Third-Party ICS Access: Know What Vendors Can Reach

Controls integrators and equipment vendors require remote access to maintain and support operational systems. Operators need to know where that access enters, what systems it can reach, what activity occurs through it, and what happens if the vendor is compromised.

Based on CISA and FBI guidance for third-party ICS integrators ↗

Control the vendor access path.

Trust in the vendor does not define the security of the connection. Third-party ICS access needs a defined scope, route, access window, and owner.

01

Scope the job

Define the PLC, HMI, engineering workstation, SCADA server, remote site, or supporting system required for the work.

02

Trace the route

Document whether access enters through a VPN, jump host, remote access appliance, cellular connection, vendor service, or another path.

03

Limit the window

Define whether access remains continuously available or is enabled only when maintenance and support require it.

04

Own the change

Document who approves access, who can change it, and who removes it when the work or relationship ends.

Trace the actual path into the control environment.

“They use the VPN” does not describe the access path. Follow the connection from the vendor entry point through each boundary to the operational systems and privileges it exposes.

Expected Access Path

01 · ORIGIN

Vendor / Integrator

Technician, support account, vendor workstation, or vendor-managed service.

02 · ENTRY

Remote Access Point

VPN, remote access appliance, vendor service, cellular modem, or another inbound path.

03 · BOUNDARY

Security Boundary

Firewall, jump host, gateway, or IT and OT boundary that passes the traffic.

04 · DESTINATION

Control Environment

Engineering workstation, HMI, SCADA server, PLC, RTU, remote site, and supporting systems.

For every hop, retain:
Entry point Destination Privilege Protocol Access window Evidence

A login record shows that access occurred. Network evidence shows where the connection went, what communicated, and whether activity stayed inside the expected path.

Understand the dependency behind the connection.

Vendor risk extends beyond the remote session. Integrators hold operational information, introduce technology, and become part of how the environment is maintained, recovered, and operated.

What the vendor holds

  • Network diagrams and device details
  • Configurations and engineering files
  • Logs and operational data
  • SCADA information
  • Credentials or account information
  • Support documentation and backups

What the vendor introduced

  • Remote access appliances
  • Gateways and cellular modems
  • Engineering workstations
  • Vendor software and services
  • External communications paths
  • Accounts and update mechanisms
~800

CISA and the FBI cite a 2025 compromise of a U.S. industrial automation company in which actors searched for customer and SCADA information and prepared about 800 files for presumed exfiltration. A compromised vendor can expose operational information before an attacker reaches the operator network.

Read the Fact Sheet ↗

If every vendor connection disappeared tonight, what breaks tomorrow?

Vendor access should support operations without becoming a single point of operational failure.

Operate
Know which operational processes depend on vendor connectivity, accounts, or services.
Troubleshoot
Retain the software, documentation, configurations, credentials, and local access required to support critical systems.
Recover
Maintain current backups and known-good configurations outside systems that may be affected.
Operate manually
Test manual operating procedures under realistic conditions before they become the fallback.

Put the handoffs in writing.

Contracts and support agreements need to match the operating environment. Remote access, system changes, incident support, data custody, and recovery all need an explicit owner.

Remote access
Authorized users, approved systems, approval process, access windows, and termination requirements.
Operational data
What can leave the environment, permitted storage, access, retention, and deletion.
System changes
Who can change configurations, firmware, software, control logic, and access settings.
Cyber incidents
Notification, evidence preservation, investigation support, and escalation responsibilities.
Recovery
Configurations, backups, documentation, credentials, and support available if vendor access is unavailable.

For electric utilities, vendor access, software integrity, incident coordination, and evidence also intersect with supply chain risk management requirements.

Six answers every operator needs from third-party access.

Review these with operations, controls, IT or security, the vendor, and leadership.

Access paths: Every third-party path into the control environment is documented.

Reach and privilege: Every path has defined reachable systems and permitted actions.

Evidence: Activity through each path can be reconstructed after the session.

Vendor-held data: Operational information held by the vendor and its storage location are known.

Introduced systems: Vendor-supplied hardware, software, accounts, and communications paths are inventoried.

Continuity: Critical operations can continue if every vendor connection is disabled.

Every unchecked item needs an owner. “The integrator handles it,” “IT owns the VPN,” and “we have a firewall” do not establish ownership of the full access path.

Third-Party ICS Access Questions

Should integrator remote access stay enabled all the time?

No. Access should match the operating requirement. If continuous access is not required, define when it is enabled, who approves it, and when it is removed.

Is a VPN enough for vendor access to an ICS or SCADA environment?

No. A VPN can secure and authenticate the connection, but operators still need to know what it can reach and what happens after the session starts.

Does the controls integrator own cybersecurity for the systems they support?

Only when the scope assigns those responsibilities. Engineering support, remote maintenance, monitoring, backups, investigation, and incident response can be owned by different parties.

What should operators retain from third-party remote access?

Retain enough evidence to show when the connection occurred, which systems communicated, where the activity went, and whether it stayed inside the expected path.

Sources and Guidance

This guide applies federal and NIST guidance to third-party remote access, integrator relationships, and operational dependencies in ICS and OT environments.

Trusted access still needs evidence.

See where a vendor connection went, what systems it reached, and what happened through it.