All Case Studies
For over three years, Merck has centrally managed the remote access of external service providers through VISULOX — secure, auditable, and without VPN for third parties.

Management Summary
Merck has used VISULOX as its central platform for secure remote access by external service providers for more than three years. All third-party access runs controlled, logged, and auditable through a single point.
Merck KGaA
erreicht mit
Visulox
+3
years of VISULOX in production
100%
of external access centrally controlled and logged
+15
external service provider companies securely connected
Secure access to IT infrastructures can be presented very transparently. The system operates stably, even with over 1000 users. Our implementation of ISO 27001 is significantly supported, especially for large infrastructures.
Challenge
External service providers and suppliers regularly need access to internal systems — for maintenance, support, and operations. Conventional VPN access for third parties is complex to manage, difficult to audit, and increases the attack surface. Merck needed a central solution that makes external access secure, controlled, and audit-ready.
Solution
External service providers and suppliers regularly need access to internal systems — for maintenance, support, and operations. Conventional VPN access for third parties is complex to manage, difficult to audit, and increases the attack surface. Merck needed a central solution that makes external access secure, controlled, and audit-ready.
Merck KGaA, one of the world's oldest science and technology companies, works with a large number of external service providers, suppliers, and system vendors who regularly need access to internal systems — for maintenance, support, configuration, and operations. For more than three years, Merck has routed all such external access centrally through VISULOX.
In the pharmaceutical industry, remote access is not merely a technical issue — it is a regulatory one. Anyone with access to systems touching quality-relevant or GxP-regulated processes must be able to demonstrate at any time who did what and when. Requirements from GMP/GxP, data integrity standards under ALCOA+, and IT security standards such as ISO 27001 demand complete traceability, clear access control, and full logging — especially when third parties are involved.Conventional VPN access for external partners reaches its limits here: it grants broad network access, is difficult to restrict, and provides little in the way of reliable audit trails at the session level. In a regulated environment, this represents avoidable risk.
Visulox consolidates all external access at a single, controlled point. Service providers receive no direct network access — they work within clearly defined, monitored sessions with precisely the permissions required for the task at hand. Every activity is logged, can be observed in real time if needed, and is fully auditable after the fact.This enables Merck to meet key requirements for third-party access in a regulated environment: minimized attack surface, continuous access control based on the least-privilege principle, and an audit-ready record of every external session. The solution has been stable in production for more than three years and has become a fixed component of Merck's access strategy for external partners.
About
Merck KGaA is a leading science and technology company headquartered in Darmstadt with a history of more than 350 years. Across Healthcare, Life Science, and Electronics, the company develops solutions ranging from medicines and therapies to laboratory products and materials for the semiconductor and display industries. With approximately 60,000 employees in more than 60 countries, Merck is one of the most storied and innovative companies in its field.
Inustry
Healthcare & Pharma
Headquarters
Darmstadt
Website
https://www.merckgroup.com
Table of Contents
Speak with Our Experts
We look forward to hearing about your challenges.
Share:
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.