Direct Answer: Treat Utility Vendor Access as Managed Operational Risk

Organizations should govern utility vendor access through a documented, risk-based system that controls who can connect, what they can access, how their privileges are approved, and when access ends. A contractor may need temporary visibility into a building-management system, water facility, power distribution equipment, or workplace network, but “temporary” access should not mean indefinite, unmonitored privilege. The practical standard is to treat every vendor connection as an identity, an entitlement, a set of permitted actions, and an accountable business purpose. IBM’s discussion of internet-exposed operational technology and Recorded Future’s reporting on vulnerability activity both support a simple conclusion: ordinary IT controls cannot safely be applied by assumption to systems whose availability and technical behavior may affect physical operations.

Also worth reading: How Do Organizations Choose Vendor Compliance Software for Facilities and Workplace Teams? · Contractor Access Compliance: How Should Organizations Control External Partner Access Without Slowing Operations? · What Is the Best Utility Software RFP Checklist for Vendor Operations?

A mature program joins identity and access management, third-party risk management, procurement, cybersecurity, facilities operations, and incident response. It does not require every utility interaction to pass through a new expensive platform, particularly when an organization operates only a handful of buildings. Instead, it requires consistent evidence about vendor accounts, remote-access paths, privileged sessions, shared credentials, software installation rights, support contracts, and emergency access. As of 27 September 2026, the central question is not whether vendors are trusted; it is whether trust has been translated into specific permissions that can be reviewed and revoked.

How Utility Vendor Access Governance Works

The process begins with an inventory of systems and suppliers that have any technical reach into the utility environment. That inventory can include electricity, water, HVAC, elevators, access control, fire systems, building automation, substations, fuel systems, and telecom services. For each supplier, the owner should record a unique user or identity provider connection, the systems reached, the business purpose, the authentication method, the privilege level, the approver, the expiration date, and the monitoring arrangement. FERC Order No. 919 and the discussion around virtualization in the Critical Infrastructure Protection environment reinforce the need to understand dependencies and compliance consequences when operational technology is connected to virtualized or cloud services.

Access should ordinarily follow least privilege, separation of duties, time limits, and verified business justification. A vendor repairing an air-handling unit may need remote access for 30 minutes, while a firmware specialist may need supervised access to a controller for a scheduled four-hour maintenance window. The appropriate control differs because the action, system, and consequences differ; governance is therefore not the application of one blanket password rule. Organizations should also distinguish ordinary support from emergency support, because an emergency path that bypasses approval and logging can become permanent if it is not tested and retired after the incident.

Shared administrator accounts, personally owned webmail addresses, permanent VPN users, and undocumented dial-in numbers defeat much of this structure. Named identities, multifactor authentication, approval workflows, session recording, and automatic expiry reduce ambiguity, although they do not remove all risk. FERC Order No. 919 also illustrates why virtualization matters: a hosted service may change technical boundaries and compliance responsibilities without changing the fact that a utility provider still depends on the vendor. Governance should identify the contractual and operational owner of each dependency before access is granted.

A Practical Governance Workflow for Facilities and Workplace Teams

Start by classifying access according to potential operational effect. A read-only request that displays equipment status is different from a request to alter set points, update firmware, create accounts, or stop service. A useful classification can use three levels: standard remote support, privileged maintenance, and emergency or safety-critical access. Each level can carry different approval, authentication, monitoring, and time-limit requirements. This lets teams apply stronger controls to the small number of sessions that can disrupt physical operations while avoiding unnecessary friction for routine status checks.

The next step is to create a request and approval record containing the supplier’s company, named technician, ticket or work-order number, target system, required privilege, start time, expected end time, and internal sponsor. The sponsor should be accountable for confirming that the work is necessary, while a system owner should confirm that the requested permissions are technically appropriate. A cybersecurity reviewer need not approve every low-risk password reset, but privileged or production access should receive an independent technical check. The record should also state whether the work affects safety, privacy, service continuity, regulatory obligations, or another facility served by the connection.

