CISA and the FBI warn critical infrastructure operators that third-party ICS integrators can open privileged paths into OT. A March–April 2025 intrusion into a U.S. industrial automation firm staged ~800 customer SCADA and device files. New guidance stresses least privilege, contract controls, monitored on-demand remote access, and the ability to operate if the integrator is compromised.
Why integrators sit on the blast radius
Critical infrastructure owners who lean on third-party industrial control system (ICS) integrators for design, SCADA programming, device support, or day-to-day operational control may be opening a privileged path into their OT environments.
In a joint fact sheet released 23 September 2026, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) urge operators to treat those relationships as a first-class cyber and supply-chain risk, not a pure engineering convenience.
ICS covers the hardware and software that monitor and automate physical processes, including SCADA and programmable logic controllers.
Integrators often hold deep access: network designs, device inventories, remote support tunnels, and sometimes live operational control.
CISA and the FBI stress the principle of least privilege (PoLP) in OT: grant only the minimum access needed to do the job.
Skip that discipline, and a compromised integrator account can become a pathway for disruptive or destructive effects on equipment and critical functions.
Third-party work can also introduce systems that are not hardened to the customer’s security baseline, and foreign-owned or overseas-hosted integrators may store data under laws that do not meet U.S. critical infrastructure expectations.
The case that makes it concrete
FBI technical analysis cited in the fact sheet describes an intrusion between March and April 2025 against a U.S. industrial automation solutions company that served power utilities and transportation customers with system integration, engineering consulting, and SCADA programming.
Once inside, actors searched terms such as “customers” and “SCADA,” then staged roughly nine zip archives covering about 800 files, including customer SCADA information, ICS device details, and schematics, for presumed exfiltration.
That kind of haul is reconnaissance gold for later attacks on operational environments and critical services.
Four questions every operator should ask
Before, and while, working with an ICS integrator, CISA and the FBI recommend risk assessments that dig into:
- What organizational data does the integrator store or access? Designs, device specs, and logs are high-value to adversaries if the integrator’s network is breached.
- Where is the data stored? International storage can put utility data under foreign legal regimes, even when the vendor is a U.S. subsidiary.
- Does the integrator have remote access for operational support? A foothold on the integrator can pivot into the utility ICS network.
- Can the organization operate independently if the integrator is compromised? Redundancy, local engineering capability, and secure offline backups of required software cut downtime when the trusted third party falls.
Geopolitical exposure should sit in the same assessment when foreign-owned integrators are in play.
What to put in contracts and controls
The agencies recommend concrete steps to shrink the attack surface:
- Bake cybersecurity and supply-chain cybersecurity into service agreements, data location and protection, remote access rules, the integrator’s security program, change and patch management, hardening of deployed components (default passwords, unused ports), authorized personnel lists, and local engineering processes that limit always-on integrator intervention.
- Minimize public internet exposure of integrator-managed devices.
- Monitor and log remote access; prefer on-demand access that operators must explicitly allow.
- Demand a full hardware/software inventory plus documentation of how it connects and how it will be updated.
- Practice manual operations and recovery that assume the third party may be unavailable or untrusted.
Bottom line for industry
Integrators remain essential partners for complex OT estates, but they are also concentrated targets.
The CISA–FBI message is blunt: apply least privilege, write security into the contract, watch remote access, keep the ability to run without the vendor, and treat stolen SCADA and device schematics as precursors to real-world disruption.
Operators who wait until after a partner breach to ask these questions are already late.
Report suspicious cyber activity to your local FBI field office or IC3, or to CISA at [email protected] / 1-844-Say-CISA.
Source fact sheet: CISA, Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators.