Read this if somebody else programmed your machines. Somebody outside your company may be able to reach your plant floor right now without asking you. Whether that is true where you work is answerable without buying anything, and this post is how. In joint guidance published September 23, 2026, the FBI and CISA tell plant owners to be cautious about granting outside control-system integrators high levels of access, to apply least privilege, and to make remote support something an operator switches on where possible. The break-in behind it happened in spring 2025 and the guidance is only landing now. Per the FBI technical analysis inside that same fact sheet, foreign actors gained access to the network of a U.S. industrial automation firm between March and April 2025, a firm selling system integration, engineering consulting and SCADA programming. They searched it for terms including "customers" and "SCADA," and created nine .zip files of roughly 800 files the FBI describes as staged for presumed exfiltration: customer SCADA information, ICS device details and other schematics.
North Carolina had 11,496 manufacturing firms employing 467,325 people on 2024 federal labor data, and manufacturing was the state's second-largest industrial sector by GDP contribution, at about 15 percent in 2023 per NCMEP. That data says nothing about how many employ a controls engineer, so ask the narrower question about your own plant: who wrote the program on the press, and can they still reach it? Where the answer is an outside firm, ask the follow-up: who approved the way back in, and when? If nobody can answer from memory, the purchase order and the service file are where to look before you conclude anything. If nobody can produce the approval, what you have is an access path whose approval status is unverified, not a proven absence of one, and it belongs on the list either way until the records settle it.
Key takeaway: Where your integrator keeps a way in, their laptop is a door into your plant, and it is one you did not install and may not be able to see. Nobody is telling you to rip out remote support. The agencies want it to work like this: your operator turns it on, your system logs it, and the rules are in the contract.
Want a written list of every outside connection into your plant floor, and who is on the other end? Ask for a plant-floor access inventory: one line per cabinet, walked with your own maintenance tech. Preferred Data Corporation has been in High Point since 1987 and works with Piedmont Triad manufacturers. Call (336) 886-3282 or contact us.
Why break into the integrator instead of the plant?
Because the integrator holds drawings for the plants it has commissioned. Breaking into your shop gets them your shop. Breaking into the house that built your line gets them design data for the plants it serves, which in the FBI's case included power utilities and transportation.
Dragos tracked 119 ransomware groups hitting industrial companies in 2025, up from 80 in 2024, affecting 3,300 organizations between them, manufacturing more than two-thirds of the victims. Separately from that ransomware count, Dragos tracks a threat group it calls AZURITE that goes after the engineering workstation, exfiltrating alarm data, PLC configurations, HMI data and process information, and which it says defenders should treat as "active prepositioning for future destructive operations, not opportunistic intrusion." That workstation is the laptop or panel PC holding your PLC program, and on a plant with no controls engineer it can belong to the integrator rather than to you.
And 26 percent of industrial control system advisories in 2025 contained no patch or mitigation from the vendor, per Dragos. Where that is the case on your own equipment, nothing having been installed on that old HMI is not neglect: there was nothing to install. The same review puts average ransomware dwell time in OT environments at 42 days industry-wide, against an average of five days for organizations with comprehensive OT visibility. You cannot patch your way out of a plant floor, so who can reach the equipment is the control you have.
If your integrator were breached tomorrow, could you still ship?
Answer this one first, because it needs nobody else's cooperation. The agencies' advice: keep the ability to recover and operate without the integrator, especially for processes you cannot ship without, and "maintain secure, offline backups of all software required to operate equipment to facilitate system recovery." Then rehearse that recovery against your own documented manual procedure, with safeguarding intact, and account for where outside parties sit in it.
Two questions settle where you stand:
- If your controls house went dark today, who has a restorable copy of the PLC program for your two most critical machines, and when was it last loaded onto real hardware?
- Is there a written manual-operation procedure for the line, has anyone on the current crew been trained to it, and does that include second shift?
If the answer to the first is "the vendor has it," you do not have a backup. You have a phone number for a company in exactly the category the FBI has just shown can be broken into. Backup and recovery for a plant is a different job from an office: what has to be restorable is a program that runs steel.
"We do not use an integrator." Here is what counts as one.
You may well answer no to that, because the word may not appear anywhere on an invoice. The document describes an integrator as a vendor providing control system design, installation, operational data analysis, device support and service, or daily operational control. All of these qualify:
- The machine builder that commissioned the new press and left a VPN client on the HMI.
- The controls house that wrote and still holds the PLC program.
- The equipment maker with a cellular gateway in the panel for warranty telemetry, reaching the internet without passing your perimeter firewall.
- The systems house maintaining the historian behind your quality reports.
- The building-automation contractor on the HVAC and compressor room.
- The scale, vision or robot vendor who "just needs to get in" during a changeover.
