How the Red Team Walks In Through the Front Door of OT
Why third-party OT access remains the most reliable attack path in OT Red Team assessment work
In December 2025, attackers compromised renewable energy plants, a combined heat and power facility, and a manufacturing company in Poland. CISA's February 10, 2026 advisory documented the path: initial access through internet-facing edge devices, pivot to HMIs and RTUs through default credentials, then wiper malware and firmware corruption. At least 30 wind, solar and heat generation sites lost operator visibility.
That is the same finding OT Red Teams report repeatedly. Third-party OT access is granted deliberately, governed lightly and often available to the wrong people on the same terms it was granted to the right ones.
The Door That Was Always Open
Third-party remote access into OT is standard operating reality. Cyolo and Takepoint Research's 2025 study found 88% of manufacturers allow remote third-party access into OT, and 60% grant access to more than 100 external parties. Claroty Team82, after analyzing more than 50,000 devices, found 55% of OT environments contain four or more remote access tools, and 22% run eight or more.
Many of those tools were not built for OT governance. Team82 reported 79% of organizations have more than two non-enterprise-grade remote access tools on OT network devices without session recording, role-based access control, auditing or MFA. As Cybersecurity Dive summarized, these are tools without the governance features required for the access they enable.
This is the architecture Red Teams encounter most often: a sprawl of access channels installed at different times by different teams, with uneven records, broad trust and weak controls.
What Three Independent Datasets Show About Third-Party Risk
Verizon's 2025 Data Breach Investigations Report, built from more than 22,000 incidents and 12,195 confirmed breaches, found third-party involvement in breaches doubled year over year, increasing from 15% to 30%. IBM's 2025 Cost of a Data Breach Report found supply chain compromises take the longest to detect and contain at 267 days because they hide inside legitimate access patterns.
The OT-specific picture is even sharper. The SANS 2025 ICS/OT Cybersecurity Survey found half of all ICS/OT incidents began with unauthorized external access, often through third-party remote maintenance, while only 13% of organizations implemented advanced controls such as session recording, ICS-aware authentication and real-time approvals.
Claroty Team82's March 2026 analysis of more than 200 attacks on cyber-physical systems in 2025 found 82% used remote access protocols against exposed internet-facing assets, with 66% involving HMI or SCADA compromise. Dragos's 8th Annual OT Cybersecurity Year in Review found 65% of assessed sites had insecure remote access conditions, including default credentials, unpatched VPNs and exposed RDP.
Three independent datasets, one repeated finding: third-party OT access remains the most reliable front door.
What the Red Team Actually Finds
CISA Advisory AA24-193A documented SILENTSHIELD Red Team findings where trust relationships with partner organizations, combined with weak credentials and network connectivity, enabled lateral movement into a partner domain controller. CISA's own lesson was direct: blindly allowing third-party network connectivity is a vulnerability by itself.
CISA Advisory AA24-326A opened with another recurring finding: initial access came through a web shell left by a third party's previous security assessment. In that case, the third party was a security vendor.
The same ground-truth conditions show up in OT Red Team assessment work: persistent vendor credentials that were never rotated, broad VPN reach intended as temporary troubleshooting access, vendor-installed tooling unknown to central security teams, shared integrator credentials across multiple sites, and access provisioned without expiration or monitoring.
None of these findings require zero-day exploitation. Red Teams typically use access exactly as it was configured to be used.
The Same Pattern in Every Named OT Incident
Mandiant testimony to the U.S. House Homeland Security Committee documented Colonial Pipeline's May 2021 intrusion starting with one inactive but still enabled VPN account without MFA, tied to previously exposed credentials. Six days of fuel disruption and $4.4 million in ransom followed one dormant account.
In November 2023, IRGC-affiliated CyberAv3ngers compromised Unitronics PLCs at the Municipal Water Authority of Aliquippa, Pennsylvania. CISA Advisory AA23-335A documented at least 75 devices compromised across multiple states, including at least 34 in water and wastewater. The operative technique was entering a vendor default password on an internet-exposed PLC.
Oldsmar in February 2021 reinforces the same architecture lesson even with uncertainty on actor attribution. Multiple computers shared one TeamViewer password, the remote access tool was internet exposed without a firewall, and systems were on unsupported operating systems. A Red Team would report those conditions as high-confidence findings in any controlled engagement.
