The CISA and the FBI warned critical infrastructure operators about cybersecurity and supply chain risks associated with third-party industrial control system (ICS) integrators, urging organizations to limit access to operational environments and apply the principle of least privilege.
The agencies pointed to a 2025 incident in which foreign cyber actors compromised a U.S. industrial automation solutions company serving power utilities and transportation entities. The attackers searched for customer and SCADA information and created nine ZIP files containing approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details and schematics.
CISA and the FBI recommend that operators secure and monitor third-party remote access, minimize internet exposure, inventory hardware and software supplied by integrators, include cybersecurity and supply chain requirements in contracts, and maintain offline backups and manual operating capabilities.
Denis Calderone, CTO, Suzu Labs:
“The ugly side of the outsourced ICS model is the amount of trust that goes along with it. Integrators are a vital part of this ecosystem, especially for smaller operators that could never staff all of that engineering expertise themselves. The integrator needs the keys to the castle. They will be responsible for maintaining network diagrams, device configurations and SCADA details while maintaining a privileged path into the operational environment. CISA and the FBI have now documented exactly why this can be a problem and how this extension of trust directly alters the risk profile of the operator.
“The FBI has not said whether this company was selected because of its role as an integrator, but the post-compromise activity strongly suggests the actors knew what they were after. They searched specifically for ‘customers’ and ‘SCADA’ and staged roughly 800 files of device details and schematics. That is targeted intelligence collection against a company that holds a map of multiple critical infrastructure environments in one place. We have been concerned about how third-party integrators implement operational security for decades. As a professional penetration tester for more than 25 years, I have repeatedly seen integrators or all sorts (ICS, building security systems, environmental controls systems, etc) ignore basic security standards while the client fails to notice because, after all, they outsourced that headache. The more than 100 water systems compromised across the US since July illustrate the consequences of the same kinds of implementation failures. Weak or default passwords, architectures designed without meaningful isolation, little or no monitoring across ICS and SCADA networks, and PLCs placed directly on the internet where anyone can find and attack them. The fact that the integrator became the target itself is of no surprise to me.
“The way to manage this relationship is through the contract and then through audit. Put least privilege, named accounts, unique credentials, MFA, data location and retention, patching, incident notification, access termination and a right to audit into the agreement. Then verify those obligations in the environment. Inventory every component and connection the integrator supplied, inspect the remote-access logs, confirm default credentials are gone, make sure no controller is sitting on the public internet, and prove that your team can cut off the vendor, restore from a local offline backup and operate safely without them. If you cannot see, limit and terminate the integrator’s access, you have outsourced more than engineering.”
John Strand, Owner, Black Hills Information Security:
“Whenever I see stories like this, I keep coming back to the fundamentals. One of my mentors used to say, ‘Good security is nothing more than an inspired application of the fundamentals.’ And that still holds true.
“We talk about reviewing third-party access into systems, but that’s basic access control and authorization. These aren’t new security concepts. What stories like this continue to expose is just how often the fundamentals still aren’t implemented.
“For all the money we’ve spent and all the technology we’ve deployed, there are still legacy systems, legacy network connections, and old pathways into critical environments. We keep seeing the same lessons repeated because organizations haven’t fully addressed the lessons we should have learned years ago.
“The fundamentals are still fundamental. And unfortunately, we’re still failing at them.”
Critical infrastructure has been a target for threat actors forever. Now is the time to secure it. Because if not now, when?
Related
This entry was posted on September 24, 2026 at 4:53 pm and is filed under Commentary with tags CISA, FBI. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
The CISA, FBI warn critical infrastructure operators of third-party ICS risks
The CISA and the FBI warned critical infrastructure operators about cybersecurity and supply chain risks associated with third-party industrial control system (ICS) integrators, urging organizations to limit access to operational environments and apply the principle of least privilege.
The agencies pointed to a 2025 incident in which foreign cyber actors compromised a U.S. industrial automation solutions company serving power utilities and transportation entities. The attackers searched for customer and SCADA information and created nine ZIP files containing approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details and schematics.
CISA and the FBI recommend that operators secure and monitor third-party remote access, minimize internet exposure, inventory hardware and software supplied by integrators, include cybersecurity and supply chain requirements in contracts, and maintain offline backups and manual operating capabilities.
Denis Calderone, CTO, Suzu Labs:
“The ugly side of the outsourced ICS model is the amount of trust that goes along with it. Integrators are a vital part of this ecosystem, especially for smaller operators that could never staff all of that engineering expertise themselves. The integrator needs the keys to the castle. They will be responsible for maintaining network diagrams, device configurations and SCADA details while maintaining a privileged path into the operational environment. CISA and the FBI have now documented exactly why this can be a problem and how this extension of trust directly alters the risk profile of the operator.
“The FBI has not said whether this company was selected because of its role as an integrator, but the post-compromise activity strongly suggests the actors knew what they were after. They searched specifically for ‘customers’ and ‘SCADA’ and staged roughly 800 files of device details and schematics. That is targeted intelligence collection against a company that holds a map of multiple critical infrastructure environments in one place. We have been concerned about how third-party integrators implement operational security for decades. As a professional penetration tester for more than 25 years, I have repeatedly seen integrators or all sorts (ICS, building security systems, environmental controls systems, etc) ignore basic security standards while the client fails to notice because, after all, they outsourced that headache. The more than 100 water systems compromised across the US since July illustrate the consequences of the same kinds of implementation failures. Weak or default passwords, architectures designed without meaningful isolation, little or no monitoring across ICS and SCADA networks, and PLCs placed directly on the internet where anyone can find and attack them. The fact that the integrator became the target itself is of no surprise to me.
“The way to manage this relationship is through the contract and then through audit. Put least privilege, named accounts, unique credentials, MFA, data location and retention, patching, incident notification, access termination and a right to audit into the agreement. Then verify those obligations in the environment. Inventory every component and connection the integrator supplied, inspect the remote-access logs, confirm default credentials are gone, make sure no controller is sitting on the public internet, and prove that your team can cut off the vendor, restore from a local offline backup and operate safely without them. If you cannot see, limit and terminate the integrator’s access, you have outsourced more than engineering.”
John Strand, Owner, Black Hills Information Security:
“Whenever I see stories like this, I keep coming back to the fundamentals. One of my mentors used to say, ‘Good security is nothing more than an inspired application of the fundamentals.’ And that still holds true.
“We talk about reviewing third-party access into systems, but that’s basic access control and authorization. These aren’t new security concepts. What stories like this continue to expose is just how often the fundamentals still aren’t implemented.
“For all the money we’ve spent and all the technology we’ve deployed, there are still legacy systems, legacy network connections, and old pathways into critical environments. We keep seeing the same lessons repeated because organizations haven’t fully addressed the lessons we should have learned years ago.
“The fundamentals are still fundamental. And unfortunately, we’re still failing at them.”
Critical infrastructure has been a target for threat actors forever. Now is the time to secure it. Because if not now, when?
Share this:
Like this:
Related
This entry was posted on September 24, 2026 at 4:53 pm and is filed under Commentary with tags CISA, FBI. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.