During the session, the system should authenticate the individual rather than relying solely on a supplier-controlled shared account. Where feasible, use multifactor authentication, a named VPN identity, a just-in-time elevation, network segmentation, and a recording or command-log trail. If a supplier cannot support named access, a defensible exception should document compensating controls, such as a supervised jump host, vendor-side session logs, short-lived credentials, and daily review. Access should expire automatically when the approved window ends; in practice, a 24-hour grant for a two-hour repair is not a precise temporary entitlement, and a grant that can be extended without a new decision should be treated as semi-permanent.

Governance Options and Platform Comparisons

Organizations can implement utility vendor access governance manually, through existing enterprise identity tools, or with a vendor-operations platform. Manual controls are understandable and inexpensive for small estates, but spreadsheets become unreliable when technicians, buildings, systems, and approvals multiply. Existing identity and privileged-access tools provide strong technical controls, yet they may not understand the facilities context, maintenance workflow, supplier contract, or physical consequence of a change. A vendor-operations platform can connect requests to buildings, systems, suppliers, approvals, documents, and monitoring, although that convenience does not replace integration with the organization’s identity, network, and endpoint systems.

FeatureManual register plus enterprise IAMDedicated vendor-operations workflowFully managed remote-access service
Typical fit1–5 buildings and a small supplier base5–100+ buildings or recurring supplier workHigh-risk or high-volume critical utility programs
Initial effortLow to moderateModerateModerate to high
Identity controlsStrong if integrated with enterprise IAMCan support named access, approvals, and expiryUsually includes hosted gateways or jump hosts
Facilities contextUsually stored manuallyNative links to sites, assets, tickets, and ownersDepends on service scope and integration
VisibilityRegister, email, and logs are separateCentral record from request through closureCentralized session and gateway telemetry
Approximate cost$0 incremental software, plus staff timeCommonly $10,000–$100,000+ per year, depending on scopeCommonly $30,000–$200,000+ per year, plus implementation
Main weaknessDrift, duplicate accounts, and missed expiryIntegration and process adoption costSupplier lock-in and limited asset customization
These prices are planning ranges rather than quotations, and actual cost can change with user count, sites, gateways, sensors, integrations, support requirements, and implementation effort. A small organization may begin with the manual register plus existing IAM, while a portfolio managing dozens of buildings and many contractors can justify a dedicated workflow. Fully managed access services can reduce the burden of operating gateways, but the organization must still decide who approves access, how the service fits its network architecture, and who remains responsible when a session has operational consequences.

Metrics, Review Cadence, and Evidence of Control

A governance program should produce evidence rather than merely announce a policy. Useful measures include the percentage of vendor identities tied to an approved business purpose, the percentage of active privileged accounts with named users and multifactor authentication, the number of overdue access reviews, and the median time between work completion and credential removal. Other useful figures are the percentage of emergency grants reviewed within one business day, the number of dormant vendor accounts, the count of shared accounts outside approved exceptions, and the percentage of supplier sessions associated with a valid ticket. Targets should reflect risk rather than an arbitrary universal percentage; for example, 100% expiry compliance may be appropriate for temporary production access, while 100% MFA may be difficult only where a specialist legacy device cannot support it and a documented compensating control exists.

Review privileged access at least quarterly and lower-risk access every six or twelve months, with additional review after contract renewal, personnel changes, site acquisition, or a material security event. High-risk accounts should be reviewed monthly by operations, and emergency credentials should be tested at defined intervals rather than being retained indefinitely “just in case.” A useful threshold is zero unowned administrative identities and zero production accounts without an expiry, although exceptions can exist if they are time-bound and approved. A target such as 95% of requests closed within 24 hours of completion is measurable, but it should not reward premature revocation before critical logs or work evidence have been captured.

Metrics should be paired with operational outcomes. Repeated emergency access, repeated account provisioning errors, or vendors requesting broader permissions than expected can indicate unclear contracts, inadequate asset records, or poor training. The cyber team should not own every finding alone; facilities owns operational necessity, procurement owns commercial terms, IT owns technical enforcement, and the supplier owns the behavior of its personnel. Quarterly governance meetings should examine exceptions and patterns as well as incidents, because recurring near misses are often cheaper to correct than a control failure.

