The remote-maintenance link that was never properly closed is now industrial cyber’s softest target. This paper sets a doctrine for just-in-time, attested vendor access.