When an original equipment manufacturer, or OEM, remotely connects to a factory environment, it may diagnose equipment or configure a programmable logic controller. This connection creates a temporary pathway through the organisation’s security boundary.
This access may be necessary to maintain equipment and avoid production delays. However, the organisation should still be able to prove:
• Who accessed the environment
• Which systems they accessed
• What actions they performed
• Whether the session was monitored
• When the access was disabled
In many manufacturing organisations, third-party access policies exist, but the technical evidence needed to prove that those policies are being followed is incomplete or unavailable.
The Gap Between Policy and Factory-Floor Reality
Most organisations have vendor management policies, supplier contracts and approved maintenance procedures.
The governance gap often appears when these requirements are applied within operational technology environments.
For example, remote vendor connections may remain active after an approved maintenance window has ended to prevent future production delays. Some connections may bypass standard authentication, logging or network segmentation controls. Others may use shared credentials, making it difficult to identify the individual responsible for each action.
During a recent control maturity review, an OEM gateway was found to have direct access to plant controllers without effective session timeouts or adequate network segmentation.
The organisation had documented requirements for third-party access. However, it could not provide reliable evidence that those requirements were consistently enforced within the production environment.
This is the difference between having a policy and being able to prove that the policy is working.
Supplier Trust Is Not Control Evidence
A long-standing relationship with an equipment supplier does not remove the need to verify how its access is controlled.
During a security incident, operational disruption, client assessment or cyber security audit, supplier reputation and contractual terms alone will not prove:
• That each access request was authorised
• That multi-factor authentication was enforced
• That user activity was logged and reviewed
• That vendor access was restricted to approved systems
• That the connection was disabled when the maintenance window ended
Security frameworks and guidance, including the ASD Essential Eight and ISO/IEC 27001, support the broader principles of controlled access, secure system configuration and verifiable security practices.
However, these principles must be applied in a way that reflects the organisation’s specific OT (operational technology) architecture, operational risks and safety requirements. A secure configuration review can help determine whether remote access systems, gateways and connected assets have been configured in line with approved security requirements.
Where remote access involves personal information, organisations operating in New Zealand should also consider their obligations under the Privacy Act 2020, including the requirement to use reasonable safeguards to protect that information.
Other legal, contractual or sector-specific obligations may apply depending on the organisation, its clients and the services it provides. Regardless of the specific framework, the underlying governance expectation remains the same: external access should be authorised, restricted, monitored and supported by reliable evidence.
What Defensible OEM Access Should Include
Manufacturing leaders should be able to demonstrate that remote maintenance access is:
• Approved for a specific business purpose
• Limited to a defined maintenance period
• Protected by strong, individual authentication
• Restricted to approved systems through network segmentation
• Logged against an identifiable individual user
• Monitored while the session is active
• Automatically disabled when the authorised period ends
• Regularly assessed through control maturity reviews and secure configuration assessments
These controls do more than reduce technical security risks.
They give boards, executives, auditors and enterprise clients confidence that the organisation’s documented governance requirements are operating effectively within the production environment.
They also provide clear evidence during assessments conducted by Essential Eight security auditors, ISO 27001 information security auditors, or other independent assurance professionals.
Turning OT Assurance Into Actionable Outcomes
Effective OT assurance requires professionals who understand both cybersecurity governance and the practical realities of factory-floor operations.
Cybernetic Global Intelligence works with manufacturing leaders, OT teams and governance stakeholders to:
• Identify remote access pathways
• Review how OEM connections are authorised
• Validate authentication, logging and segmentation controls
• Assess whether access is removed when it is no longer required
• Identify weaknesses before they become audit findings, security incidents or operational disruptions
Clients work directly with experienced OT and governance, risk and compliance assessors throughout the engagement. This supports clear communication, timely decisions and practical recommendations that reflect the organisation’s operating environment.
Organisations seeking a certified cyber security consultant in Australia should look for professionals who can connect governance requirements with the technical and operational conditions found in industrial environments.
The outcome should not be another generic checklist.
It should be clear, board-ready evidence showing:
• Which controls are working effectively
• Where security or governance gaps remain
• What risks those gaps create
• Which improvements should be prioritised
Remote OEM access should support production continuity without weakening security governance. The question is not simply whether your suppliers are trusted. The question is whether their access is controlled, monitored and independently verifiable.