Home › Intelligence › Brief
BREACH BRIEF🟠 High Advisory

CISA Advises Critical Infrastructure Operators to Enforce Least‑Privilege with Third‑Party ICS Integrators

The FBI and CISA issued guidance urging owners of SCADA and PLC environments to apply the principle of least privilege for third‑party integrators. The advice highlights a control‑assurance gap that, if left unchecked, can expose critical‑infrastructure to supply‑chain compromise and audit deficiencies.

LiveThreat™ Intelligence · 📅 September 24, 2026· 📰 cisa.gov
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
2 recommended
📰
Source
cisa.gov

CISA Advises Critical Infrastructure Operators to Enforce Least‑Privilege with Third‑Party ICS Integrators

What Happened — The FBI and CISA released a fact sheet urging owners and operators of critical‑infrastructure industrial control systems (ICS) to apply the principle of least privilege (PoLP) when granting high‑level access to third‑party integrators that design, install, or operate SCADA and PLC environments.

Why It Matters for Trust & Control Assurance

  • PoLP is a core control‑assurance requirement that can be continuously monitored and evidenced, reducing the risk of a supply‑chain compromise.
  • Demonstrating documented third‑party access restrictions satisfies multiple framework objectives (e.g., NIST CSF Identify and Protect functions).
  • Verisq’s Vendor Risk Management capability provides a single source of truth for third‑party access reviews, continuous monitoring, and audit‑ready evidence.

Who Is Affected – Operators in energy & utilities, water, transportation, and other sectors that rely on SCADA, PLC, or other OT platforms.

Recommended Actions –

  • Inventory all third‑party ICS integrators and map the specific privileges they require.
  • Enforce PoLP through role‑based access controls and document the justification for each privilege.
  • Capture and retain evidence of access reviews in a centralized Trust Center for audit readiness.

Technical Notes – The guidance focuses on governance and access‑control processes rather than a specific vulnerability; no CVE or exploit is cited. It highlights the risk of malicious actors leveraging over‑privileged third‑party accounts to disrupt physical processes.

Source: CISA Fact Sheet – Considerations for Critical Infrastructure Operators Working With Third‑Party ICS Integrators

📰 Original Source
https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →