# FBI and CISA Warn of ICS Integrator Risks

The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have jointly issued guidance to critical infrastructure operators emphasizing the need to mitigate cybersecurity risks posed by third-party industrial control system (ICS) integrators. This advisory follows a significant 2025 breach involving a U.S. industrial automation provider, highlighting vulnerabilities in operational technology environments. The agencies recommend procurement professionals enforce stringent cybersecurity obligations in contracts with integrators, limit their access to sensitive systems, and implement robust security controls to protect critical infrastructure from similar threats.

- **Why this matters:** Procurement officers should incorporate explicit cybersecurity requirements and access controls in contracts with ICS integrators to reduce exposure to supply chain and operational technology risks.
- Organizations managing critical infrastructure must evaluate third-party integrator relationships and ensure compliance with FBI and CISA guidance to prevent potential breaches.
- This advisory signals increased federal scrutiny on ICS supply chain security, potentially influencing future contract terms and vendor selection criteria.
- Contractors specializing in industrial automation and cybersecurity services may find opportunities to support infrastructure operators in meeting these enhanced security expectations.

**Jurisdictions:** federal
**Industries:** Public Safety, Energy & Utilities
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** September 28, 2026

### Government Entities
- Federal Bureau of Investigation (FBI)
- Cybersecurity and Infrastructure Security Agency (CISA)

### Sources
- [FBI, CISA Warn of Third-Party ICS Integrator Risks -- Security Today](https://securitytoday.com/articles/2026/09/28/fbi-cisa-warn-of-third-party-ics-integrator-risks.aspx) - Security Today