Vendor Support vs Third-Party Risk
Grant vendor remote access only through time-limited, fully logged, MFA-protected sessions with contractual cybersecurity obligations enforced.
CyberTRIZ analysis · Seveso contradiction CY012 · one of 8,235 worked contradictions published by CyberTRIZ.AI
Regulations
Business Context
Equipment manufacturers frequently require remote access to diagnose
problems, install updates, or support industrial systems. Every
third-party connection, however, introduces additional cybersecurity
risks.
The Contradiction
Greater vendor access improves maintenance support.
More restricted access improves cybersecurity.
Why It Exists
External organizations may not follow the same cybersecurity controls or
operational practices as the facility they support.
Direction
Provide vendor access through monitored, time-limited, and approved
remote sessions with strong authentication and complete activity
logging.