Remove obscure access vectors and back doors, especially modems; limit any remaining access. Where possible implement monitoring-only access enforced by data diodes (not software-enforced read-only); prohibit persistent vendor connections; require remote access to be operator-controlled, time-limited and procedurally similar to lock-out/tag-out; use the same paths for vendor and employee connections; and use two-factor authentication.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.