
Secomea’s “State of Industrial Remote Access 2026” research flags a governance gap in OT third-party access: in North America, 57% of organizations manage 6+ external vendors with OT remote access, but only 46% have full auditability of vendor sessions and just 23% review vendor credentials monthly or more. The report argues that stronger identity controls, just-in-time vendor access, centralized approvals, and rapid revocation are increasingly necessary as attacks increasingly abuse trusted remote sessions rather than perimeter weaknesses. It also notes 75%+ of organizations prefer or would adopt a standardized platform for managing vendor access versus fragmented VPN/tooling approaches.
The investable signal is not “more cyber spend,” but a shift in who gets paid for it: buyers are moving from connectivity tools to identity, workflow control, auditability, and revocation. That favors platform vendors that can sit in the approval chain and integrate with enterprise IAM/PAM stacks, while compressing the opportunity for fragmented VPN-style products and niche OT point solutions. Over 6-18 months, this should be a relative tailwind for larger software names with cross-domain security credibility, not a near-term revenue catalyst for any one vendor.
The main risk is that this remains a governance story rather than a budget unlock. Industrial customers often acknowledge the problem for 2-3 quarters before converting it into purchase orders, and CapEx pressure can still delay rollouts if production teams view controls as an operational friction cost. The clearest falsifier is a lack of procurement evidence in upcoming earnings cycles: if OT-security mentions do not turn into backlog, ARR, or “security and compliance” budget growth by the next two reporting quarters, the theme is probably more narrative than cash-flow accretive.
Contrarian view: the market may be underestimating how much of this spend migrates to the CIO/CISO budget from the plant floor, which structurally helps software platforms with enterprise distribution. IT (Gartner) is only a marginal beneficiary via advisory/research demand and is not the best expression of the theme. The cleaner read-through is to watch for industrial-security attachments in cybersecurity platforms rather than chase the private-vendor press release itself.
AI-powered research, real-time alerts, and portfolio analytics for institutional investors.
Request TrialOverall Sentiment
neutral
Sentiment Score
-0.10
Ticker Sentiment