Secrets Management & Key Vault Infrastructure3 min readUpdated September 2026

Secrets Management Where the Shop Floor Meets the Cloud

A precision contract manufacturer's IT environment doesn't look like a software company's. Part of it lives above the shop floor, in ERP and cloud systems that behave like any other business's infrastructure, and part of it lives on the shop floor itself, where machines and control systems may not have reliable internet access at all. The Doppler versus Vault decision actually splits along that same line.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Why Manufacturing IT Looks Different From a SaaS Company's

A software company assumes every system can reach the internet whenever it needs to. A manufacturer often can't make that assumption for the equipment actually running production, because plant networks are sometimes deliberately isolated from the internet for reliability and safety reasons, not just security. A cloud-only secrets tool simply can't reach systems that were built to stay disconnected.

The Case for Vault When Part of Your Network Can't Reach the Internet

Vault can run entirely on-premises, on hardware inside your own network, with no dependency on an external service being reachable. For credentials tied to PLCs, SCADA systems, or manufacturing execution software running on an isolated network segment, that self-hosted option is the only one that fits the constraint at all.

The Case for Doppler for Everything That Sits Above the Shop Floor

For your ERP system, quality management software, and any cloud-hosted business application, none of which need to run air-gapped, Doppler's hosted simplicity removes the operational burden of running infrastructure just to manage secrets. There's no reason to extend the shop floor's isolation requirements to systems that were never isolated to begin with.

Where the Line Between OT and IT Actually Falls

The dividing line usually isn't a single network switch, it's wherever your plant's operational technology segment ends and your general business IT begins. Draw that line explicitly with whoever manages plant network segmentation before deciding which secrets tool covers which side, rather than assuming the boundary matches an org chart.

A Practical Split for a Manufacturer With Both

Run a self-hosted Vault instance scoped to the operational technology segment, and use Doppler for the business systems that already assume internet connectivity. Keep the two environments' credentials fully separate, so a compromise on one side of the OT and IT boundary can't be used to reach the other.

Split credentials along the boundary between plant and business systems:

  • Put credentials for PLCs, SCADA and manufacturing execution software in a self-hosted Vault reachable from the isolated plant segment.
  • Put ERP, quality management and other cloud business application credentials in a hosted tool such as Doppler.
  • Draw the line between operational technology and business IT explicitly with whoever manages plant network segmentation.
  • Keep the two environments' credentials fully separate, so a compromise on one side can't be used to reach the other.
  • Change every default credential, including those on vendor remote support tunnels, before equipment enters production.

A Common Mistake: Assuming a Vendor's Remote Support Tunnel Is Already Secured

Equipment vendors frequently install a remote access tunnel for support and diagnostics, and it's easy to assume the vendor is responsible for securing it since they set it up. In practice, the credential controlling that tunnel is often left at whatever default the technician configured during installation, and nobody on the plant side ever revisits it once the equipment is running.

Treat every vendor-installed remote access path as your own credential to manage, not the vendor's. Confirm what credential controls it, change it from the installation default, and add it to the same inventory you keep for every other piece of shop floor equipment.

A Decision Rule for Where a Credential Belongs, On-Prem or Cloud

If a system needs to keep functioning during an internet outage, because production can't simply pause when connectivity drops, its credentials belong in an on-premises vault reachable from the same isolated segment. If a system already depends on internet connectivity to function at all, its credentials can safely live in a cloud-hosted tool without adding any new point of failure.

Apply this test to any system you're unsure about: would a lost internet connection stop this system from running regardless of where its credentials live? If yes, the credential's location doesn't change the outage, so keep it on-premises for consistency and to avoid depending on a connection the system itself doesn't need.

Keeping Two Plants' Credentials From Drifting Apart Over Time

A manufacturer running more than one facility tends to start with identical setups and drift apart within a year: one plant's team rotates a vendor credential after a scare, the other doesn't hear about it, and now the two sites are running on different versions of what was supposed to be the same access policy.

Keep a single source of truth for which credentials should exist at each site and when they were last rotated, even if the credentials themselves live in separate Doppler projects or Vault namespaces per plant. A shared checklist that both site leads review on the same schedule catches drift before an auditor, or an incident, catches it for you.

This matters most for the vendor and OEM credentials tied to shared equipment models across plants, where a compromise at one site is a real signal to check the identical machine at every other site right away.

Put the checklist itself in the same tool you use to track credentials, not a separate document that can go stale on its own schedule, so a review of one automatically surfaces the other.

Executive Capability Standard

What Good Looks Like

A precision manufacturer keeps shop floor credentials separate from office IT credentials, changes every machine's default password before it goes into production, and can rotate a credential without needing an internet connection on the plant floor.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Inventory every PLC, SCADA system, and piece of shop floor equipment still running a factory default credential.
2. Do Manually:Change default credentials by hand during scheduled maintenance windows and log the change on paper or a shared spreadsheet.
3. Delegate:Give plant IT ownership of shop floor credentials, separate from whoever manages office and ERP credentials.
4. Automate:Run a self-hosted Vault instance on-premises for any system that can't reliably reach the internet.
5. Buy:Segment the network so a shop floor credential compromise can't reach ERP or customer data even if the vault itself is breached.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

AWS

Relevant for the ERP and cloud-facing systems above the shop floor, even when the shop floor itself stays on-premises.

Visit AWS→

Frequently Asked Questions

Can a secrets vault run entirely on-premises for a plant with no reliable internet?

Yes, HashiCorp Vault can be deployed entirely inside your own network with no dependency on reaching the internet, which fits an isolated plant floor segment. A cloud-hosted tool like Doppler cannot serve that same isolated segment by design.

Should PLC and SCADA credentials be managed the same way as ERP credentials?

No. PLC and SCADA systems often sit on a deliberately isolated network and may have limited support for modern authentication methods, so they typically need a self-hosted vault reachable from that segment, while ERP and business systems can use a cloud-hosted tool without issue.

What's the risk of leaving machine credentials at factory default settings?

A default credential is publicly documented by the equipment manufacturer, so anyone who identifies the equipment model can look up the login. Changing every default credential before equipment goes into production removes one of the easiest paths an attacker could take into your operational network.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides