Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What do security teams get wrong about third-party…
Governance, Ownership & Risk

What do security teams get wrong about third-party access reviews in manufacturing networks?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 26, 2026 Domain: Governance, Ownership & Risk

A common mistake is treating vendor access like employee access and reviewing it too slowly. Third-party permissions should be more frequent, more granular, and tied to documented sessions where possible. Teams also miss the need to verify onboarding, offboarding, and privilege changes continuously. If vendor access is not visible and regularly checked, hidden exposure can persist long after the business need has ended.

What manufacturing access reviews often miss

Third-party access in manufacturing is not just another user list to certify. Vendors often connect through remote support channels, jump hosts, OT-adjacent tooling, or shared operational accounts, so the review has to reflect actual access paths, session frequency, and business purpose. The key mistake is judging access on a static roster instead of on how the vendor is really reaching production or plant systems.

Reviews also fail when teams copy employee recertification rules into a vendor context. A contractor with short, task-specific access should not sit on a quarterly cycle if the access was only needed for a one-day intervention, and a persistent maintenance relationship should be tied to a documented owner, scope, and renewal trigger. That is why access reviews need to be paired with onboarding, offboarding, and privilege change control, not treated as a standalone checkbox.

In practice, the review should answer three questions: who still needs access, what exact systems or sessions are in use, and whether that access still matches the approved work order or service relationship. If the team cannot connect an entitlement to a current operational need, the default should be removal or escalation for validation.

Why speed and granularity matter more than calendar-based review

Manufacturing environments accumulate stale third-party access quickly because support windows, outages, commissioning work, and vendor maintenance are often intermittent. A slow review cadence creates a large gap between the business event that justified the access and the point where someone checks whether it still exists. That gap is where hidden exposure persists, especially when vendor credentials are reused across sites or systems. See IAM and IGA Basics for the governance model behind access certification and entitlement review.

Granularity matters because “vendor access” is rarely one thing. It may include VPN entry, remote desktop, OT historian access, privileged application roles, or temporary break-glass permissions. A useful review separates those access paths and checks each one against the documented purpose. The same vendor can be low risk on a report-only account and high risk on a maintenance account with write access to production assets.

Manufacturing teams should also distinguish between an account being active and access being exercised. Session-level evidence, ticket linkage, and time-bounded approvals tell you much more than a name on an entitlement report. NHI Lifecycle Management Guide is useful here because it frames provisioning, offboarding, and visibility as lifecycle controls rather than periodic admin tasks.

How to make third-party reviews actually reflect plant reality

Good reviews start with the access path, not the org chart. For manufacturing networks, that means inventorying vendor entry points, mapping which systems each vendor can touch, and confirming whether access is direct, brokered, supervised, or inherited through another tool. When the environment includes OT or mixed IT/OT architecture, the review should also confirm that remote access is segmented from the control plane and that privilege does not cross zones without an explicit business case. A concise operational reference is Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs, which covers provisioning, rotation, offboarding, and governance.

Teams should expect the strongest control signal to come from change events: new vendor contracts, new plant lines, emergency support approvals, credential rotation, and departure of a named vendor contact. If those events are not feeding the review process, the review is already behind. Continuous verification matters more than a larger review packet.

Manufacturing access reviews work best when ownership is explicit. Operations owns the business need, security owns the control standard, and the system owner or vendor manager owns the evidence that the access still matches the job. If one team is expected to certify everything, the review usually turns into a rubber stamp.

Risk and Threat Considerations

Third-party access in manufacturing creates a long-lived exposure path when credentials, sessions, or remote support permissions remain active after the work has ended. The risk is not only unauthorized entry, but also delayed detection of privilege creep, reused access across plants, and a weak audit trail when a vendor account is shared or poorly scoped.

Failure mechanism: Access is granted for a legitimate maintenance or support need, then left in place because reviews are too infrequent, too broad, or disconnected from actual session activity and offboarding events.

Impact: Hidden vendor access can enable unauthorized changes, lateral movement into plant-connected assets, or prolonged exposure of operational systems long after the business justification has expired.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementVendor access reviews depend on lifecycle control of accounts and timely removal of unused access.
IA-5 — Authenticator ManagementThird-party access often persists through unmanaged credentials, tokens, or shared authenticators.
AC-6 — Least PrivilegeManufacturing vendor access should be limited to the narrowest systems and actions required.
Recommendation — Review and revoke third-party accounts on defined triggers, not only on a calendar cadence. Rotate, expire, and trace authenticators used by vendors and service access paths. Restrict third-party permissions to the minimum scope needed for the approved task.
CIS Controls v8CIS-6 — Access Control ManagementAccess reviews in manufacturing are fundamentally about managing who can reach critical systems and why.
CIS-5 — Account ManagementVendor accounts need continuous review, onboarding, and offboarding discipline to prevent stale exposure.
Recommendation — Inventory third-party access paths and remove any entitlement that lacks a current business need. Maintain a complete account inventory and retire third-party access when the relationship changes.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication and Access ControlThe question centers on verifying and constraining third-party access to plant-connected assets.
GV.RM-01 — Risk Management StrategyManufacturing teams must align vendor access review frequency and depth with operational risk.
Recommendation — Validate that third-party identities and access rights are approved, current, and appropriately constrained. Set review frequency and escalation thresholds based on the business impact of vendor access.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThird-party access frequently becomes over-scoped when vendor permissions are reviewed too slowly.
NHI-01 — Improper OffboardingThe page explicitly highlights missed offboarding as a source of persistent hidden exposure.
NHI-07 — Long-Lived SecretsStale manufacturing access often survives because credentials and tokens are allowed to live too long.
Recommendation — Strip vendor access back to the smallest viable privilege set and recertify it often. Remove vendor access immediately when the business need ends or the relationship changes. Expire and rotate vendor secrets on a short, enforced lifecycle tied to actual use.

Practitioner Guidance

What to prioritise: Review vendor access by session, system, and business owner, not by vendor name alone. The highest-value checks are the ones that can revoke unused access quickly and prove whether a permission is still tied to current work.

What to verify: Confirm that every third-party entitlement has a named owner, a current ticket or contract basis, and a revocation path for offboarding or scope changes. If you cannot show when the access was last used, treat it as an exception that needs validation.

Practitioner takeaway: In manufacturing, third-party access reviews are only effective when they are event-driven, session-aware, and tied to operational ownership, otherwise they become a delayed inventory of risk rather than a control.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org