Vendor remote access is one of the most common paths into an otherwise well-segmented OT environment. Before granting it, work through these questions.

Is the access time-bound?

Access should be enabled for the duration of approved work only, not left standing indefinitely.

Is it scoped, not flat?

The vendor should reach only the specific systems their work requires -- not a flat VPN into the entire OT network.

Is monitoring/support access separated from engineering-change access?

A vendor who only needs to view diagnostic data should not share the same access path as one authorized to push firmware or configuration changes.

Is MFA enforced, independent of the vendor's own systems?

Do not rely solely on the vendor's internal security posture -- enforce your own authentication requirements on the connection into your environment.

Is the session logged and reviewed?

Every vendor session should be logged in a system you control, and reviewed -- not just trusted because the vendor is known and has worked with you before.

Is there a documented offboarding trigger?

Access should be automatically revoked when a contract ends, a project closes, or a vendor employee changes role -- not left active until someone happens to notice.