FBI, CISA Warn of Third-Party ICS Integrator Risks
Federal agencies urged critical infrastructure operators to limit outside access that could expose SCADA information or create routes into operational networks.
- By Danielle Naidu
- Sep 28, 2026
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) issued guidance on Sept. 23 about managing the cybersecurity risks created when outside industrial control system integrators receive access to critical infrastructure environments.
An FBI technical review cited in the guidance described a 2025 breach of a U.S. industrial automation provider serving customers that included power utilities and transportation organizations. During March and April, foreign actors searched its network for customer-related and supervisory control and data acquisition material. They then placed roughly 800 items into nine compressed archives. The contents included system diagrams, industrial device information and customer SCADA data, the agencies said.
The guidance recommended limiting each integrator to the access required for its work and examining the risks presented by supply chains and remote connections. Contracts should establish cybersecurity obligations. Operators were also advised to oversee and record remote sessions, document integrator-supplied technology, secure offline backups of software needed to operate equipment and prepare to run essential processes if an integrator becomes unavailable.
About the Author
Danielle Naidu is assistant editor for Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.