Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
WASHINGTON — The FBI and Cybersecurity and Infrastructure Security Agency are warning critical infrastructure owners and operators to closely examine the access, control, and supply-chain risks created when third-party industrial control system integrators are given access to operational technology environments.
In a joint fact sheet issued September 23, 2026, the agencies said third-party ICS integrators can provide services ranging from control system design and installation to operational data analysis, device support, service, and daily operational control. Those relationships can also create sensitive pathways into systems that monitor and automate physical processes, including supervisory control and data acquisition systems and programmable logic controllers.
The FBI and CISA said critical infrastructure operators should apply the principle of least privilege when granting integrators access to operational environments. That means users, processes, and systems should receive only the access necessary to perform assigned tasks and no more. The agencies warned that failing to limit access can expose pathways malicious cyber actors may exploit to disrupt equipment and critical functions.
The warning focuses heavily on the risk created when integrators are trusted with system design, remote access, operational data, or direct control over industrial environments.
The agencies said third-party integrators can unintentionally introduce weaknesses when systems and services are deployed without being configured to meet the customer’s security requirements. Supply-chain risk can also increase if integrators and infrastructure operators do not establish clear requirements for secure procurement and handling of components.
Data location is another concern.
The fact sheet warns that third-party integrators hosting data outside the United States may be subject to foreign data-storage and management laws that do not align with the security needs of U.S. critical infrastructure entities. The agencies advise operators to account for those legal and geopolitical conditions when evaluating foreign-owned integrators and determining where sensitive operational information is stored.
The joint guidance also includes a concrete example drawn from FBI technical analysis.
Between March and April 2025, malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company that provided system integration, engineering consulting, and SCADA programming for industrial customers, including power utilities and transportation entities. Once inside the network, the actors searched terms including “customers” and “SCADA” and created nine ZIP files containing approximately 800 files for presumed exfiltration. The material included customer SCADA information, ICS device details, and other schematics.
The FBI and CISA warned that information taken from an integrator’s network could later be used to support disruptive attacks against operational environments and critical services.
That example illustrates the core concern behind the advisory: an attacker does not always need to compromise a utility, transportation system, or industrial operator directly if a trusted integrator already possesses access, documentation, engineering details, or network information connected to those environments.
The agencies recommend that critical infrastructure organizations routinely conduct risk assessments when evaluating contracts involving third-party access to industrial systems. Those reviews should examine the organization’s data autonomy, process controls, supply-chain exposure, hardware and software dependencies, and the security of both information technology and operational technology systems associated with the integrator.
Operators are also urged to determine exactly what data an integrator can access or store. Network designs, device specifications, logs, and other technical records can provide useful intelligence to malicious actors if an integrator’s network is compromised.
Remote access receives particular attention.
If an integrator maintains remote connectivity into an organization’s ICS network, the agencies warn that an attacker who compromises the integrator may be able to pivot into the customer environment and potentially gain control of industrial systems. Infrastructure operators are encouraged to evaluate how those remote connections are secured and what level of access they provide.
The FBI and CISA also recommend that operators determine whether they can continue functioning if an integrator is compromised or becomes unavailable. Redundant capabilities, independent recovery procedures, and secure offline backups of software required to operate equipment can reduce dependence on a third party during an incident.
The guidance calls for cybersecurity and supply-chain security requirements to be written directly into contracts and service agreements. Those requirements can address data-storage locations, protection of ICS data and design documentation, remote-access capabilities, the integrator’s cybersecurity program, change and patch management, deployment security, authorized personnel, and local engineering support.
The agencies also recommend evaluating any industrial devices with direct internet exposure and minimizing that exposure where possible. Operators should understand where devices are hosted, disconnect unnecessary public-facing access, monitor and log remote connections, and use on-demand remote access where feasible so integrator access must be actively authorized.
Critical infrastructure operators are further advised to request complete inventories of software and hardware supplied by integrators, document how those components connect to the organization’s infrastructure, understand how they will be updated, and maintain procedures for manual operations when automated or third-party support is unavailable.
In an ICS environment, an integrator may hold far more than ordinary vendor access. Depending on the service arrangement, that third party may possess design information, remote connectivity, engineering documentation, configuration data, software dependencies, and direct knowledge of operational processes.
That level of trust can become a serious vulnerability if the integrator itself is compromised.
The FBI and CISA are urging operators to plan for that possibility before an incident occurs by limiting access, monitoring remote connections, preserving offline recovery resources, documenting dependencies, and ensuring organizations can operate without uninterrupted third-party support.
The agencies are also urging critical infrastructure operators to report suspicious cyber activity. Reports can be made to local FBI field offices, the Internet Crime Complaint Center, or CISA’s 24/7 Operations Center. Urgent threats involving immediate danger to life should be reported to 911.
The September 23 fact sheet is marked TLP:CLEAR, meaning the information may be distributed without restriction under standard copyright rules.
The central message from the FBI and CISA is straightforward: third-party ICS integrators can be essential to modern industrial operations, but access to critical systems must be treated as a security boundary.
For infrastructure operators, the risk is no longer limited to whether their own networks are hardened.
The security posture of the companies designing, maintaining, connecting to, and supporting those systems can become part of the same threat surface.
Federal Bureau of Investigation and Cybersecurity and Infrastructure Security Agency, Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators, September 23, 2026. TLP:CLEAR. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