This access can predate the current IT provider. A panel modem can go in on a commissioning weekend, installed by a technician who has since changed employers, with nothing written down. Start from the records you do have: monitored switch ports, vendor VPN accounts and asset discovery can fill in a real part of the list. The floor walk validates and completes them rather than replacing them.
What to have maintenance look for, from outside the panel
One line per machine, on one sheet. Every item below is visible without opening anything:
- A stub or whip antenna on the outside of the panel.
- Any network cable leaving the panel that does not go to the machine, especially one running to a wall jack.
- Whose sticker is on the panel, and the phone number on it.
- The machine number, so the list matches your asset register.
Inside the panel is a different job, and not yours. Do not open a control cabinet to chase this, and do not ask maintenance to. Opening one is qualified-person work under NFPA 70E, and a stopped machine is not a de-energized one. If you want the inside of a panel checked, raise it with whoever owns your electrical safety program and let them scope it into a planned shutdown under their own procedure. Everything this post asks you to do is outside the enclosure.
The outside pass is walking and asking, not a capital project. Do it before anyone quotes you anything.
Will switching off the builder's modem void my warranty?
It can, and nobody can tell you otherwise without reading your service agreement. On some equipment the telemetry link is tied to the warranty or the service contract, and that is worth checking first, because pulling it can hand the vendor a defense on a later claim.
So settle it before you touch anything: read what the agreement requires, ask the builder in writing whether reaching the machine over a route you provide and monitor satisfies it, get that by email, then change the connection. What a builder needs is reachability, not a private door.
Not sure which of your machines phone home, or under what contract? Call (336) 886-3282 and ask for the floor walk.
The four questions to answer before the next purchase order
The guidance frames these as risk-assessment questions. Treat them as purchasing questions: an answer you got on the phone is worth nothing once the salesperson has moved on.
| The question the agencies ask | What it is really testing | Where the answer has to live |
|---|---|---|
| What organizational data does the integrator store or have access to? | Your network designs, device specs and logs are useful to an attacker. | A named list you hold a copy of |
| Where is the data stored? | Whether your drawings sit abroad. If the integrator is foreign-owned and data is held internationally, the agencies note that country's laws may govern it even when the integrator is a U.S. subsidiary. | The agreement |
| Does the integrator have remote access for operational support? | Whether a break-in at their office becomes control of your equipment. | A written access record: route, account, approver, what is logged |
| Can the organization operate independently if the integrator is compromised? | Whether you can run and recover without them. | A tested procedure, plus offline copies of the software |
Eight clauses for the next equipment order
The agencies name seven areas for contracts and service agreements: data storage locations, information protection and protection of ICS data and design documentation; remote access capabilities; the integrator's own cybersecurity program; change and patch management policies; securing delivered components, such as changing default passwords and disabling unused ports; authorized personnel with access; and processes enabling local engineering support so integrator intervention is limited.
Here they are as eight clauses. Six track the agencies' contract areas and clause 4 implements their monitored, on-demand access step, but the seventh area is not covered below: add your own clause on processes that enable local engineering support, so integrator intervention is limited. Clause 2, the bar on activating an outside connection without written approval, is ours. Clause 5 is split: the restorable program copy is the agencies' own call for offline backups, quoted earlier in this post, while the warranty sentence attached to it is ours. This is a starting set rather than a complete contract, so have your counsel read the wording before it goes in one.
- Before handover, Seller shall provide Buyer in writing every item of hardware and software supplied, every remote connection Seller installs or uses, including any cellular, wireless or dial-up device inside a supplied panel, and the names of Seller personnel holding access, with notice within five business days of any change.
- Seller shall not activate any connection from supplied equipment to a network outside Buyer's plant without Buyer's prior written approval.
- Seller shall change all default passwords and disable unused ports before handover, and shall certify this in writing.
- Seller shall reach equipment only over a route Buyer provides and can monitor and log, and only when a Buyer representative has approved the session.
- Seller shall deliver the as-shipped PLC, HMI, drive and robot programs and configurations in a form Buyer can restore without Seller, with any passwords needed to load them, and Buyer's use of those files to repair or recover the equipment shall not void warranty.
- Seller shall state where copies of Buyer's programs, drawings and logs are stored, in which country, and how they are protected against disclosure.
- Seller shall describe its own cybersecurity program, including how it secures the machines its staff use to reach Buyer's equipment.
- Seller shall state its change management and patch management policies for the hardware and software it supplies, including how Buyer is notified of an update.
If your next machine order is a year out, the same terms go into the next service renewal with vendors already in the building.
None of it is a capital project, which is what makes it awkward to sell. Ask for help with this and what comes back may well be a network segmentation project, and segmentation is genuinely the right long-term answer. It is also, in our experience, a capital project that needs a shutdown window. Eight clauses and a phone call are not. Nobody can bill for the second version, including us, which is a reason to ask for it specifically rather than wait for it to be offered.
