news.mlab.sh
Back to the feed
threat-intel

Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators

High
Summary

The FBI and CISA have issued a fact sheet highlighting risks associated with using third-party industrial control system (ICS) integrators for critical infrastructure operators. The document emphasizes the need for careful contract negotiation, robust security practices, and proactive monitoring to mitigate the risk of malicious actors exploiting integrator access to compromise ICS environments. Recent activity shows a foreign cyber actor gained network access to a U.S. automation solutions company, exfiltrating sensitive data like SCADA information and schematics, potentially enabling future disruptive attacks.

The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have jointly released a fact sheet addressing the security considerations for critical infrastructure operators working with third-party industrial control system (ICS) integrators. ICS is a complex network of hardware and software designed to manage physical processes, including systems like Supervisory Control and Data Acquisition (SCADA) and Programmable Logic Controllers. Integrators provide services such as system design, installation, operational data analysis, and device support, but their access can introduce significant security vulnerabilities.

Critical infrastructure owners and operators must exercise caution when granting third-party integrators high levels of access to industrial processes, adhering to the principle of least privilege (PoLP). PoLP limits user, process, and system access to only what’s necessary, protecting against malicious actors seeking to compromise critical infrastructure. Failure to implement PoLP can expose systems to attacks and potentially lead to disruptive and destructive effects.

Recent analysis by the FBI indicates that between March and April 2025, a U.S. industrial automation solutions company, offering services to power utilities and transportation entities, was targeted by malicious foreign cyber actors. The actors gained network access and subsequently searched for terms like ‘customers’ and ‘SCADA,’ creating nine .zip files containing approximately 800 files, including customer SCADA information, ICS device details, and schematics. The intent was likely to exfiltrate this data for later use in disruptive attacks.

The fact sheet stresses the importance of thorough contract negotiation with integrators, including requirements for data storage locations, information protection agreements, remote access capabilities, cybersecurity program basics, change management policies, and processes for local engineering support. Organizations should also evaluate devices with external internet exposure and work with integrators to minimize this risk. Continuous monitoring and logging of remote access are crucial, utilizing on-demand remote access whenever possible. Furthermore, operators should request a complete inventory of software and hardware supplied by the integrator, along with documentation on how it connects to their infrastructure and how it will be updated. Finally, maintaining manual operation procedures and recovery capabilities is essential, accounting for the role of third parties in the environment.

Resources are provided, including guidance from CISA on asset inventories, SBOMs, and supply chain risk management, as well as the Communications Sector Coordinating Council (CSCC) and IT Sector Coordinating Council’s (SCC) Supplier, Products, and Services Threat Evaluation. Reporting suspicious cyber activity is strongly encouraged to the FBI or CISA via their 24/7 Operations Center. The document emphasizes that CISA and the authoring agencies do not endorse any commercial entity, product, company, or service.

Read the full article at CISA Advisories