The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have published a fact sheet titled "Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators." The document aims to help critical infrastructure entities reduce risk and minimize vulnerabilities when engaging with external industrial control system integrators.
Industrial control systems (ICS) are umbrella terms covering integrated networks of hardware and software designed to monitor and automate physical processes, including SCADA systems and programmable logic controllers. Third-party integrators provide services ranging from control system design and installation to operational data analysis, device support, and daily operational control.
The fact sheet warns that granting third-party integrators high levels of access to industrial processes can expose owners and operators to malicious cyber actors. Not adopting the principle of least privilege (PoLP) within operational technology (OT) environments may provide sensitive access pathways that actors can exploit to cause disruptive and destructive effects to equipment and critical functions.
Examples of risk include the inadvertent introduction of security issues when third-parties expose systems not pre-configured to the customer's security requirements. Supply chain risks arise if integrators and owners do not enforce clear requirements for the secure procurement and handling of system components. Additionally, third-party integrators operating data outside the United States may be subject to different data storage and management laws that do not meet U.S. critical infrastructure security needs.
According to FBI technical analysis, between March and April 2025, malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company. This company offered services including system integration, engineering consulting, and SCADA programming for industrial customers, including power utilities and transportation entities. While on the network, threat actors searched terms including "customers" and "SCADA," and created nine .zip files consisting of approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details, and other schematics. Malicious cyber actors could leverage the exfiltrated information to later conduct disruptive attacks against operational environments and disrupt critical services.
The agencies recommend that critical infrastructure owners and operators make risk-informed decisions when considering third-party integrators, guided by a robust understanding of organizational risks. Organizations should routinely conduct risk assessments to evaluate contracts involving access to industrial systems, determining impacts to data autonomy and process controls. Risk assessments should address hardware and software supply chain vulnerabilities, as well as IT and OT security of devices and associated networks. When considering foreign-owned integrators, geopolitical considerations should be included, such as how the critical infrastructure entity may be targeted based on the geopolitical climate.
Questions organizations should consider in their risk assessments include what organizational data the integrator stores or has access to, whether the integrator has network segmentation and monitoring capabilities, and if access can be revoked promptly upon contract termination.