Agencies Warn on ICS Integrators as NIST Drafts OT Guide
CISA and the FBI urged least-privilege ICS integrator access after a 2025 breach, while NIST drafted an updated OT security guide.
The FBI and CISA released a fact sheet advising critical infrastructure operators to apply least privilege and risk assessments when granting third-party ICS integrators access. It cites a March–April 2025 intrusion in which foreign cyber actors compromised a U.S. industrial automation company serving power utilities and transportation entities and searched for terms such as “customers” and “SCADA.” Accounts differ on the staged data: CISA described nine .zip files totaling roughly 800 files, including customer SCADA information, ICS device details, and schematics, prepared for presumed exfiltration, while one CISA point says the files were exfiltrated; SecurityWeek said nine archives held 800 network schematics, device configurations, and customer records and also referred to customer SCADA records. The advisory warns the material could enable future disruptive attacks and recommends assessing supply-chain risk, data-storage location, remote access, and geopolitical exposure. Separately, NIST released a draft of SP 800-82 Revision 4, Guide to Operational Technology (OT) Security, with comments due November 30, 2026; it broadens coverage to building automation, water, agriculture, freight rail, maritime, and industrial IoT-cloud convergence and reorganizes guidance around NIST CSF 2.0, including zero trust and monitoring.
- FBI and CISA issued a fact sheet urging least privilege and risk assessments for third-party ICS integrator access.
- A March–April 2025 intrusion compromised a U.S. industrial automation company serving power utilities and transportation entities; actors searched for terms such as “customers” and “SCADA.”
- CISA says nine .zip files of roughly 800 files—customer SCADA information, ICS device details, and schematics—were staged for presumed exfiltration; one CISA point says they were exfiltrated.
- SecurityWeek describes nine archives containing 800 network schematics, device configurations, and customer records, and also refers to customer SCADA records.
- Recommended reviews cover supply-chain risk, data-storage location, remote access, and geopolitical exposure; stolen data could support future disruptive attacks.
- NIST draft SP 800-82 Revision 4, Guide to Operational Technology (OT) Security, has public comments due November 30, 2026.
- The NIST revision adds building automation, water, agriculture, freight rail, maritime, and industrial IoT-cloud coverage and aligns guidance with NIST CSF 2.0, zero trust, and monitoring.
Coverage timelineoldest first · each row is one article
- · 3d agoConsiderations for Critical Infrastructure Operators Working With Third-Party ICS Integrators
CISA Advisories· 48
FBI and CISA published guidance urging critical infrastructure operators to limit third-party ICS integrator access, citing a 2025 breach of a U.S. automation firm.
- · 2d agoOT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
SecurityWeek· 68
NIST drafted an updated OT security guide while CISA and the FBI warned about risks from third-party ICS integrators.