Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security How should manufacturers reduce IT and OT attack…
Cyber Security

How should manufacturers reduce IT and OT attack surface exposure as digital systems converge on the factory floor?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Cyber Security

Manufacturers should treat OT and IT convergence as an attack surface expansion problem, not just a productivity upgrade. Start by validating exposed paths, then automate repeatable testing, prioritize remediation by business impact, and benchmark results over time. The goal is to find real exploitability before attackers do, reduce downtime risk, and keep security controls aligned with operational constraints.

What “attack surface exposure” means when IT and OT converge

In a converged factory environment, the attack surface is no longer just the plant network or the enterprise network, it is the trust boundary between them. Every new remote access path, integration, shared credential, exposed management interface, and bridged data flow creates a possible route from low-criticality systems into production operations. The practical question is not whether systems are connected, but which connections are actually exploitable.

Manufacturers should separate convenience connections from necessary production dependencies, then validate which paths are reachable, authenticated, and permitted at runtime. That is the difference between a visible architecture and a defensible one. Baseline coverage should include IT systems that can influence OT, because compromise often moves through identity, remote administration, patch orchestration, or file transfer paths rather than directly through the controller layer.

A useful reference point for OT-specific exposure is NIST SP 800-82 Rev 3, OT Security Guide, which frames segmentation, system boundaries, and industrial control constraints as core design concerns. For operational context and advisories, CISA Industrial Control Systems remains a practical source for industrial environment guidance.

How to reduce exposure without breaking production

The strongest pattern is to reduce surface area in layers. Start with externally reachable services and anything that bridges IT and OT, then move inward to admin interfaces, vendor access, monitoring paths, and any accounts or secrets that can reach multiple environments. The goal is to remove unnecessary exposure first, then tighten what must remain through segmentation, allowlisting, and privilege reduction.

Automated discovery and repeatable testing matter because factory environments change constantly, and manual reviews age quickly. Teams should validate exposed services, scan for misrouted traffic, test policy enforcement, and compare results over time so that new access paths are caught early. This is especially important where safety, uptime, and maintenance windows limit how aggressively controls can be changed.

Attack paths often rely on weak trust assumptions, such as “this management network is internal” or “this vendor tunnel is temporary.” A breach of a shared service, exposed credential, or remote support channel can become a stepping stone into OT if the path is not tightly bounded. That is why manufacturers should treat secrets sprawl and exposed credentials as part of attack surface reduction, not as an isolated identity hygiene issue. The same logic appears in real breach cases such as Schneider Electric credentials breach, where exposed credentials became the entry point to broader access.

What good practice looks like on the factory floor

Good practice is measurable. Manufacturers should be able to show which IT to OT paths exist, which are approved, which are monitored, and which have been removed. They should also be able to rank remediation by business impact, so the highest-risk exposure is addressed first rather than the easiest issue. When a control would increase downtime risk, the decision should be explicit, documented, and tied to an operational owner.

One practical benchmark is whether the organisation can prove that exposed paths shrink over time while production stability stays intact. If the answer is no, the program is still inventorying risk rather than reducing it. Visibility into credentials, vendor connections, and cross-domain access is often the hardest part, which is why poor secret handling is so dangerous in converged environments. NHIMG’s 2025 State of NHIs and Secrets in Cybersecurity is useful background for the broader exposure problem, especially where shared or long-lived credentials persist across environments.

For the attack-surface control layer, manufacturers can also benefit from the NHI and secret-sprawl lens because machine-to-machine access often becomes the easiest path between IT and OT. The fact that many organisations still store secrets in vulnerable locations makes exposure reduction a lifecycle issue, not a one-time hardening project. That is why secrets sprawl analysis and NHI governance guidance are directly relevant when factory operations depend on service accounts, API keys, and remote integrations.

Practitioner takeaway: In converged manufacturing environments, the real win is not fewer connections, it is fewer unbounded connections. If a path cannot be justified, monitored, and constrained by business need, it should not be trusted enough to reach production.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.RA — Risk AssessmentConvergence changes exposure and attack paths, so risk assessment must be continuous.
PR.AC — Identity Management, Authentication and Access ControlShared access paths and remote administration are central to converged factory exposure.
PR.DS — Data SecuritySecrets, credentials, and control data often bridge IT and OT environments.
Recommendation — Assess IT and OT exposure changes continuously and prioritize the highest-impact paths first. Restrict cross-domain access with strong authentication and least privilege. Protect credentials, tokens, and operational data wherever they cross environment boundaries.
NIST SP 800-63IAL — Identity Assurance LevelRemote and vendor access into OT depends on trustworthy identity proofing and assurance.
AAL — Authenticator Assurance LevelConverged environments need strong authentication for privileged cross-domain access.
Recommendation — Use higher assurance where remote access can reach production systems. Require stronger authenticators for accounts that can cross from IT into OT.
NIST Zero Trust (SP 800-207)JAA — Policy Decision and EnforcementZero trust is directly relevant to constraining which IT paths can reach OT assets.
DP — Continuous Diagnostics and MitigationAttack surface reduction requires ongoing validation of reachable paths and trust assumptions.
Recommendation — Enforce policy decisions at each boundary instead of trusting the factory network implicitly. Continuously validate access paths and remove any connection that is no longer justified.
CIS Controls v86.3 — Remove Disabled or Unused AccountsUnneeded accounts and vendor access often expand the IT OT attack surface.
4.8 — Unapproved Remote Access SoftwareRemote support tools are common exposure points in factory environments.
12.1 — Network Infrastructure ManagementSegmentation and boundary control are essential to limiting lateral movement into OT.
Recommendation — Remove unused cross-domain accounts and revoke stale OT-adjacent access. Block unauthorized remote access tools and tightly control approved support channels. Segment IT and OT networks and restrict routing between them to necessary flows only.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org