INSIGHTS
Third-Party ICS Access and the Engineering Authorization Gap
On September 23, 2026, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) published a joint fact sheet on risk considerations for critical infrastructure operators working with third-party industrial control system (ICS) integrators. It is a useful prompt for a distinction worth stating plainly: a network pathway into an environment is not the same question as whether a specific engineering action on that pathway is authorized.
WHAT THE FACT SHEET SAYS
Considerations for third-party ICS integrator access.
The fact sheet recommends the principle of least privilege for users, processes, and systems; listing authorized personnel with system access; monitoring and logging remote access and preferring on-demand access over standing connections; requesting an inventory of integrator-supplied software and hardware; and maintaining the ability to recover and operate independently if an integrator is compromised. It also describes FBI technical analysis of a compromise, between March and April 2025, of a U.S. industrial automation solutions company that served industrial customers including power utilities and transportation entities, in which threat actors searched for terms including "customers" and "SCADA" and created nine ZIP files containing approximately 800 files for presumed exfiltration.
Read the primary source directly: Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators, FBI and CISA, September 23, 2026.
WHERE THE QUESTIONS DIFFER
A network pathway is not an engineering authorization.
Remote access controls answer a question about reachability. EWSP addresses a narrower, later question at its own boundary.
Remote access controls, monitoring, and the other measures the fact sheet describes answer a question about reachability: may this integrator, or this connection, reach the operational environment at all. EWSP addresses a narrower and later question, at its own control boundary: once an engineering pathway exists, is the covered engineering activity against a specific industrial asset authorized under the applicable policy and available evidence. A trusted integrator relationship, like a trusted workstation or a trusted network path, establishes eligibility to perform engineering work. It does not by itself establish unrestricted authority to perform every engineering action.
HOW THE CONSIDERATIONS RELATE TO EWSP
A deliberately narrow overlap.
Most of the fact sheet's considerations sit outside what EWSP does. The overlap that exists is specific, and stated narrowly on purpose.
COVERED BY EWSP
COMPLEMENTED BY EWSP
OUTSIDE EWSP SCOPE
- VPN and privileged access management infrastructure
- Personnel access administration and authorization
- Evaluation of an integrator's own cybersecurity program
- Contractual and supply-chain security requirements
- Data residency and storage location governance
- Plant-wide backup and disaster recovery
- Manual operations procedures
DESIGN PARTNERS AND PILOTS