The FBI and CISA have released a joint fact sheet on how critical infrastructure operators can reduce risk when relying on third-party industrial control system (ICS) integrators. The agencies urge limiting integrator access to only what each task requires and warn that an integrator's network can give malicious actors a pathway into customer environments. The document cites an FBI case in which foreign cyber actors breached a U.S. industrial automation company in early 2025, searching for terms like "SCADA" and staging roughly 800 files, including customer SCADA information, device details, and schematics.
WaterISAC notes that many water utilities depend on integrators for PLC programming, SCADA upgrades, and troubleshooting, and that integrators often hold network drawings, control logic, and credentials. One compromised firm could expose many utilities. Recent PLC attacks at water systems also showed the danger of default passwords.