Always-on access versus access somebody has to approve
The agencies' wording is careful: monitor and log remote access, make integrators reach equipment by routes you can watch, and "use on-demand remote access if possible, so operators have to proactively allow remote access."
| Standing VPN or vendor modem | Access somebody approves | |
|---|---|---|
| Who decides a session happens | The vendor, at any hour | Your operator, in the moment |
| What a break-in at the vendor gets | A path that works without anybody at your plant acting | A request that goes nowhere until somebody at your plant acts |
| Evidence afterward | Whatever logging you required, wherever it lives | The same logging, plus a record of who approved this session |
| Cost to set up | Configuration and a conversation | Configuration and a conversation, where your vendor's platform supports it |
Look at the cost row. Now the objection. The problem is not that nobody is awake at 2 a.m. It is whether the person who is awake has been told they are allowed to let a vendor in. A shift lead who has not been told will not guess, and should not have to.
So name the approvers by shift, in writing, nights and weekends included, give each a way to approve from a phone in a noisy building, and decide in advance what happens if nobody answers in ten minutes. Skip that and the approval step fails at the moment you need it.
Who does what, and what the owner will ask
- Plant manager: walk the floor with maintenance, produce the list, name the approvers by shift.
- Owner: approve the clause language and settle the warranty question with the builder in writing.
- Whoever cuts purchase orders: add the clauses to equipment orders and service renewals.
- On cost: ask whoever you engage, us included, to scope the floor walk in writing before work starts rather than opening an hourly.
- On doing nothing: a national statistic will not move an owner. Three of your own facts will: what a week without your primary line would actually cost you, which is a number to work out rather than assume, whether your cyber policy already carries vendor-access conditions, and whether your automotive or defense customers already require this.
Frequently Asked Questions
Does this apply to a small manufacturer, or only to utilities?
A qualifying small plant is inside the addressed audience. CISA's Critical Manufacturing sector is defined by what you make rather than how many people you employ: primary metals, machinery, electrical equipment and transportation equipment, with no employee-count threshold in the definition. Outside it, your integrator is still the link.
Our machine has a cellular modem the builder installed. Is that covered?
Yes. It falls under the fact sheet's second step, which tells operators to work with integrators to understand where devices are hosted and to cut exposure by disconnecting them from the public internet. A cellular link out of a panel can reach the internet without passing your perimeter firewall, and it may be in no IT record at all. Do not assume it is invisible either: a gateway also wired to a monitored plant network can show up on a managed switch or in discovery tooling, so ask for that data before you rely on the walk alone. Find it, settle the warranty question in writing, then decide whether it stays, moves behind a route you monitor, or gets switched off.
How do we find out what the integrator actually installed?
Just ask, and give a reason they can accept. The fact sheet's fourth step is to request an inventory of all software and hardware the integrator supplied, plus documentation for how it connects to your network and how it gets updated. Sent to a vendor you have worked with for years, something like this gets answered where an audit letter does not. Use it only if it is true for you, because a vendor may ask which customer:
Our insurance renewal and a couple of our customers want us documenting every outside connection into the plant floor and keeping our own copy of the machine programs on site. This is not about your work, I just have to answer it on paper. Three things when you get a minute:
- Which machines here can you get into remotely, and how do you get in?
- Who on your end has that access?
- Can you send me a current copy of the programs for the press line?
If there is real time in it, tell me what it costs and I will get it approved.
For the wider method, CISA and partner agencies published asset inventory guidance for OT owners and operators. For the deeper standard, NIST has a draft fourth revision of SP 800-82 out for comment until November 30, 2026; Revision 3 is still the current final version.
Is any of this a promise that we cannot be hit?
No, and treat anyone who says otherwise as a sales risk. Ransomware that sits unnoticed for 42 days on average, per Dragos, is not defeated by a clause. What these controls change is how much one supplier's bad week costs you, and whether you can prove afterward who was on your network.
Our IT provider says the plant floor is out of scope. Now what?
That answer can be legitimate, because plant-floor work is a different discipline from desktop support. It is not a reason to leave the seam unowned. Put the boundary in writing: name who owns the access list, who approves a vendor session, and where the offline copy of the program lives. An unowned boundary between office network and floor is the kind of gap an OT assessment exists to surface.
Put it in the next purchase order, and walk the floor before you sign it. We do this work from High Point and come to your plant: Greensboro, Winston-Salem, Lexington, Statesville, Hickory, Charlotte, anywhere within 200 miles. Call (336) 886-3282, see our cybersecurity services, our network work, or manufacturers.
Related Resources
- Third-party vendor risk management for NC manufacturers
- CISA ICS advisories and plant-floor OT defense, for an advisory with no patch
- SCADA security for NC manufacturers, the layer an integrator may own
- Network segmentation for NC manufacturers, the long answer this post says not to wait for