FBI
Sept. 23, 2026
Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
Introduction
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—
hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight
considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working
with third-party industrial control system (ICS) integrators.
ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and
automate physical processes, encompassing specialized control systems and devices, such as supervisory
control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators
provide varying types of services for ICS, such as control system design, installation, operational data
analysis, device support and service, and daily operational control.
Critical infrastructure owners and operators should maintain caution when granting third-party ICS
integrators high levels of access or control over industrial processes, ensuring the principle of least
privilege (PoLP), is applied. PoLP within OT environments lends itself to granting users, processes, and
systems only the minimum access necessary to perform their assigned tasks, and no more. PoLP is
designed to protect owners and operators. Not adopting principles such as PoLP could expose owners and
operators to malicious cyber actors seeking to compromise critical infrastructure, possibly providing
sensitive access to pathways that actors can exploit to cause disruptive and destructive effects to
equipment and critical functions.
Critical infrastructure owners and operators should action the recommendations in this fact sheet to work
with integrators to ensure secure practices and frameworks are put in place to reduce the risk of malicious
actors exploiting third-party accesses to compromise critical infrastructure operational environments.
Examples of Risk and Exploitation
Continued:
https://www.ic3.gov/CSA/2026/260923.pdf