CISA, FBI issue ICS integrator guidance
The guide urges tighter remote access controls, stronger contracts, and manual operations for critical infrastructure using third-party ICS integrators.
CISA and the FBI released a new guidance sheet for critical infrastructure operators that work with third-party ICS system integrators. The document calls for cybersecurity and supply chain requirements in contracts, reduced public exposure of devices, logging of remote access, hardware and software inventories, and the ability to keep operating manually.
CISA and the FBI published a new guidance sheet on September 23 for critical infrastructure organizations that work with third-party ICS system integrators. The document, titled Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators, is aimed at reducing reliance on outside vendors and tightening remote access, technical documentation, and continuity planning.
What does the new guidance ask for?
The guidance recommends adding cybersecurity and supply chain security requirements to contracts, reducing the public exposure of devices, monitoring and logging remote access, requiring hardware and software inventories, and maintaining manual operating capabilities. It also suggests allowing remote access on demand rather than keeping it permanently enabled.
The joint guidance also says operators should document how integrator-provided components connect to the infrastructure and how they receive updates. According to independent coverage, it also calls for limiting each integrator to the minimum access necessary, supervising and recording remote sessions, protecting offline copies of the software needed to run equipment, and preparing essential processes so operations can continue if the integrator becomes unavailable.
What risk is the guidance trying to reduce?
The guidance treats the ICS integrator as a supply chain risk and as a dependency that can complicate continuity if the third party is compromised or unavailable. That view is reinforced in additional analysis, which emphasizes the need for local engineering capabilities, redundancy, and offline backups.
In practice, the combined coverage points to operators avoiding dependence on a single management or support path. The document's logic is that if the integrator fails or is affected, the facility should still be able to sustain essential functions through internal procedures and software kept offline.
What other risk signals accompany the guidance?
The same sector coverage package includes exposure and OT incident data across different industries. SpyCloud said 1,787 organizations linked to the U.S. water and wastewater sector show exposure to infostealer malware, including 258 with compromised credentials associated with OT or remote access systems.
Another report, attributed to SpyCloud but not independently confirmed, said at least 250 organizations could have credentials capable of accessing operational systems that control water pumps and flows. An additional note said those infostealer-collected credentials would affect 1,787 water suppliers, about 20% of the providers included in the review, although that source said it does not independently validate the dataset.
At the same time, an OT cybersecurity benchmarking report cited by the sector coverage said 91% of energy and utilities respondents suffered a significant OT cybersecurity incident in the previous 12 months. The same reporting line added that 87% of maritime respondents reported significant OT incidents during that period.
Sources
- FBI, CISA Warn of Third-Party ICS Integrator Riskssecuritytoday.com· Security Today
- Stolen Passwords Put More Than 1700 U.S. Water ...techshotsapp.com· TechShots
- Daily OT Security News: September 25, 2026securityboulevard.com· SecurityBoulevardUnverified URL
- OT Confidence Outpaces Asset Visibilitysecuritytoday.com· Security Today
- 258 U.S. Water Organizations Have Credentials Exposed ...esecurityplanet.com· eSecurity Planet
- CISA and FBI Release Fact Sheet to Help Critical Infrastructure Operators Work with Third-Party ICS Integratorscontent.govdelivery.com· CISA
- SpyCloud finds 1787 US water providers exposed to malwarethecooldown.com· The Cool Down
- This Week in Cyber: September 18 to 24, 2026crunchatlas.com· CrunchAtlas
- Your ICS Integrator Is a High-Value Target—CISA and FBI Map the Riskministryofcyberaffairs.com· Ministry of Cyber Affairs
- More than 90% of energy companies report high levels of cyber attacksenergylivenews.com· Energy Live News
- Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integratorscyberict.com· Cyber ICT



