FBI and CISA warn critical infrastructure operators to rein in third-party ICS integrators
A new joint fact sheet asks water, power and manufacturing operators to lock down the outside engineers who quietly run their control systems.

Key points
- The FBI and CISA published a joint fact sheet on third-party ICS integrators urging critical infrastructure operators to apply least-privilege access to the outside firms that install and run their control systems.
- ICS, short for industrial control systems, is the hardware and software that runs physical processes like pumping water or keeping a factory line running.
- The guidance covers SCADA systems and programmable logic controllers, the small computers that open valves and start motors on the plant floor.
- The agencies want operators to stop granting integrators broad, permanent, high-privilege access to those systems.
- Threat Vectr's own leak-site tracking shows ransomware crews continue to list manufacturing and utility victims week after week, many reached through trusted vendor connections.
The US government wants critical infrastructure operators to take a hard look at the outside companies wiring up their industrial systems. That's not a new concern, but the FBI and CISA are now putting it in writing.
The FBI and the Cybersecurity and Infrastructure Security Agency, known as CISA, published a joint fact sheet this week on the risks of working with third-party industrial control system integrators. These are the specialist engineering firms that design and often quietly keep running the computers that control physical equipment. The agencies aren't describing a single breach. They're describing a pattern.
What is an ICS integrator, and why does this matter?
An ICS integrator is the outside firm a utility or manufacturer hires to build and maintain its control systems. Think of the contractor who installs a shop alarm, keeps a key, and can log in remotely to fix it at 2am. Now picture that for a water treatment plant.
Industrial control systems, or ICS, are the mix of hardware and software that run physical processes. That includes SCADA, which stands for supervisory control and data acquisition and is the screen an operator watches to see tank levels or grid loads, and programmable logic controllers, the small rugged computers that actually open a valve or start a pump.
Integrators often hold deep access to all of it. They may design the system, install it, service the devices, or in some cases run day-to-day operations. That access rarely gets trimmed once the job is done.
This isn't an abstract risk. Our 23 September story "FBI warns foreign hackers raided a US industrial contractor for SCADA blueprints" reported that a March to April 2025 intrusion at an automation firm netted around 800 files on power and transport customers, reached precisely because that contractor held extensive access.
What are the FBI and CISA actually asking for?
The headline ask is the principle of least privilege, which means giving any user or system only the access it needs for its job, and nothing more. Applied to a water utility, that means an integrator's account shouldn't be able to reach the billing network and the safety controllers simultaneously just because it was convenient during install.
The CISA fact sheet tells owners and operators to stay cautious when handing integrators high levels of control over industrial processes. Assume the integrator's laptop, VPN or cloud tool could be compromised, and design access so that a breach there doesn't become a breach at the plant.
Should the public worry about their water or power?
Not in a panic sense. There's no named incident behind this fact sheet. What there is: a long pattern of attackers reaching industrial targets through the trusted side door of a vendor or contractor. Threat Vectr's own tracking of ransomware leak sites shows manufacturers and utilities getting listed most weeks, and post-mortems on those incidents keep pointing back to remote access held by an outside supplier. The FBI and CISA are trying to get ahead of the next one.
| Item | Detail |
|---|---|
| Publishing agencies | FBI and CISA |
| Document type | Joint fact sheet |
| Audience | Critical infrastructure owners and operators |
| Core principle | Least privilege for third-party ICS integrators |
| Systems in scope | SCADA, programmable logic controllers, wider ICS |
My read: this fact sheet is aimed less at security teams, who already know, and more at the executives who sign the integrator contracts. Least privilege costs money and slows projects down. Until procurement treats vendor access as a safety issue, the same door will keep getting kicked in.



