FBI and CISA Warn Critical Infrastructure: Secure Your ICS Integrators
The **FBI** and **CISA** have issued a joint fact sheet urging critical infrastructure entities to bolster security when engaging third-party Industrial Control System (ICS) integrators. The warning highlights significant supply chain risks and potential vulnerabilities introduced by external access to sensitive operational technology (OT) environments, emphasizing the need for robust risk assessments and the strict application of the **principle of least privilege (PoLP)**.
The **Federal Bureau of Investigation (FBI)** and **Cybersecurity and Infrastructure Security Agency (CISA)** have released a critical advisory for owners and operators of vital infrastructure. The joint fact sheet underscores the inherent risks associated with integrating third-party Industrial Control System (ICS) integrators into operational environments and provides actionable recommendations to mitigate these threats.
ICS refers to the integrated hardware and software networks that monitor and automate physical processes, including **Supervisory Control and Data Acquisition (SCADA)** systems and **programmable logic controllers**. Third-party integrators offer a range of services, from system design and installation to operational data analysis and daily control.
### The Peril of Unchecked Access
The agencies stress the importance of caution when granting external parties high levels of access or control over industrial processes. They advocate for the rigorous application of the **principle of least privilege (PoLP)** within OT environments, ensuring users, processes, and systems are granted only the minimum access necessary to perform their assigned tasks.
Failing to adopt **PoLP** can expose critical infrastructure to malicious cyber actors. Such vulnerabilities could provide pathways for adversaries to compromise systems, leading to disruptive and destructive effects on equipment and essential functions.
### Real-World Exploitation: A Looming Threat
Integrating third-party ICS integrators, much like IT systems, can inadvertently introduce security gaps. Systems not pre-configured to a customer's specific security requirements, or reliance on integrators for system design without clear secure procurement mandates, pose significant supply chain risks.
The advisory highlights a concerning incident: between March and April 2025, foreign cyber actors infiltrated the network of a U.S. industrial automation solutions company. This company provided services to critical sectors, including power utilities and transportation. The attackers sought terms like "customers" and "SCADA," exfiltrating approximately 800 files, including customer **SCADA** information, ICS device details, and schematics. Such data could be weaponized for future disruptive attacks against operational environments.
### Strategic Risk Assessment is Key
Critical infrastructure owners and operators must make informed decisions when considering third-party integrators, guided by a comprehensive understanding of the risks associated with providing sensitive system access.
Routine risk assessments are crucial for evaluating contracts involving industrial system access, assessing impacts on data autonomy and process controls. These assessments should cover hardware and software supply chain vulnerabilities, as well as the IT and OT security of devices and networks. Geopolitical considerations should also be factored in when engaging foreign-owned integrators.
Key questions for risk assessments include:
* **What organizational data does the integrator store or access?** Consider the potential for malicious actors to access network designs, device specifications, and logs through the integrator's network.
* **Where is the data stored?** For foreign-owned integrators, understand if data is stored domestically or internationally, as foreign laws may apply even to U.S. subsidiaries.
* **Does the integrator have remote access for operational support?** Evaluate the security of remote connections, as a compromised integrator network could provide a pivot point into your critical systems.
* **Can the organization operate independently if the integrator is compromised?** Implement redundancies and maintain the ability to recover and operate without the integrator, especially for critical processes. Secure, offline backups of all necessary software are essential.
### Proactive Measures to Fortify Defenses
The **FBI** and **CISA** recommend the following steps to reduce risks associated with third-party ICS integrators:
* **Integrate cybersecurity and supply chain cybersecurity into contracts and service agreements.** Specify requirements for data storage, information protection, remote access capabilities, the integrator's cybersecurity program, change management, patch management, securing deployed components (e.g., changing default passwords, disabling unused ports), authorized personnel, and processes for local engineering support.
* **Evaluate devices with external internet exposure.** Work with integrators to understand device hosting and minimize public-facing internet exposure.
* **Monitor and log remote access.** Ensure integrators use monitored access routes. Prioritize on-demand remote access where operators must proactively grant permission.
* **Request a comprehensive inventory** of all software and hardware supplied by the integrator, including documentation on infrastructure connections and update procedures.
* **Practice manual operation procedures** and maintain capabilities for system recovery, accounting for third-party involvement in recovery processes.
### Essential Resources
For further guidance, owners and operators can refer to **CISA's** *Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators* and *2026 Minimum Elements for a Software Bill of Materials (SBOM)*. Additionally, the **Communications Sector Coordinating Council (CSCC)** and **IT Sector Coordinating Council (SCC)**'s *Supplier, Products, and Services Threat Evaluation* and **NIST's** *Cybersecurity Supply Chain Risk Management* provide valuable insights into managing supply chain risks.