Join our Newsletter — 33% off our NHI Course

Vendor access in water utilities: are OT controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Water utilities face elevated cyber risk because remote vendor access, default credentials, shared accounts, and limited centralised control still create easy paths into operational technology, according to StrongDM’s discussion of the NIST NCCoE water and wastewater reference design. The governance problem is not connectivity itself but whether access can be bounded, monitored, and revoked without weakening operations.

Editorial analysis by NHI Mgmt Group, based on content published by StrongDM: “Water Utilities Cybersecurity Guide: Challenges & Solution”.

Key questions

Q: What breaks when water utilities rely on vendor access without OT identity governance?

A: The control gap is that external support becomes a standing access path instead of a task-specific exception.

Q: Why do shared OT accounts increase risk in critical infrastructure environments?

A: Shared accounts erase attribution and let several people act through the same credential, which means no one can tell which operator, contractor or attacker performed a sensitive action.

Q: How should utilities phase out default credentials in OT systems?

A: Start by inventorying devices that still ship with vendor or inherited defaults, then replace them with uniquely owned credentials and a recovery process that does not depend on the original shared secret.

Practitioner guidance

  • Tighten vendor support pathways Map every external maintenance path into a single inventory that shows who can reach which OT assets, through what mechanism and under what approval condition.
  • Eliminate default OT credentials Remove manufacturer and inherited defaults from devices and controllers, then verify that replacement credentials have named owners and documented recovery steps.
  • Remove shared accounts from OT access Assign one identity per person or service role so access reviews, incident reconstruction and emergency revocation are all possible.

Bottom line: Water utility OT risk is being amplified by access patterns that are hard to govern, not by connectivity alone.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Vendor access is the governance boundary that OT security often fails to treat as identity infrastructure. Water utilities do not just have a connectivity problem. They have a lifecycle problem, because outside support paths frequently remain active longer than the work they are meant to enable. That makes vendor access a standing identity issue, not a temporary operational convenience. The practitioner conclusion is simple: if the access path cannot be bounded, it is already an exposure path.

A question worth separating out:

Q: What should security teams do when remote vendor access is already embedded in OT operations?

A: They should bring that access into one policy layer, define which actions are allowed on which systems and ensure every session is logged and revocable. If vendor access remains ad hoc, OT risk will stay permanently elevated.

👉 Read our full editorial: Water utility cyber risk exposes vendor access gaps in OT security


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.