A modality vendor demands a standing remote-support path or voids support: how do you grant it, and what does an intruder inherit?
answer
- reachability when needed, not always
- terminate on a broker you own
- one destination, one port, one direction
- records show bytes moved, not content
- someone must open it at 3am
basics
~20 sGrant it brokered and time-boxed rather than standing: the vendor terminates on a broker you control, the path opens on request and expires by itself. A permanent permit is a doorway an intruder inherits into the segment holding your widest exceptions.
solid answer
~50 sStart by refusing the shape, not the requirement. The vendor needs reachability at some moments; what they ask for is reachability at all moments, and those are very different exposures. Terminate the vendor on a broker you own - a jump point or identity-aware proxy where their people authenticate against your directory, sessions are recorded and access is granted per request with an expiry - and let the device see only the broker. If a device must dial home instead, permit exactly one destination, one port and one direction, and deny everything else the device might originate. Two things to concede honestly. First, the session is usually encrypted, so your boundary records show that bytes moved between two endpoints for a duration, never what was done. Second, brokering has a real bill: someone has to be reachable to open the path, and the vendor's response-time clock runs while you do. That trade is what you are actually defending.
go deeper
Know that vendor remote support is a permitted path through your boundary like any other, that it should name one destination and one port, and that leaving it permanently open is a decision rather than a default.
Explain the difference between a standing permit and access opened per request with an expiry, and what each means for who authenticates the vendor engineer and whether anyone can reconstruct the session afterwards.
Design it: broker termination, narrow origination for dial-home devices, alerting on the flow's absence, and a clear statement of what your records prove - movement, volume and timing, not content.
Own the commercial half. Usage data, contract renewal and procurement terms are the levers that remove standing vendor paths; decide who accepts the residual risk while a path you cannot yet move stays open.
## Why this is the sharpest exception in the estate The unpatchable population already carries the widest permits you write, because the compensating control is the only control. Now the vendor requires a path in - for diagnostics, calibration, image transfer or licence checks - and threatens the support contract if they do not get it. That path terminates on a machine you may not patch, may not instrument and may not log in to. It is the single most valuable permit an adversary could inherit anywhere in the estate, and it is usually granted once at installation and never examined again. ## Standing versus brokered | Standing permit | Brokered access | | --- | --- | | Reachable at all hours, whether or not anyone is working | Opened on request, closed by an expiry | | Authentication happens at the vendor's end, under their controls | Authentication happens at your broker, against your directory, with your second factor | | Use is indistinguishable from misuse | Every session has a requester, a reason and a window | | Compromise of the vendor is compromise of your segment | Compromise of the vendor still faces your authentication | | No operational cost | Someone must be available to open it, against the vendor's clock | The design position to argue is that the vendor's requirement is reachability *when they need it*, and a contract clause written as always-on is a convenience, not a technical necessity. Most vendors will accept a broker if the alternative is a purchase decision; the leverage exists at renewal and at procurement, which is why the conversation belongs there rather than in a firewall ticket. ## If the device must dial home Some equipment reverses the direction: it originates a persistent outbound connection to the vendor and support arrives back through it. That is often better than an inbound doorway, because the connection is originated by the device rather than by anyone on the internet, but it needs the same discipline. Permit exactly one destination, one port and one direction, from that one address. Deny every other outbound flow the device could originate, including name resolution to anywhere other than your own resolvers, because an intruder on the device would otherwise have a general-purpose outbound channel handed to them. And record the flow, because the absence of the dial-home for three days is a genuine signal that something changed on a host you have no other view into. ## What you can and cannot prove afterwards Be precise here, because interviewers listen for over-claiming. Flow records for the session prove that bytes moved between two endpoints, in what volume, for how long, and nothing about the content. If the transport is encrypted, an on-path observer can typically see the destination name asked for in the handshake and the certificate presented, not the commands run or the files copied. Your broker is what closes that gap: session recording, an authenticated requester, and a start and end time you can correlate against a change to the device. Without the broker, the honest answer to *what did the vendor do on Tuesday* is that you cannot say. ## What an intruder inherits Work it through concretely. Someone who takes the vendor's own support infrastructure or an engineer's credentials arrives at your boundary with an authorised source, at a time nobody reviews, aimed at a machine that keeps no local record. With a standing permit they are already inside the clinical segment. With a broker they must pass your authentication and their session is recorded, which does not stop them but does mean you can answer what happened. This is the whole argument for the operational cost, and it is a supply-chain risk expressed as a firewall rule. ## The rollout order that actually works 1. Enumerate every existing vendor path, because there are always more than the register says. 2. Record what each one is used for and how often - many are used twice a year, which weakens the always-on argument considerably. 3. Stand up the broker and migrate the low-friction vendors first, so the pattern is proven before you argue with the difficult one. 4. Take the remaining standing permits to the contract owner with the usage data, and make the change a condition of the next renewal or purchase. 5. Keep the ones you cannot move, narrowed to one destination and one port, on an exception with an expiry and a named owner. ## The summary answer Grant the access, refuse the shape. Terminate the vendor on something you control, make the path exist only while it is being used, keep the device's own permitted originations narrow enough to be useless, accept that you are buying an on-call obligation, and be honest that boundary records show movement and not content.
- The vendor refuses the broker and cites the support contract. What is your next move?Move it out of engineering and into commercial. Collect the usage data - most support paths are used a handful of times a year - and take the standing permit to the contract owner as a risk they are accepting on the vendor's behalf. Make broker termination a condition of the next renewal or purchase, and keep the interim permit narrowed, expiring and owned.
- Why can a device dialling out be preferable to an inbound support permit?Because the connection is originated by the device to one known destination, so there is no listening doorway for anyone on the internet to reach. It is only better if the outbound permit is a single destination and port with everything else denied; a dial-home plus general outbound access is worse than an inbound rule, since an intruder on the device inherits a free channel.
- What signal do you get from the dial-home flow itself?Its presence, timing and volume. A device that has phoned home every hour for two years and stops has changed in some way you cannot otherwise see, and a session at an unusual hour or with an unusual volume is worth a question to the vendor. It proves bytes moved, never what they were.
saying these in an interview costs you the question
- Grants a permanent inbound permit because the contract says so
- Claims boundary logs show what the vendor engineer did
- Lets the device originate general outbound traffic for dial-home
- Treats vendor authentication as equivalent to your own
- Ignores the on-call cost of opening access on request