СкамыОригинал на английском
Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
Русский перевод готовится и скоро появится на сайте. Пока доступен оригинал на английском.
Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and
CISA Alerts··4 мин чтения
Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control. Critical infrastructure owners and operators should maintain caution when granting third-party ICS integrators high levels of access or control over industrial processes, ensuring the principle of least privilege (PoLP), is applied. PoLP within OT environments lends itself to granting users, processes, and systems only the minimum access necessary to perform their assigned tasks, and no more. PoLP is designed to protect owners and operators. Not adopting principles such as PoLP could expose owners and operators to malicious cyber actors seeking to compromise critical infrastructure, possibly providing sensitive access to pathways that actors can exploit to cause disruptive and destructive effects to equipment and critical functions. Critical infrastructure owners and operators should action the recommendations in this fact sheet to work with integrators to ensure secure practices and frameworks are put in place to reduce the risk of malicious actors exploiting third-party accesses to compromise critical infrastructure operational environments. Examples of Risk and Exploitation Much like IT systems, using third-party ICS integrators in critical infrastructure may inadvertently introduce security issues to a customer environment by exposing systems and services not pre-configured to the customer’s security requirements. Critical infrastructure owners and operators that rely on third-party integrators for system design face supply chain risks if integrators and owners and operators do not collectively enforce clear requirements for the secure procurement and handling of system components. Furthermore, third-party integrators that operate and host data outside of the United States may pose additional risks, as they may be subject to different data storage and management laws that do not meet the security needs of U.S. critical infrastructure entities. According to FBI technical analysis, between March and April 2025, malicious foreign cyber actors gained access to the network of a U.S. industrial automation solutions company that offered services—such as system integration, engineering consulting, and SCADA programming—for industrial customers, including power utilities and transportation entities. While on the network, threat actors searched terms, including “customers” and “SCADA,” and created nine .zip files consisting of approximately 800 files for presumed exfiltration, including customer SCADA information, ICS device details, and other schematics. Malicious cyber actors could leverage the exfiltrated information to later conduct disruptive attacks against operational environments and disrupt critical services. Recommendations to Assess Risk Critical infrastructure owners and operators should make risk-informed decisions when considering introducing third-party integrators into their networks and operations, guided by a robust understanding of the organizational risks posed by providing sensitive access to their systems. Organizations should routinely conduct risk assessments to evaluate contracts that involve access to industrial systems, to determine impacts to the organiz