-
FBI and CISA released a joint advisory that third-party industrial control system integrators can give attackers a way to access critical infrastructure.
-
A 2025 attack exposed about 800 files with customer SCADA data, device details and system plans.
-
The agencies advise that operators limit vendor access, watch remote connections and implement clear security controls in contracts.

New guidelines from the FBI and CISA address the security risks faced by the operators of critical infrastructure when collaborating with third-party providers of industrial control systems.
These guidelines came in a September 23 fact sheet, where the agencies provided tips on reducing security vulnerabilities related to these companies. Integrators can design, install and support industrial systems. Some also analyze data or help run systems each day.
That work can give vendors deep access to a customer’s network and equipment. If attackers compromise an integrator, they may use that access to reach its customers. The agencies cited a 2025 attack to show why operators should take this risk seriously.
The Importance of Third-Party Access
The Industrial Control System, ICS for short, enables businesses to manage and control their physical operations. ICS consists of SCADA systems and programmable logic controllers.
The third-party integrators are able to deal with numerous functions within the ICS environment. They may design systems, install equipment, provide support or manage operations. That work often requires access to sensitive networks and data.
The FBI and CISA say operators should follow the principle of least privilege. To put it simply, every user should have access to only what they need for their job.
Too much access provides opportunities for an attacker to penetrate deeper into a system in the event of a breach. An attacker, having access to an integrator, can gain access to a client’s industrial network.
The agencies also warn about supply chain risks. An integrator may bring hardware or software into an environment without meeting the customer’s security needs.
Data location can create another concern. Operators should know where vendors store sensitive information and who can access it. Foreign ownership or overseas storage may also create legal and security concerns.
A 2025 Attack Offers a Warning
The FBI cited an intrusion that took place between March and April 2025. Foreign cyber actors broke into a U.S. industrial automation company. The company provided system integration, engineering advice and SCADA programming for industrial customers.
Its customers included power utilities and transportation organizations. After entering the company’s network, the attackers searched for terms such as “customers” and “SCADA.” They then created nine ZIP files containing about 800 files. Those files included customer SCADA information, ICS device details and system schematics.
Neither the FBI nor CISA clarified whether there was any successful file theft. Nonetheless, the agencies warned that this information may enable attackers to plan future attacks on industrial systems.
The incident shows why operators should treat vendor networks as part of their wider security risk. The threat extends beyond third-party access, as the FBI recently warned that Iran-linked hackers continue targeting U.S. industrial control systems.
Check What Vendors Can Access
The agencies recommend regular risk reviews for contracts that give integrators access to industrial systems. Operators should first identify the data each vendor can access or store. Network plans, device details and system logs can give attackers valuable information after a vendor breach.
Organizations should also know where vendors keep that data. They should understand who can access it and how the vendor protects it. Remote access needs close attention as well. A hacker can use compromised credentials of a vendor to gain access to the customer’s system directly.
There’s one important question operators need to ask: what happens if the integrator becomes unavailable? Critical organizations should have a plan that allows essential operations to continue without the vendor.
Put Security Rules in Contracts
FBI and CISA also recommend putting cybersecurity requirements into vendor contracts. Contracts should explain how vendors must protect ICS data and system designs. They should also cover data storage, remote access, software updates and security changes.
Operators should know which vendor employees can access their systems. They should also require vendors to change default passwords and disable unused ports.
The agencies recommend asking vendors for a full list of the hardware and software they install. Operators should also receive documentation that explains how those products connect to their systems.
That information can help operators spot unwanted connections and respond faster when something goes wrong.
Keep Remote Access Under Control
The fact sheet puts special focus on remote connections. Operators should log and monitor vendor access whenever possible. They should also control how vendors connect to industrial networks.
For sensitive systems, organizations can use on-demand access. This approach lets an operator approve a vendor connection only when someone needs it.
The FBI and CISA also urge organizations to check devices that face the public internet. Operators should know which devices have internet access and remove exposure that they do not need.
Organizations should also keep secure offline backups of software and data needed to run critical equipment. The agencies recommend another basic safeguard: practice manual operations.
Critical sites should know how to keep essential processes running if a vendor loses access, suffers a cyberattack or cannot provide support.
Vendors Remain Part of the Risk
The new guidance does not create a new federal cybersecurity rule. Instead, it gives critical infrastructure operators practical steps for managing third-party risks.
The agencies’ message is simple. A trusted vendor can still become an entry point for an attacker. Operators need to know what each integrator can access, what information it holds, and how it connects to industrial systems.
They also need a plan for keeping essential operations running if that relationship suddenly breaks down. For critical infrastructure, vendor security is not separate from the organization’s own security. It forms part of the same risk picture.