WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity

Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators

Detailed view of network cables plugged into a server rack in a data center.
Illustrative photo.Photo by Brett Sayles on Pexels

What happened

Risk assessments should address hardware and software supply chain vulnerabilities introduced by integrator equipment, as well as the IT and OT security of these devices and their associated networks. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control.

Critical infrastructure owners and operators should maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes, ensuring the principle of least privilege (PoLP), is applied. If the integrator is foreign-owned, consider whether the utility data is stored within the United States or internationally. Having redundancies in place and the ability to recover the system and operate without the integrator, especially for operationally critical processes, can reduce risk in the event of integrator compromise.

Key facts

  • Risk assessments should address hardware and software supply chain vulnerabilities — introduced: by integrator equipment, as well as the IT and OT security of these devices and their associated networks

Sources & evidence