What should critical infrastructure operators do when working with third-party ICS integrators?

Critical infrastructure operators working with third-party ICS integrators should focus on reducing risk and limiting vulnerabilities in those relationships.
The direct answer
The FBI and CISA fact sheet is aimed at critical infrastructure entities that work with third-party industrial control system integrators. It was published by CISA on September 23, 2026.
The confirmed focus is relationship risk: how operators work with integrators that provide services for ICS environments, including control-related work.
What to review in the relationship
The context does not list a detailed checklist, but it does confirm the risk area. Operators should use the fact sheet to review the relationship between the critical infrastructure entity and the third-party ICS integrator, especially where the integrator touches ICS environments.
That matters because ICS are networks of hardware and software used to monitor and automate physical processes.
What not to assume
The available context does not provide specific technical controls, contract clauses, deadlines, or reporting requirements. For those details, consult the official fact sheet itself.
Because guidance can be updated, use CISA’s current page when applying it to an operating environment.
How can operators reduce risk from third-party integrators in ICS environments?

Operators can reduce risk by treating third-party ICS integrator relationships as a specific security concern, not just a procurement or operations detail.
Where to focus
The FBI and CISA fact sheet focuses on reducing risk and limiting vulnerabilities for critical infrastructure entities that work with third-party industrial control system integrators.
The available context confirms that third-party integrators can provide services for ICS environments, including control-related work. That makes the relationship important because ICS help monitor and automate physical processes.
A practical way to use the fact sheet
Use the fact sheet as a starting point for reviewing where a third-party integrator connects to, supports, or performs work in an ICS environment.
Based only on the confirmed context, the key questions are:
- Does the organization work with third-party ICS integrators?
- Do those integrators provide services in ICS environments?
- Does the work include control-related activity?
- Are the relationship risks and possible vulnerabilities being reviewed?
Important limitation
The context does not include the fact sheet’s specific recommendations. It confirms the audience and purpose, but not a full control list.
For operational decisions, read the CISA fact sheet directly and check whether a newer version has been posted.
Which organizations is the FBI and CISA ICS integrator fact sheet meant for?

The FBI and CISA ICS integrator fact sheet is meant for critical infrastructure entities that work with third-party industrial control system integrators.
Who is included
The confirmed audience is not every technology user or every business. It is specifically critical infrastructure entities with third-party ICS integrator relationships.
The fact sheet focuses on reducing risk and limiting vulnerabilities in those relationships.
Why that audience matters
Industrial control systems are described as networks of hardware and software used to monitor and automate physical processes. Third-party integrators may provide services in those environments, including control-related work.
That combination makes the relationship important for critical infrastructure operators.
What the context does not define
The available facts do not list specific sectors, organization sizes, eligibility categories, or mandatory requirements. It also does not say the fact sheet applies only to one type of ICS environment.
If your organization may fall into the target audience, the official CISA resource is the place to confirm how the guidance is framed.
What types of ICS work can third-party integrators provide for critical infrastructure entities?

Third-party ICS integrators can provide services for industrial control system environments, including control-related work.
What is confirmed
The FBI and CISA fact sheet notes that third-party integrators can support ICS environments. The context specifically mentions control-related work.
It also explains that ICS are networks of hardware and software used to monitor and automate physical processes.
How to read that practically
For critical infrastructure entities, this means third-party integrators may be involved in systems connected to real operational processes, not only general business technology.
That is why the fact sheet focuses on reducing risk and limiting vulnerabilities in those relationships.
What is not specified
The context does not list exact service categories, tools, system components, or contractual responsibilities. It only confirms that integrators can provide services for ICS environments and may do control-related work.
For a fuller list of considerations, review the CISA fact sheet directly, especially if you are mapping it to a specific integrator relationship.
Sources / Learn more
Related reading
- What should Citrix NetScaler ADC and Gateway administrators do before applying patches for the exploited zero-days?; Which Citrix NetScaler vulnerabilities were added to CISA’s Known Exploited Vulnerabilities Catalog?
- What changed for ChatGPT’s third-party integrations now that ‘apps’ were renamed to ‘plugins’ in July 2026?
- How can borrowers get an inaccurately reported discharged student loan corrected with Equifax, Experian, or TransUnion?
- What conflict-of-interest facts did the SEC say Zoe Financial failed to fully and fairly disclose?; How did Zoe Financial’s adviser-matching referral service work according to the SEC order?; What should prospective clients ask before using an adviser referral service with affiliated adviser support services?

Leave a Reply