connectivity becomes dangerous when devices inherit excessive permissions or broad remote reach.
IA-5 — Authenticator Management Long-lived shared secrets and reusable credentials often create the hidden exposure in connected plants.
Recommendation — Apply IA-9 to require strong authentication for external and machine access paths. Apply AC-6 to limit each connected asset to the minimum access it needs. Apply IA-5 to rotate, protect, and retire authenticators on a defined lifecycle.
ISO/IEC 27001:2022 A.5.15 — Access control Connectivity without access redesign is fundamentally an access-control problem in the ISMS.
Recommendation — Define and enforce access-control rules for every new remote path.
CIS Controls v8 CIS-6 — Access Control Management Connected factory assets need account and access governance to prevent broad trust and lateral spread.
Recommendation — Implement access control management to limit and review who can reach industrial systems.

Practitioner Guidance

What to prioritise: Treat the first connectivity wave as an access redesign exercise. Start with the assets whose compromise would affect production, safety, or recovery, then map exactly who or what needs remote access and why.

What to verify: Confirm that every remote path has an explicit owner, a narrowly scoped purpose, and a revocation method. If you cannot quickly answer who can connect, with what identity, and from where, the access model is not yet ready.

Practitioner takeaway: Connectivity is not the control; governed access is. The factory becomes materially safer only when remote reachability is matched by clear identity, tight authorization, and short-lived privilege.