Back Industrialcyber.Co CISA, FBI warn critical infrastructure operators of third-party ICS risks, urge least privilege ...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the federal Bureau of Investigation (FBI) issued guidance for critical infrastructure operators working with third-party industrial control system (ICS) integrators, warning that external providers can introduce cybersecurity and supply-chain risks into operational environments. The agencies said integrators can provide services including control system design, installation, operational data analysis, device support and service, and daily operational control. They urged operators to use the principle of least privilege when granting integrators access to industrial systems and to assess the security implications of giving third parties access to sensitive ICS environments.
The fact sheet points to a 2025 incident in which foreign cyber actors accessed a U.S. industrial automation solutions company that provided system integration, engineering consulting, and SCADA programming services to industrial customers, including power utilities and transportation entities. Between March and April 2025, while on the network, threat actors searched terms, including ‘customers’ and ‘SCADA,’ and created nine [dot]zip files consisting of approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details, and other schematics. Malicious cyber actors could leverage the exfiltrated information to later conduct disruptive attacks against operational environments and disrupt critical services.
“Critical infrastructure owners and operators should maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes, ensuring the principle of least privilege (PoLP) is applied,” it added. “PoLP within OT environments lends itself to granting users, processes, and systems only the minimum access necessary to perform their assigned tasks, and no more. PoLP is designed to protect owners and operators.”
Moreover, failure to adopt principles, such as PoLP, could expose owners and operators to malicious cyber actors seeking to compromise critical infrastructure , possibly providing sensitive access to pathways that actors can exploit to cause disruptive and destructive effects to equipment and critical functions.
CISA and the FBI recommend that operators assess what data integrators can access and where it is stored, secure and monitor remote access, inventory hardware and software supplied by integrators, minimize internet exposure, include cybersecurity and supply-chain requirements in contracts, and maintain offline backups and manual operating capabilities so critical processes can continue if an integrator is compromised.
Critical infrastructure owners and operators should make risk-informed decisions when considering introducing third-party integrators into their networks and operations, guided by a robust understanding of the organizational risks posed by providing sensitive access to their systems.
Organizations should routinely conduct risk assessments to evaluate contracts that involve access to industrial systems, to determine impacts to the organization’s data autonomy and process controls. Risk assessments should address hardware and software supply chain vulnerabilities introduced by integrator equipment, as well as the IT and OT security of these devices and their associated networks.
When considering implementing foreign-owned integrators, critical infrastructure owners and operators should also include geopolitical considerations in their risk assessments, such as how the critical infrastructure entity may be directly or indirectly targeted based on the geopolitical climate.
The CISA-FBI fact sheet called upon critical infrastructure owners and operators to consider what organizational data a third-party ICS integrator stores or can access when assessing risks to operational systems. Network designs, device specifications, logs and other information critical infrastructure systems can provide useful intelligence to malicious cyber actors. Organizations should therefore assess the potential for a malicious cyber actor to obtain such information through an integrator’s network when determining the risks associated with allowing an integrator to store or access it.
Organizations should also assess where the data is stored, particularly when an integrator is foreign-owned. If utility data is stored outside the United States, the laws of the country where the data is located may govern that information, including when the integrator operates as a U.S. subsidiary.
Remote access for operational support is another consideration. When an integrator has remote access to an organization’s ICS network, a malicious cyber actor who compromises the integrator’s network could potentially use that access to pivot into the utility’s network and gain control of its systems. Organizations should therefore evaluate the security of remote connections and the risks posed by these potential access points.
Critical infrastructure owners and operators should also determine whether they can operate independently if an integrator is compromised. Redundancies and the ability to recover systems and continue operations without an integrator, particularly for operationally critical processes, can reduce risk following a compromise. Operators should maintain secure, offline backups of all software required to operate equipment to support system recovery.
The authoring agencies recommend that critical infrastructure owners and operators include cybersecurity and supply chain cybersecurity requirements in contracts and service agreements with third-party ICS integrators . These agreements should address data storage locations, information protection requirements, and safeguards for ICS data and design documentation. They should also specify remote access capabilities, the basics of the integrator’s cybersecurity program, change and patch management policies, and measures used to secure deployed components, such as changing default passwords and disabling unused ports.
Agreements should identify authorized personnel who can access systems and establish processes that enable local engineering support when necessary while limiting the level of integrator intervention required.
Organizations should also evaluate devices with external internet exposure and work with integrators to identify where those devices are hosted. Where possible, organizations should minimize exposure by disconnecting devices from the public-facing internet. Remote access should be monitored and logged, with integrators required to access equipment through routes that organizations can monitor. Where possible, organizations should use on-demand remote access so that operators must proactively authorize remote connections.
Critical infrastructure owners and operators should request an inventory of all software and hardware supplied by the integrator, along with documentation describing how those components connect to the organization’s infrastructure and how they will be updated. Organizations should also practice procedures for manual operations and maintain the capabilities needed to operate systems manually, while accounting for the role of third parties in the environment and in recovery procedures.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