Common Mistakes That Weaken the Program

The first common mistake is confusing a supplier contract with an access-control record. A contract can establish liability and confidentiality, but it rarely specifies the exact technician, system, command, and expiration needed for a maintenance session. The second is allowing a vendor’s preferred access method to become the organization’s permanent architecture. If a supplier insists on a shared account or an inbound tunnel, the internal owner should document the risk, test the connection, restrict its destination, and set a review date rather than silently accepting the dependency.

Another mistake is treating all vendor access as remote IT access. Operational technology can behave differently from ordinary information technology, and vendor expertise may be concentrated in a small number of people. Morgan Lewis’s analysis of virtualization in the CIP environment, and broader IBM and industrial-security reporting, point to the operational consequences of exposed or poorly governed OT. Organizations should not shut down a safety-related supplier access path without an approved alternative, but they should test remote support, local response procedures, spare parts, and escalation contacts before an emergency occurs.

A fourth error is treating the annual review as the control. If access is granted in January and not examined until December, the program detects drift slowly. Temporary credentials also fail when they are never linked to a work order or automatically revoked. Finally, buying a platform does not create governance: if facilities and procurement do not enter accurate asset and supplier information, and if IT does not enforce the resulting decisions, the system becomes another attractive database with stale data. The best control is the one that an operator can use during a real maintenance event without bypassing the process.

When Organizations Should Act and What It May Cost

Immediate action is warranted when a supplier has standing remote access to a production utility system, an account has no named owner, a password is shared, or an internet-facing management interface is not covered by monitoring. An organization should also act promptly after a supplier breach, a merger, a site transition, or a change from on-premises equipment to a hosted or virtualized service. A practical 30-day target is to identify the first 20 highest-risk connections, remove orphaned credentials, confirm multifactor authentication on privileged paths, and assign an owner and expiration date to every remaining account.

The next 60–90 days can cover the full supplier and site inventory, standardized request forms, named identities, ticketing, approvals, and session evidence. During days 90–180, organizations can introduce segmented access, just-in-time elevation, supplier attestations, quarterly reviews, emergency exercises, and reporting to leadership. These timelines are planning targets, not guarantees; a critical water or power environment may require faster containment, while a small office portfolio may need a lighter process. The research context includes concrete examples of utility dependence, including Bangladesh’s West Zone Power Distribution Company and the Phnom Penh Water Supply Authority’s reported 320,000 cubic meters per day in 2012, illustrating that utility operations can involve substantial physical and public-service obligations.

Pricing should be framed as risk reduction plus operating cost, not as a universal “security tax.” A small team may spend roughly $0 in additional software initially, although staff time for inventories, reviews, and testing is real. Mid-sized programs can face $10,000–$100,000+ annual platform costs, while managed gateway and privileged-access services can exceed $200,000 depending on scale and response requirements. Hardware, network changes, supplier fees, audits, and legal or contract work may add cost. The correct comparison is the expected reduction in unauthorized changes, downtime, investigation effort, and regulatory exposure against the cost of identifying and controlling the organization’s highest-risk dependencies.

A Balanced Governance Standard

Utility vendor access governance is not about blocking the people who maintain critical systems. It is about making their work authorized, time-bound, observable, and reversible while preserving a safe route for urgent response. The strongest programs distinguish risk categories, name individuals, connect access to a documented purpose, enforce multifactor authentication and segmentation where possible, review exceptions, and remove access promptly after work ends. They also recognize that identity, network, software, and contractual controls solve different problems; a named login does not protect a vulnerable controller, and a good contract does not prevent an over-privileged session.

For a B2B virtual-utility and workplace operations context, the most useful starting point is usually a small inventory of systems with real physical or operational influence, followed by controls for those systems rather than an indiscriminate rollout. By 27 September 2026, organizations should be able to answer four questions for every supplier connection: who has access, why do they have it, how is it monitored, and when will it be removed? If those answers are unavailable, the organization is not yet governing access; it is merely relying on trust. A measured program can improve over time, provided leadership treats the inventory and review cadence as operating responsibilities rather than one-time compliance projects.