As reported by CISA in a joint fact sheet with the FBI published September 23, 2026, critical infrastructure operators are being urged to reassess the access and control they grant to third-party industrial control system (ICS) integrators. The advisory is concise but pointed: when integrators are handed broad access to SCADA systems, PLCs, and other OT assets without enforcing the principle of least privilege, they become an attractive pathway for malicious actors seeking to cause physical disruption.

Key Takeaway: As reported by CISA in a joint fact sheet with the FBI published September 23, 2026, critical infrastructure operators are being urged to reassess the access and control they grant to third-party industrial control system (ICS) integrators.

Shield53 views this guidance as overdue but welcome. For years, the operational technology sector has tolerated access models that would never pass scrutiny in enterprise IT environments. Integrators routinely receive persistent VPN credentials, shared administrator accounts, and standing access to safety instrumented systems — sometimes for months or years after a project concludes. The threat model has shifted faster than the contractual and technical controls governing these relationships.

Why This Matters Now

The convergence of IT and OT networks, accelerated by remote monitoring demands and digital transformation initiatives, has dramatically expanded the attack surface available through integrator pathways. Recent threat intelligence indicates that adversaries — including state-sponsored groups — are actively profiling managed service providers and integrators as a means of reaching hardened OT environments they cannot directly access. A single compromised integrator can become a pivot point into dozens of critical infrastructure operators.

Key Risk Factors Identified

Why This Matters Now
Persistent standing access: Integrators retain credentials long after project completion, creating dormant but exploitable pathways.
Shared and generic accounts: Many integrator teams use shared credentials, eliminating individual accountability and complicating incident attribution.
Inadequate network segmentation: Integrator access frequently bridges IT and OT zones without proper isolation, defeating defense-in-depth strategies.
Unmonitored remote sessions: Remote access sessions for maintenance and troubleshooting often go unaudited, allowing malicious activity to blend with legitimate work.
The most dangerous vulnerability in your OT environment may not be a CVE — it may be the contractor who still has domain admin on your SCADA layer from a project that ended in 2024.

Who Is Most Exposed

Water utilities, energy generation and distribution, food manufacturing, and transportation systems tend to exhibit the weakest integrator governance due to lean operational teams and heavy reliance on external expertise. Small and mid-sized critical infrastructure operators are particularly vulnerable, as they often lack dedicated OT security staff and default to whatever access model the integrator requests.

Shield53 Recommendations

What You Should Do

  • Inventory all third-party access: Conduct a full audit of every integrator, vendor, and contractor with current or lingering access to OT systems. Revoke credentials for completed projects immediately.
  • Eliminate shared accounts: Mandate individually identifiable credentials for all integrator personnel. Implement PAM (privileged access management) for OT environments where feasible.
  • Adopt just-in-time access: Replace standing VPNs with time-boxed, approval-based access workflows. Integrator sessions should require explicit authorization and automatically expire.
  • Enforce network segmentation: Isolate integrator access paths using jump hosts, OT-specific DMZs, and protocol-aware firewalls. Never allow integrators direct access to PLCs from corporate networks.
  • Implement session monitoring: Record and review integrator remote sessions. Deploy OT-aware monitoring tools that can detect anomalous commands or configuration changes.
  • Update contracts and SLAs: Embed cybersecurity requirements — including access lifecycle, incident notification timelines, and audit rights — into integrator contracts. Require integrators to demonstrate their own security posture.
  • Conduct periodic tabletop exercises: Simulate integrator-path compromise scenarios to test detection, response, and communication workflows before a real incident occurs.

The CISA-FBI fact sheet is not just a recommendation — it should be treated as a baseline expectation. Regulators are signaling that integrator governance will increasingly factor into compliance and liability frameworks. Organizations that continue treating third-party OT access as an operational convenience rather than a security risk will find themselves on the wrong side of both adversaries and auditors.