How-to · OT vendor access

The vendor reaches the PLC.
Never the network.

Every plant depends on outsiders: the machine builder who tunes the line, the integrator who patches SCADA, the OEM on a support contract. The usual answer is a VPN into the control network, which is also the usual finding in incident reports. The alternative: a brokered, recorded, time-boxed session that terminates in the DMZ, so the vendor sees one system, not a network.

  • Purdue-model friendly
  • No inbound VPN
  • Runs air-gapped
Walkthrough

From VPN exception to governed vendor session.

Five steps that fit the reference architecture you already run: enterprise zone, industrial DMZ, control zone.

  1. 01

    Place the gateway in the industrial DMZ

    Monopam deploys self-hosted, next to the systems it protects. The gateway sits in the DMZ between the enterprise and control zones (level 3.5 in Purdue terms) and is the only path a vendor session takes. No inbound tunnel crosses into the control network, and nothing about the deployment requires an outbound SaaS dependency.

    Tip — OT-focused remote-access SaaS tools relay vendor sessions through a cloud the plant does not control. A self-hosted broker keeps the session, the recording, and the credentials on site, which is what air-gapped and regulated sites actually need.
  2. 02

    Model each vendor as an organization

    Create a vendor organization per supplier: authorized email domains so invitations cannot drift to personal mailboxes, IP restrictions for where their engineers may connect from, a contract window, and a default access duration for every account under it.

  3. 03

    Invite engineers through the approval flow

    A vendor engineer is invited by name, with an expiry and an MFA requirement. The invitation itself passes an approval before it is sent; enrollment is a passwordless magic link. No shared "maintenance" account, no password exchanged over email.

    Tip — The expiry is enforced in the PAM layer and mirrored to the identity layer. When the contract ends, both doors close on their own.
  4. 04

    Gate and record every connection

    Point the vendor at the one resource they maintain: the engineering workstation, the HMI, the jump host in front of the PLC subnet. Their connection can require just-in-time approval from your team before it starts, is always recorded, and notifies the sponsor the moment it opens.

    Tip — Recording covers the full session with keystroke transcription, which is the evidence NIS2 supply-chain measures and IEC 62443 remote-access requirements keep asking for.
  5. 05

    Let expiry and reviews do the cleanup

    Accounts disable themselves at expiry or after inactivity. Periodic access reviews put the remaining list in front of an approver; a rejection disables the account. The audit trail per vendor answers the who-what-when for every session of the engagement.

Ready for the full picture?

The complete walkthrough — with every screenshot, every flag, and version-specific notes — lives in our help center.

Explore vendor privileged access

Ready to start managing
identities the right way?

Spin up a fully-loaded trial tenant in under five minutes. No credit card. No sales gate.