Industrial Technology

The Weakest Link in Industrial Cybersecurity Is Not a Hacker. It Is the Contractor With Remote Access

Nearly all OT security incidents trace back to a compromise at the IT level, not an attack on the control system itself, and the breach data shows exactly why third-party access is where that gap gets exploited.

September 22, 2026·Industrial Technology
A technician in a hard hat and safety vest inspecting an HMI touchscreen on an industrial electrical control panel

Key Takeaways

  • 96% of OT security incidents start with a compromise at the IT or corporate-network level, not a direct attack on the control system itself.
  • 61% of manufacturing breaches now involve a third party, according to Verizon's 2026 Data Breach Investigations Report.
  • 54% of manufacturers do not vet a vendor's security posture before granting it access to plant systems.
  • 27% of OT security incidents trace to transient device risk, including USB drives and contractor laptops carried onto the plant floor.

Most industrial cybersecurity spending still assumes the attacker is on the outside, working to break in through a firewall or a phishing email. The breach data no longer supports that assumption. Across manufacturing, the majority of intrusions into operational technology now arrive through a door the plant itself opened: a vendor's laptop, a contractor's remote diagnostic session, an integrator's credentials left active long after the project ended. The control systems getting the AI and automation budget are, in most facilities, the same systems nobody has fully mapped for who else can reach them.

The Door Nobody Is Watching

Third-party remote access into operational technology has become routine faster than the governance around it has matured. Analysis published by OT Nexus, drawing on IIoT World's 2026 ICS/OT Cybersecurity Trends research, found that 96% of OT security incidents originate from an initial compromise at the IT or corporate-network level rather than a direct assault on the control system itself, and describes third-party and vendor access as "one of the most consistently under-governed entry points across industrial environments." A meaningful share of that exposure is physical rather than digital: the same analysis puts transient-device risk, including USB drives and contractor laptops carried onto the plant floor by outside personnel, at 27% of OT incidents.

None of that is a hypothetical exposure. It is the working condition of a typical plant floor today: equipment vendors, system integrators, maintenance contractors, and managed service providers moving in and out of facilities and networks that were never designed with that volume of outside connectivity in mind, governed inconsistently if at all once the initial project that justified the access has ended.

What the Breach Data Actually Shows

The consequence shows up directly in incident statistics. Analysis compiled by DeepStrike, drawing on Verizon's 2026 Data Breach Investigations Report and Ponemon Institute research from 2025, puts the third-party share of manufacturing breaches at 61%, up sharply from prior years. Ponemon's figures are more specific still: 42% of manufacturers reported experiencing a breach through third-party or vendor access, and 54% admitted they do not vet a vendor's security posture before granting it access to their systems.

Once an intrusion reaches the operational technology layer, the consequences escalate quickly. The same DeepStrike analysis, citing Dragos incident data, found that roughly a quarter of manufacturing ransomware incidents caused a full shutdown of the affected OT site, and that 75% disrupted operations to some degree. Sophos 2025 research put the share of attacked manufacturers who ultimately paid a ransom at 51%. None of this requires a sophisticated adversary. Verizon's data attributes 61% of manufacturing breaches to straightforward system intrusion rather than social engineering, which is consistent with attackers using access that was already granted rather than access they had to defeat.

Governance Has Not Kept Pace With Automation

The exposure is widening because the investment driving it shows no sign of slowing. Fortinet's research puts manufacturing's share of all cyberattacks globally at roughly one in four as of 2024, and finds that 56% of manufacturing firms are actively piloting smart manufacturing initiatives as a competitive strategy, meaning more connected sensors, more remote-accessible controllers, and more integration partners with a reason to reach into the network. Fortinet's 2026 State of Operational Technology and Cybersecurity Report, based on a global survey of more than 700 OT professionals, describes a genuinely mixed picture: security maturity, vendor consolidation, and C-suite oversight of OT risk are all improving, even as ransomware and third-party exposure persist.

The gap sitting underneath that mixed picture is ownership. Board-level attention rising in parallel with the incident rate is not the same as a named team accountable for every credential that reaches the control layer, and the IT-versus-OT split IIoT World's research points to is exactly what lets that gap persist: a corporate IT function that owns network security but not plant relationships, and a plant engineering function that owns contractor relationships but not network security. That is precisely the condition under which a diagnostic session outlives its purpose, a shared credential never gets revoked, and an integrator's remote connection sits open for a project that finished months ago.

Nothing in this data argues against automation, AI-augmented operations, or the vendor ecosystem that makes modern smart manufacturing possible. It argues that the access those relationships require has to be managed with the same discipline as the systems it connects to.

More in Industrial Technology

All Resources →