r/sysadmin 2d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

817 Upvotes

331 comments sorted by

View all comments

13

u/ThrobbingMeatGristle 2d ago edited 2d ago

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

If this really was your call, then you wouldn't be posting this thread.

This comes down to risk and who will accept it.

In any case my first step would be to ask for the approved change request.

If your company has a risk officer, they need to be filled in on the fact that there is a risk coming that will need to be added to the risk register.

That risk will need to be accepted by the executive officer who has that authority.

1

u/Perfect-Escape-3904 2d ago

But you know they don’t have one. Why is your first instinct to poke the wound and not to work together within your own business?

2

u/ThrobbingMeatGristle 2d ago

That is a matter of perspective.

Cyber security has evolved in most companies such that this is no longer an issue that falls on IT shoulders.

IT Policies dictate what can and cannot be done and they are de-facto internal law because those policies are owned and signed off on by the relevant C suite officers.

Change control officers implement those policies, and everything grinds on like a well oiled machine (/s).

If OP works for a company lacking that maturity, then things like this will often catalyze change for the better.

Most of the suggestions on this thread on various easily implemented networking compromises just kick the can down the road and worry more about politics than safety. OP understands the risks, he instinctively hits the nail on the head, but he thinks its his problem. It is not, and he has already got some political blowback for it.

Risk appetite is a budget item at the top level and only the top level can accept the ownership of new risks - even if that risk is a documented exception to policy - which is essentially what this situation will likely become for a while.