FBI and CISA Warn Critical Infrastructure Operators About ICS Integrator Access

Security technician validating backup and recovery for an access control controller

The FBI and the Cybersecurity and Infrastructure Security Agency issued guidance on September 23 about cybersecurity risks created when third-party industrial control system integrators receive access to critical-infrastructure environments. The agencies urged operators to treat integrator connections as governed, monitored access paths rather than permanent trusted links.

A provider breach exposed customer information

According to the guidance summarized by Security Today, a 2025 breach of a US industrial automation provider affected an organization serving power and transportation customers. Foreign actors searched the provider network for customer and supervisory control and data acquisition material, then placed hundreds of items into compressed archives.

The episode illustrates how a compromise at one engineering or support company can create visibility into multiple operators. Drawings, device information and customer SCADA data can help attackers understand industrial environments even when they have not yet reached an operational network.

Access should be limited and observable

The agencies recommended limiting each integrator to the access required for its work, recording remote sessions and documenting supplied technology. Contracts should define cybersecurity obligations, while operators should maintain offline copies of software needed to run equipment and prepare for a provider becoming unavailable.

Organizations should also review dormant accounts, shared credentials, remote-access gateways and support pathways after projects end. These controls align supplier governance with technical segmentation and operational resilience. The warning is especially relevant to SectechMedia readers responsible for Industrial Safety & Monitoring, where maintenance access can cross the boundary between business systems and essential processes.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *