CISA and FBI warn that an automation integrator can become a path into industrial systems
New guidance explains how operators should control integrator remote access, ICS documentation, contracts and the ability to operate independently.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 28 September 2026
- READING TIME
- 10 min read
- TOPIC
- Supply Chain Security
CISA and the FBI have issued joint guidance for critical-infrastructure operators that rely on external industrial-control-system integrators. The central lesson is straightforward: a company that designs, programs or remotely services automation may hold documentation and access paths leading to many facilities at once.
This is not an argument against integrators. Many operators need their specialist knowledge. Process owners must not, however, transfer control without understanding what data the supplier stores, where connections originate, who has access and whether the facility can continue after the supplier is compromised.
The incident behind the warning
According to FBI technical analysis, foreign malicious actors accessed the network of a US industrial-automation company between March and April 2025. The supplier provided system integration, engineering consulting and SCADA programming to industrial customers including power utilities and transport entities.
The attackers searched for terms such as “customers” and “SCADA.” They created nine ZIP archives containing approximately 800 files, apparently prepared for exfiltration. The material included customer SCADA information, ICS-device details and schematics.
The guidance does not say that these files were subsequently used to attack a particular facility. CISA and the FBI warn, however, that the information could support planning for disruptive attacks against operational environments and critical services.
Engineering documentation may be as valuable as a password
A network diagram, controller inventory, software versions, project names, communications configuration and process description help an attacker understand an environment before the first connection. They can reveal high-impact equipment, inform tool selection and support a credible pretext for an operator or service desk.
Supplier data classification should therefore extend beyond personal information. Engineering documents, PLC programme copies, HMI projects, configuration files and support logs need protection proportional to the consequences of misuse.
Data location also matters. An integrator may use its own cloud, ticketing system, backup and subcontractors. Removing a file from one portal does not mean it has disappeared from every location.
Four questions leadership should ask
CISA and the FBI frame the assessment around four practical areas.
What data does the integrator have? Inventory network designs, device specifications, logs, programme copies and process documentation. “Support access” is too vague an answer.
Where is the data stored? Location affects governing law, subcontractor access and response. The operator needs to know the hosting and backup locations, not merely the supplier’s headquarters.
Does the integrator have remote access? Establish the connection path, accounts, authentication, privilege scope and session logging. A standing connection “just in case” creates an unnecessary route into the process.
Can the facility operate without the integrator? Local capability, documentation, software copies and manual procedures are essential. A supplier should not be the only party able to restart equipment after an incident.
Remote access should be enabled on demand
The agencies recommend that integrators use routes the owner can monitor and that remote access be enabled on demand where possible, requiring the operator to allow it deliberately. An account should have minimum privilege, a defined lifetime and an identified user.
In practice, a service session should begin with an approved ticket, pass through a controlled access point, require strong authentication and leave an audit log. The access window should close when work ends. A shared “vendor” account makes it impossible to establish who performed a change.
Monitoring should cover more than sign-in. Operations performed, file transfers, programme changes, new accounts and connections to other segments all matter. Session recording needs legal and operational agreement but may provide an important audit trail for high-impact work.
What belongs in an integrator contract
The CISA and FBI guidance covers data-storage location, ICS-document protection, remote access, the supplier’s security programme, change and patch practices, security of deployed components and lists of authorised personnel.
A contract should also define:
- when and how an incident potentially affecting the customer must be reported;
- log preservation and forensic cooperation;
- deletion of data when support ends;
- subcontractor use;
- emergency access revocation without supplier assistance;
- delivery of current configurations, software copies and recovery instructions;
- a right to verify the most important requirements.
A generic clause saying that a supplier follows good practice does not establish whether a specific route to a controller is protected.
Inventory and manual operations are not optional extras
An operator should receive an inventory of hardware and software supplied by the integrator, together with connection and update documentation. Without it, the owner cannot tell which components face the internet, have reached end of support or need a patch.
The agencies also recommend secure offline copies of software required to operate equipment and rehearsed manual procedures. A project backup without a compatible tool version, licence and restoration instructions may be useless during an outage.
Manual operation may not preserve full capacity, but it should protect people, the environment and the most important service. Exercises must account for integrator unavailability, connectivity loss and uncertainty about whether the existing configuration can be trusted.
The issue extends beyond formally designated critical infrastructure
A factory, warehouse, building, treatment plant, laboratory or logistics centre may use the same supplier-access model even if it is not formally designated as critical infrastructure. A compromise can still produce physical or operational consequences.
A practical starting point is a joint review involving operations, automation engineering, IT, security, procurement and the business owner. Each group understands a different part of the dependency; none will see the complete path from contract to controller alone.
Source facts and Breachroad’s conclusions
The joint CISA and FBI fact sheet describes the integrator incident, nine archives containing approximately 800 files, and recommendations covering data, remote access, contracts, inventories, offline copies and manual operation. It describes exfiltration as presumed and does not confirm a later attack on customers.
The sample service-session flow, additional contract terms and review approach are Breachroad’s conclusions. See our wider guide to third-party risk management and incident-response planning. Organisations can rehearse integrator failure and local fallback through an incident-response tabletop exercise.


