Manufacturers should treat IoT expansion as an identity and access problem, not only an asset problem. The practical response is to tighten privileged access for vendors, limit always-on access, segment production systems, and verify every connection into operational technology. This reduces the chance that a single compromised credential or device becomes a plant-wide disruption or a path to sensitive process data.
Why manufacturers should treat vendor and IoT expansion as an access-control problem
As factories add sensors, connected equipment, remote service channels, and supplier portals, the attack surface grows in two directions at once: more devices to expose, and more external parties able to reach production. That means the practical control point is not just inventory, but who can authenticate, what they can touch, and how long that access stays valid. For vendor access, the most relevant starting point is a strict third-party access model like Third-Party, B2B and Contractor Access Guide, because it aligns sponsorship, least privilege, and time-bounded access with operational reality.
In manufacturing, that distinction matters because an IoT device often becomes a bridge into operational technology, while a vendor credential can become a bridge into the same environment through support channels, maintenance tools, or shared management planes. The security question is therefore not only whether the device is patched, but whether its access path is intentionally constrained, observed, and revocable.
Manufacturers should assume that every new connected endpoint increases both exposure and the number of trust relationships that must be governed.
Which controls actually shrink the blast radius
The strongest reductions in cyber risk come from combining access restriction with network segmentation and explicit oversight of privileged activity. Remote vendors should not hold always-on access to production unless there is a documented operational need, and even then the access should be narrowed to specific systems, windows, and functions. A privileged session model helps here because it can broker, record, and control high-risk sessions, including vendor remote access, as described in Privileged Session Management Guide.
IoT and OT environments also need a zone-based design so that a compromised endpoint does not become a universal pivot point. The practical goal is to make each device, account, and remote path useful for one purpose only, rather than allowing shared access patterns that collapse into plant-wide trust. That is why an OT-specific identity model is useful for operations teams: OT and ICS Identity and Access Guide ties vendor remote access, PAM, shared-account risk, and segmentation together in a way generic IT guidance often does not.
Manufacturers should also separate device trust from operator trust, because a well-managed device can still become dangerous if its management account, API key, or remote support channel is overexposed.
What good looks like when production systems are exposed to vendors
Good practice is visible when the plant can answer four questions quickly: who can reach the system, from where, for how long, and under what approval. If a vendor can connect without a named owner, a defined time limit, or session oversight, the exposure is already too broad. In parallel, every remote path should be segment-scoped so that support access to one asset does not create lateral movement into adjacent systems, historians, or engineering workstations.
For manufacturers, this also means verifying that exception handling is controlled. Emergency access should be rare, logged, and reviewed, not treated as a standing workaround. A useful benchmark is whether the organisation can remove a vendor account, rotate the related credential, or disable an IoT management path without breaking unrelated operations. If not, the access design is too coupled to tolerate compromise.
Manufacturers should measure whether access is time-bound, attributable, and segment-limited, because those are the conditions that prevent routine support from becoming a persistent intrusion path.
Risk and Threat Considerations
Expanded IoT and vendor access create two compounding risks: exposed devices increase the number of potential footholds, and external access paths increase the chance that a single stolen credential or abused session can reach production systems. The most dangerous failure mode is not a noisy outage, but quiet privilege reuse across multiple machines or sites, where one compromised connection can move from maintenance access into sensitive process data or operational disruption.
Failure mechanism: Attackers or intruders can exploit overbroad vendor access, shared accounts, weak segmentation, or long-lived credentials to pivot from a low-value entry point into production control paths, then reuse that trust to persist or move laterally.
Impact: The result can be plant interruption, loss of process visibility, tampering with industrial systems, exposure of sensitive operational data, or a larger recovery effort because the compromise sits inside a trusted maintenance channel.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Vendor and IoT access should be limited to only the functions needed. |
| IA-9 — Service Identification and Authentication | Connected devices and remote services need strong machine-to-machine authentication. | |
| SC-7 — Boundary Protection | Segmentation and zone boundaries are central to limiting lateral movement in OT environments. | |
| Recommendation — Enforce least privilege for vendor and OT accounts. Require authenticated trust for device and service connections. Segment OT networks to contain vendor or IoT compromise. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | The question centers on constraining and reviewing external access to production. |
| CIS-12 — Network Infrastructure Management | Network segmentation and boundary control are key to reducing IoT-driven exposure. | |
| Recommendation — Review and restrict vendor access paths regularly. Separate production zones from less trusted networks. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Manufacturers must govern who can reach connected systems and vendor channels. |
| A.8.5 — Secure authentication | Remote vendor and device access depends on strong authentication. | |
| Recommendation — Apply access control to all remote and operational entry points. Use strong authentication for vendor and device access. | ||
Practitioner Guidance
What to prioritise: Start with the access paths that can reach production, not with the largest list of connected assets. If a vendor, integrator, or remote service tool can authenticate into operational technology, treat that path as a critical control point and verify ownership, approval, session recording, and revocation first.
What to verify: Confirm that every vendor connection has a business owner, a scope boundary, a time limit, and a reviewable audit trail. If any of those are missing, the access model is still relying on trust rather than control.
Practitioner takeaway: In manufacturing, IoT risk is reduced less by counting devices and more by compressing the number of trusted paths into production, because smaller trust boundaries create smaller blast radii.
Related resources from NHI Mgmt Group
- How should security teams reduce breach risk when APIs, third parties, and privileged accounts expand the attack surface?
- How should security teams use cyber asset context to reduce attack surface risk at scale?
- How should security teams reduce portal risk when internal apps, APIs, and third-party services expand the attack surface?
- How should healthcare IT teams reduce breach risk when vendors, VPNs, and shared credentials expand the attack surface?