
As the manufacturing industry continues to evolve and rely on remote access to maintain operational continuity, a new challenge has emerged: balancing the need for speed with the requirement for secure third-party access governance. According to recent research by Secomea, many manufacturers are struggling to keep up with the demands of governing third-party access across their operational technology (OT) environments.
The past few years have seen a significant increase in ransomware attacks targeting industrial organizations, prompting manufacturers to invest heavily in securing remote access. However, as vendor ecosystems expand and regulations place greater emphasis on accountability, many organizations are discovering that enabling remote access is only part of the challenge. In fact, Secomea's latest State of Industrial Remote Access 2026 research suggests that many organizations are still struggling to close the gap between operational speed and third-party access governance.
The research highlights a growing dependence on third-party support, with 57% of organizations in North America managing six or more external vendors with remote access into OT environments. However, only 46% of these organizations report full auditability of vendor sessions, and just 23% review vendor credentials monthly or more frequently. This limited visibility into who has access and whether that access remains appropriate leaves many organizations vulnerable to potential security risks.
The findings also show that organizations with shared IT and OT ownership of remote access experience lower incident rates than those where responsibility sits solely within either function. This reinforces the importance of governance alongside technology in maintaining secure and efficient remote access. According to Secomea, effective third-party access governance extends beyond secure connectivity and combines identity verification, least-privilege access, just-in-time vendor access, centralized approval workflows, comprehensive audit trails, and rapid revocation of access once work is complete.
As the industry continues to shift towards more centralized governance models, manufacturers are looking for ways to improve visibility, accountability, and control over third-party access. In fact, more than three quarters of North American organizations say they either already use or would prefer a standardized platform for managing vendor access. This indicates a move away from fragmented VPNs and vendor-specific remote access tools towards more integrated solutions.
To address these challenges, Secomea recommends that manufacturers assess their remote access strategy to ensure it includes comprehensive governance, visibility, and control. This includes evaluating current vendor access management practices, implementing zero-trust principles, and improving visibility into OT remote access. By taking a more proactive and integrated approach to third-party access governance, manufacturers can reduce the risk of security breaches and maintain operational continuity while supporting the need for speed and efficiency.
57% of organizations in North America manage six or more external vendors with remote access into OT environments
Only 46% of organizations report full auditability of vendor sessions, and just 23% review vendor credentials monthly or more frequently
Organizations with shared IT and OT ownership of remote access experience lower incident rates than those where responsibility sits solely within either function
Effective third-party access governance extends beyond secure connectivity and combines identity verification, least-privilege access, and comprehensive audit trails
More than three quarters of North American organizations say they either already use or would prefer a standardized platform for managing vendor access