This pattern links directly to Article 55 on visibility gaps and Article 66 on legacy constraints. It also aligns with the third-party shadow current from Shadow Current Blog 9.
The Vendor-Targeting Trend Red Teams Now Scope For
Dragos's 2026 OT Cybersecurity Report identified a trend now central to Red Team scoping: in 2025, ransomware affiliates increasingly targeted engineering firms, OT managed service providers, ICS equipment vendors and integrators.
The logic is simple. If attackers compromise the vendor, they can inherit credentialed paths into many customers simultaneously. The attacker does not need to force entry into each environment independently.
This trend shifts Red Team scenario design away from single-organization assumptions and toward cross-organization trust exploitation, where third-party OT access becomes the shared multiplier.
What Changes in a Well-Governed Environment
Across CISA guidance, NIST SP 800-82, IEC 62443, TSA Pipeline Security Directive 2021-02F and practitioner research from BeyondTrust, Cyolo and Claroty Team82, the control pattern is consistent: identity-based brokered access instead of broad VPN trust, MFA on every session, just-in-time provisioning with expiration, asset-scoped permissions, session recording, credential vaulting and centralized inventory of all remote access paths.
In environments with those controls, OT Red Team assessment findings change materially. Shared credentials are no longer available, dormant access cannot persist indefinitely, lateral movement from vendor sessions is constrained to scoped assets, and session recording raises evasion cost while improving containment evidence.
The strategic layer is addressed in vCISO series Article 77. The operations layer is addressed in CFC series Article 77. This article is where both layers meet testable engagement evidence.
Where This Goes Next
Vendor access is a structural finding, like the visibility and legacy findings before it. These are architecture-level conditions that shape attack paths before any exploit chain begins. Phase 4 of this series turns to operational reality: whether compliance posture matches actual security and whether incident response holds up when adversaries are already inside.
Audits ask whether a vendor access policy exists. The Red Team asks whether that policy governs what is actually in the network. Different questions produce different outcomes.
Learn more about the OT vCISO role in this executive brief: The Missing Leadership Layer in Industrial Cybersecurity.
Explore how this applies in live engagements: OT Red Team Assessment.
Third-party OT access is usually intentional.
Compromise is usually opportunistic.
Control maturity decides which one wins.
The fastest Red Team path is often not exploitation. It is credential hygiene failure at deployed edge and integrator-managed access points.
Sprawl multiplies blind spots. Different tools, credentials and ownership boundaries create pathways that central security teams cannot fully inventory.
Blindly trusted connectivity between organizations can collapse segmentation assumptions and extend compromise scope beyond one environment.
If access does not expire by design, old pathways become persistent attack surface. Red Teams test these pathways first because success probability is high.
When vendor credentials are reused across sites, one upstream compromise can grant attackers access to many customer environments at once.
CISA documented a practical attack path starting with edge exposure and ending in OT operational impact across multiple generation sites. This chain did not require highly exotic access techniques.
Default credentials and unmanaged remote trust carried the attacker from initial foothold to consequential OT disruption.
AA24-193A highlighted partner trust relationships plus weak credentials enabling lateral movement across organizational boundaries. AA24-326A showed initial access through third-party residue from a prior assessment.
Together these advisories mirror what OT Red Team assessment programs continue to validate in commercial and public-sector environments.
Well-governed environments reduce finding severity by design. Shared credentials are removed, broad network trust is replaced by asset-scoped approvals, and dormant sessions are eliminated through expiration.
Session recording and centralized inventory also convert incident response from uncertainty to evidence-driven containment.
Most programs still rely on remote access patterns that were operationally convenient but never designed for adversarial resilience. That is why third-party OT access remains the most repeated high-confidence finding.
Red Team movement typically follows existing trust: exposed edge, valid vendor credential, broad remote reach, lateral pivot into HMIs and control assets, then persistence or impact actions.
In governed architectures, access is brokered and time-bound, credentials are vaulted, sessions are scoped, and activity is recorded. Findings shift from critical exposure to bounded exceptions.
Third-party OT access is not rare edge risk. It is core operating reality and one of the most reliable Red Team entry paths.
Independent data from Verizon, IBM, SANS, Dragos and Claroty points to the same pattern: trusted remote access remains under-governed.
When access is identity-bound, scoped, expiring and monitored, Red Team findings become containable instead of systemic.
