CISA and FBI Release Fact Sheet to Help Critical Infrastructure Organizations Working With Third-Party ICS Integrators Reduce Risk

09/23/2026 2:00 PM EDT

Banner image for the Cybersecurity & Infrastructure Security Agency featuring the agency's logo and a digital globe with network connections.

Today, the Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) released a fact sheet, Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators, to help critical infrastructure (CI) organizations work with their third-party industrial control systems (ICS) integrators to establish secure practices and frameworks that protect the operational environment.

ICS is an umbrella term for the network of hardware and software used to monitor and automate physical processes and includes specialized control systems and devices like supervisory control and data acquisition (SCADA) systems and programmable logic controllers (PLCs). Third-party ICS integrators provide various services that support CI organizations, such as design, installation, operational data analysis, device support and services, and daily operational control. CI owners and operators should apply the principle of least privilege within their operational environments to help ensure integrators can complete their assigned tasks while reducing the risk of threat actors exploiting third-party access to compromise equipment and critical functions.

Key Recommendations:

  • Prepare contracts and service agreements that include cybersecurity and supply chain cybersecurity with requirements on key areas like data storage, remote access, patch policies, authorized personnel lists, and engineering controls to limit integrator lock-in.
  • Evaluate devices with external internet exposure and work with integrators to understand and minimize exposure by disconnecting devices from public-facing internet (see CISA’s Internet Exposure Reduction Guidance).
  • Ensure integrators access equipment through routes the organization is able to monitor.
  • Request an inventory of all software and hardware supplied by the integrator, including documentation describing how it connects to infrastructure and how it will be updated.
  • Practice procedures and maintain capabilities for manual operations, keeping in mind, and accounting for, where third parties fit into the environment and recovery procedures.

Read the fact sheet to learn more about how to work with third-party integrators to reduce risk in shared operational environments.


Discover more from #News247WorldPress

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading