Case Study Vendor Access, Zero Trust Manufacturing

Governing Third-Party Remote Access on a Discrete Manufacturing Plant Floor

A manufacturer replaced standing vendor VPN access to production line PLCs with time-boxed, logged, per-ticket access after a near-miss configuration error.

C By CYNAPSE Knowledge Team 22 Jul 2026 | 05:42

Environment

A discrete manufacturing plant relied on several equipment vendors for ongoing support of PLCs and robotic cells on the production floor. Each vendor had been issued a standing VPN account, set up years earlier during initial commissioning and never revisited.

Challenge

A vendor technician, troubleshooting a similar machine at a different customer site, accidentally connected to the plant's network using credentials that had never been deactivated after the original support contract ended, and briefly pushed an unintended configuration change. No safety incident occurred, but the near-miss made clear that nobody in the organization could produce a current list of who had standing access to production systems.

Approach

The plant inventoried every vendor account with network access, matched each to an active support contract, and removed everything that could not be justified. Standing VPN accounts were replaced with a time-boxed access model: a vendor requests access tied to a specific maintenance ticket, access is granted for a defined window, all activity is logged, and access expires automatically. Vendor-facing systems were moved into their own zone rather than being reachable directly from the same segment as the production line's core control network, following IEC 62443 conduit logic.

Outcome

The plant could account for 100% of active third-party access at any point in time, replacing an informal trust relationship with an auditable process, and the access review became a standing quarterly task rather than a one-time cleanup.

Discussion

No replies yet. Start the discussion with a practical recommendation or implementation lesson.