Maintenance windows as an entry point: securing external vendor access with Illumio and Xage
Hardly any company gets by without external maintenance access today: the machine builder services its equipment remotely, the system integrator installs updates, the service provider checks the backups at night. This access is operationally indispensable. At the same time, it ranks among the biggest entry points for attacks. While internal systems are usually well monitored, a maintenance window often opens a door whose use no one controls in detail. Maintenance windows deserve the same scrutiny as any other access path.
With NIS2, this also becomes a compliance issue: the directive requires that third-party access, too, be documented, controlled, and limited to what is necessary. If you cannot say today which service provider accessed which system and when, you will run into a problem at the audit at the latest.
The situation in numbers
The current SANS report on ICS security shows how wide the gap between aspiration and reality is: around half of the recorded security incidents trace back to unauthorized external access. At the same time, only about 13 percent of companies use advanced controls such as session recording or time-limited access, and 31 percent do not even keep a central inventory of their remote access points. The most common attack path, of all things, is the one controlled least often.
What can go wrong with maintenance access
The basic problem with traditional remote maintenance: the external technician gets VPN access and ends up in a network that allows far more than the task requires. The consequences range from unpleasant to existential:
- Lateral movement: From the maintenance access point, other systems are reachable. A compromised service provider account then opens far more than the maintenance target.
- Production downtime: One wrong configuration in the wrong place paralyzes critical processes, whether deliberate or accidental.
- Data exfiltration: Sensitive production and customer data leaves the company unnoticed.
- Missing traceability: Without recordings, there is no way to establish who did what in a dispute. That becomes a problem for forensics, warranty claims, and NIS2 documentation.
The principle: Zero Trust for service providers, too
The answer is conceptually simple: external sessions are treated as untrusted by default. Access is granted only to the specific target system, for the time needed, and with the minimum necessary privileges. Every session is monitored and logged. For this to work in practice, two building blocks have to interlock: segmentation that limits the radius of movement, and an access layer that controls the door.
Building block 1: Zero Trust Segmentation with Illumio
Illumio starts where the greatest damage occurs: lateral movement. The platform first makes all data flows between systems visible: who talks to whom, and is that even necessary? On this basis, least-privilege rules are created down to the workload level, purely software-based and without rebuilding the network.
For the maintenance scenario, that means: even if a service provider's access is compromised, the attack ends at the segment. The maintenance target is reachable, the neighboring systems are not. The potential master key becomes a key for exactly one door.
Building block 2: identity-based access with Xage Security
Xage Security controls the door itself, especially in OT and industrial environments where traditional remote access tools reach their limits. Instead of a blanket VPN tunnel, Xage grants access based on identity: per person, per asset, per action, and if desired only for a defined time window, matched to the maintenance job.
On top of that comes what is often missing in the maintenance context: multi-factor authentication even for legacy systems that cannot handle MFA themselves, session brokering through a controlled access point, and complete recording of the sessions. That makes it verifiable after the fact who did what and when. NIS2 demands this traceability, and in a warranty dispute it is worth its weight in gold.
How we can help
As a managed security service provider and partner of Illumio and Xage Security, we bring both building blocks together, from analysis to managed service:
- Inventory: We catalog all remote access paths, including the forgotten vendor portals and agents that never pass through a VPN.
- Architecture & implementation: We design the segmentation and access architecture to fit the environment and implement it without putting running applications and systems at risk.
- Managed service around the clock: Our Network Operations Center monitors access and rules 24/7, detects deviations, and keeps the documentation current and audit-proof.
How we secure networks with Zero Trust Segmentation is shown on our page on microsegmentation .
If you want to dig deeper into OT remote access: in our post "Securing OT remote access: why VPN and MFA alone are not enough" we examined the ICS-specific controls in detail.
Conclusion
For a compact overview of the Illumio platform (Segmentation and Insights), see our Illumio page .
External maintenance access cannot be abolished, but it can be brought under control. If you limit the radius of movement through segmentation and grant access identity-based, time-limited, and recorded, you turn the biggest entry point into a controlled, documented process. The best time to do that is before the next maintenance window, not after the first incident.