(TLP:CLEAR) FBI and CISA Highlight Risks of Third-Party ICS Integrator Access to Critical Infrastructure
Created: Thursday, September 24, 2026 - 12:32
Categories: Cybersecurity, Federal & State Resources, OT-ICS Security
Summary: Yesterday, the FBI and CISA released a joint fact sheet, “Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators”. It explains how owners and operators can reduce risk when they rely on outside firms to design, install, support, or operate industrial control systems. The agencies stress the importance of limiting integrator access to only what each task requires, and they warn that an integrator’s network can give malicious actors a pathway into customer operational environments, or detailed knowledge of them.
The fact sheet cites an FBI case in which foreign cyber actors accessed the network of a U.S. industrial automation company between March and April 2025. The company provided system integration, engineering consulting, and SCADA programming to industrial customers, including power utilities and transportation entities. While inside, the actors searched for terms such as “customers” and “SCADA.” They then staged roughly 800 files in nine compressed archives, apparently for exfiltration, including customer SCADA information, ICS device details, and schematics. The fact sheet also offers risk assessment questions for integrator relationships. Its recommendations include writing cybersecurity requirements into service agreements and monitoring integrator remote access.
Analyst Note: Many water and wastewater utilities, particularly small and mid-sized systems, depend on integrators for programmable logic controller (PLC) programming, SCADA upgrades, human-machine interface (HMI) configuration, and after-hours troubleshooting. In practice, the integrator often holds the utility’s network drawings, control logic, and credentials, and sometimes has standing remote access. A single integrator may support dozens of utilities in a region, so one compromise at that firm could expose many systems at once. The fact sheet does not identify water utilities among the affected customers. However, the stolen material (SCADA details and schematics) is the kind of reconnaissance data that could shorten an adversary’s path to disrupting treatment or distribution processes.
How equipment is deployed matters as much as who has access to it. In the recent widespread compromises of internet-exposed PLCs at water utilities, attackers got in through default passwords (or no passwords at all). Similar intrusions took place in the 2023 compromises of Unitronics PLCs at several water utilities. These incidents showed how devices left in their default configuration after installation can become an easy entry point.
WaterISAC encourages members to treat integrator relationships as part of their OT attack surface. Practical steps include:
- For each integrator, identify what utility data it holds (drawings, PLC and HMI project files, passwords), and confirm where that data is stored and how it is protected.
- Replace always-on vendor connections with on-demand remote access that utility staff enable, monitor, and disable after each session.
- Add security requirements to new and renewing contracts. These can cover default password changes, named authorized personnel, and patch and change management expectations.
- Keep offline copies of current PLC logic, HMI projects, and software licenses. Exercise manual operations so critical processes can continue if an integrator is unavailable or compromised.
These steps align with Fundamental 11, Secure the Supply Chain, in WaterISAC’s 12 Cybersecurity Fundamentals. WaterISAC encourages members who identify suspicious activity involving integrator or vendor access to report it to WaterISAC, as well as to the FBI or CISA.
Original Source: https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators
Additional Reading:
- Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products
- Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators
- Secure Connectivity Principles for Operational Technology (OT)
- WaterISAC 12 Cybersecurity Fundamentals for Water and Wastewater Utilities
Related WaterISAC PIRs: 6, 8, 9, 11, 12
