A water utility may appear to be protected by a fence, a control room and a locked equipment cabinet. But the path into its machinery may begin somewhere else: in a contractor’s remote-support network, engineering laptop or cloud dashboard.
That is the significance of two federal developments this month. On September 21, the National Institute of Standards and Technology released an initial public draft of the fourth revision of its operational-technology security guide. Two days later, the FBI and Cybersecurity and Infrastructure Security Agency issued a fact sheet focused specifically on third-party industrial-control-system integrators.
The agencies are not suggesting that contractors are inherently negligent or malicious. They are describing a more basic technical reality: the security boundary of a water plant, utility or transportation system may extend into networks and devices the owner does not directly control.
The important question is therefore not simply whether a facility has a firewall or whether its software is patched. It is whether the owner knows who can reach the machinery, through which path, with what authority—and whether the facility can continue operating if that outside relationship is compromised.
The contractor may be part of the control system
Industrial control systems are not ordinary office software. They include programmable logic controllers, supervisory control and data-acquisition systems, engineering workstations, sensors, human-machine interfaces and network gateways. Together, they monitor and change physical processes such as pump pressure, valves, treatment equipment and electrical switching.
The FBI and CISA describe third-party integrators as companies that may design control systems, install equipment, analyze operational data, support devices and, in some cases, conduct daily operational control. For smaller utilities, that outside expertise may be necessary. Few local governments can employ specialists for every controller, sensor and aging piece of industrial equipment.
Necessity, however, does not eliminate the risk. A contractor may possess remote-access credentials, engineering software, project files, network diagrams, device inventories or cloud-hosted monitoring tools. It may also supply similar hardware and configurations to several customers.
That creates a supply-chain problem with a physical consequence. A compromised contractor may not need to attack every water plant separately if its network contains the information or access pathways associated with several plants.
One compromised contractor can expose a map of many systems
The FBI said foreign cyber actors gained access between March and April 2025 to the network of a U.S. industrial-automation company that provided system integration, engineering consulting and SCADA programming for industrial customers, including power utilities and transportation entities.
According to the FBI and CISA, the attackers searched for terms including “customers” and “SCADA” and created nine compressed files containing approximately 800 files. The files included customer SCADA information, industrial-control-system details and schematics.
No public finding says that the stolen information was used to disrupt every customer. The concern is what such information makes possible. Network designs, device specifications and project files can show an attacker how an environment is organized before anyone changes a setting or takes control of a device.
The risk is also multiplied by standardization. In a separate July warning about attacks on internet-facing programmable logic controllers at water and wastewater utilities, the FBI said similarities in network setups provided by third parties could allow malicious actors to reproduce successful techniques across multiple customers.
Since July 27, water and wastewater utilities in at least seven states have reported incidents involving certain Rockwell Automation and Allen-Bradley controllers. The FBI said attackers changed device IP addresses and passwords, causing loss of monitoring and control. Reported effects included pressure loss and flooding. The agency did not say that every incident was caused by a third-party integrator. The broader lesson is that repeated configurations can create repeated weaknesses.
What the federal guidance asks owners to know
The FBI and CISA recommend that infrastructure owners address third-party access in contracts and operating procedures rather than treating it as an informal technical convenience.
- Require cybersecurity and supply-chain protections in service agreements.
- Identify where operational data and design documentation are stored.
- Maintain a list of authorized personnel who can access systems.
- Request an inventory of all hardware and software supplied by the integrator.
- Document how those components connect to the owner’s infrastructure and how they are updated.
- Monitor and log remote access, using on-demand access where possible.
- Minimize or eliminate direct public-internet exposure for control devices.
- Maintain offline backups and local engineering support.
- Practice manual operations and recovery procedures that do not depend entirely on the integrator.
These recommendations sound straightforward until an owner tries to answer the underlying questions. Which vendors can connect? Through which systems? Using which credentials? To which devices? Under what conditions? Where are the logs reviewed? How quickly can access be revoked?
An organization may have a contract that requires logging without anyone regularly examining the logs. It may have a backup without knowing whether the backup contains a legitimate controller configuration. It may have a manual procedure that has never been tested while communications, monitoring and vendor support are unavailable.
Zero trust is not a magic phrase
Federal guidance increasingly uses terms such as least privilege, secure gateways, segmentation and zero-trust architecture. The concepts are useful, but they are not solutions by themselves.
Least privilege means giving a contractor only the access required for a specific task—not permanent access to an entire control environment. On-demand access means the utility enables a connection when it is needed rather than leaving it continuously available. A jump host or secure gateway provides a monitored intermediary instead of allowing a contractor to connect directly to a controller. Segmentation limits how far an intruder can move if one device or account is compromised.
Each measure reduces the potential blast radius. None makes compromise impossible. They also depend on accurate inventories and disciplined administration. Least privilege is difficult when nobody knows which devices a contractor installed. On-demand access is less useful if the same account is shared by several people. Segmentation is weakened when emergency exceptions become permanent connections.
The NIST draft reflects this broader view of operational technology. Its revised coverage includes water and wastewater, building automation, freight rail, maritime systems, food and agriculture, industrial internet-of-things devices and cloud convergence. It also expands discussion of asset management, network monitoring, system-management functions and zero-trust principles. The document is guidance, not a mandatory regulation, and its public-comment period runs through November 30, 2026.
The independence test
The most valuable question for a utility is also the least glamorous: Can it operate without the contractor?
That does not mean every facility must permanently duplicate every vendor capability. It means the owner should be able to revoke outside access, restore a known-good configuration, contact an alternative engineering resource, identify the devices in the environment and continue safe operations while the incident is investigated.
The FBI’s water-sector guidance recommends reviewing controller project files for unauthorized changes, checking connected modems and workstations, verifying backups before restoration and reimaging devices when lateral movement may have occurred. Recovery is not simply a matter of pressing “restore.” Operators must establish which files are legitimate, which devices were touched and whether an attacker moved beyond the original controller.
For a small utility, this may be expensive. But outsourcing technical work should not also mean outsourcing knowledge of what the system contains or how it can be recovered.
A contractor may reasonably maintain a water plant’s control system. It should not become impossible for the owner to determine who can reach that system, where its most sensitive information is stored or how to operate safely when the contractor is unavailable.
Critical infrastructure is increasingly maintained through digital relationships that extend beyond the physical facility. Security depends on whether owners can see, limit and replace those relationships before an incident forces them to.













