FBI, CISA Tie ICS Integrator Guidance to Live Intrusion
The advisory is the first joint FBI-CISA product explicitly linking a third-party integrator compromise to exfiltration of customer SCADA schematics, and it puts the hardening burden on the operator, not the integrator.
TL;DR
FBI and CISA published joint guidance Thursday urging critical infrastructure operators to enforce least-privilege access for third-party ICS integrators. The advisory anchors its recommendations in a March-April 2025 intrusion at a U.S. industrial automation vendor (one that served power utilities and transportation entities) where threat actors searched for "SCADA" and "customers" and created nine .zip files of roughly 800 files for presumed exfiltration. The guidance stops short of mandating contractual audit requirements or setting a compliance deadline; it's advisory, not a binding operational directive.

The fact sheet is the first time CISA and the FBI have tied ICS integrator risk guidance to a named intrusion rather than generic threat-actor TTPs. That's the signal. When an agency appends a real breach (customer SCADA information, ICS device details, schematics) to recommendations it has been making since at least 2010, it's telegraphing that the abstract risk is now the concrete one.
What the guidance actually says, and what it doesn't
The document walks operators through two buckets: assess risk, then reduce it. On assessment, it tells operators to ask four questions of any integrator relationship: what organizational data the integrator stores or accesses, where that data sits (foreign-owned integrators may subject it to non-U.S. law), whether the integrator has remote access, and whether the operator can operate independently if the integrator is compromised. On reduction, it covers contract language (data storage locations, remote access capabilities, integrator cybersecurity program basics, authorized personnel lists), device inventory requirements, on-demand remote access with operator-controlled monitoring and logging, and manual-operation contingency planning.
What's absent: any mention of a binding operational directive, a compliance deadline, or a requirement that operators contractually mandate specific audit rights over integrator networks. This is guidance, not regulation. An operator who reads it and changes nothing has violated no federal requirement.
The intrusion that forced the hand
According to FBI technical analysis, between March and April 2025 malicious foreign cyber actors accessed the network of a U.S. industrial automation solutions company whose services included system integration, engineering consulting, and SCADA programming for customers in power utilities and transportation. Once inside, the actors searched for "customers" and "SCADA" and assembled approximately 800 files across nine .zip archives for presumed exfiltration, customer SCADA information, ICS device details, and schematics.
The guidance doesn't name the vendor or the threat actor. It doesn't need to. The scenario it describes is the one operators have been warned about: a trusted third party with always-on remote access to multiple customer environments becomes the ingress point, and what walks out the door isn't just the integrator's intellectual property but the operator's own control-system blueprints.
Practitioners' Monday
For the engineer or contracting officer who has to do something with this, three changes from last week:
First, least-privilege enforcement now has a named incident behind it. The internal conversation shifts from "best practice" to "this happened." That matters for budget and priority conversations that were previously theoretical.
Second, integrator contracts need review, specifically the clauses covering data storage geography, remote access posture, and the integrator's own cybersecurity program. The guidance supplies a checklist that doubles as a negotiation template.
Third, the manual-operations and offline-recovery testing the guidance recommends means operators need to confirm they can isolate from the integrator's network and still restore systems. That's an exercise, not a policy memo. Someone has to schedule it.
Published ·Deep Fathom