INSIGHTS

Third-Party ICS Access and the Engineering Authorization Gap

On September 23, 2026, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) published a joint fact sheet on risk considerations for critical infrastructure operators working with third-party industrial control system (ICS) integrators. It is a useful prompt for a distinction worth stating plainly: a network pathway into an environment is not the same question as whether a specific engineering action on that pathway is authorized.

WHAT THE FACT SHEET SAYS

Considerations for third-party ICS integrator access.

The fact sheet recommends the principle of least privilege for users, processes, and systems; listing authorized personnel with system access; monitoring and logging remote access and preferring on-demand access over standing connections; requesting an inventory of integrator-supplied software and hardware; and maintaining the ability to recover and operate independently if an integrator is compromised. It also describes FBI technical analysis of a compromise, between March and April 2025, of a U.S. industrial automation solutions company that served industrial customers including power utilities and transportation entities, in which threat actors searched for terms including "customers" and "SCADA" and created nine ZIP files containing approximately 800 files for presumed exfiltration.

Read the primary source directly: Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators, FBI and CISA, September 23, 2026.

WHERE THE QUESTIONS DIFFER

A network pathway is not an engineering authorization.

Remote access controls answer a question about reachability. EWSP addresses a narrower, later question at its own boundary.

Remote access controls, monitoring, and the other measures the fact sheet describes answer a question about reachability: may this integrator, or this connection, reach the operational environment at all. EWSP addresses a narrower and later question, at its own control boundary: once an engineering pathway exists, is the covered engineering activity against a specific industrial asset authorized under the applicable policy and available evidence. A trusted integrator relationship, like a trusted workstation or a trusted network path, establishes eligibility to perform engineering work. It does not by itself establish unrestricted authority to perform every engineering action.

HOW THE CONSIDERATIONS RELATE TO EWSP

A deliberately narrow overlap.

Most of the fact sheet's considerations sit outside what EWSP does. The overlap that exists is specific, and stated narrowly on purpose.

COVERED BY EWSP

Selected engineering authorizationEngineering activity within EWSP's explicitly configured coverage can be evaluated against policy and locally enforced, with authorization and enforcement evidence retained for the covered session.

COMPLEMENTED BY EWSP

Least privilege for engineering activityEWSP applies policy-based authorization to selected engineering activity. It does not implement an organization's entire least-privilege program for users, processes, and systems.
Remote access governance and monitoringRemote access and privileged access management controls determine whether a pathway into the environment exists at all. EWSP's boundary begins after that pathway exists, for the engineering activity it covers.
Engineering and application contextEWSP maintains context relevant to the engineering activity it authorizes. It is not a general software or hardware inventory system.
Recovery planningEWSP includes enforcement and recovery behavior for its own protection boundary. It is not a substitute for offline backups, disaster recovery planning, or manual operating procedures.

OUTSIDE EWSP SCOPE

DESIGN PARTNERS AND PILOTS

Validate the engineering authorization boundary in a real workflow.

contact@ewsp.org