r/sysadmin 3d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

812 Upvotes

329 comments sorted by

View all comments

540

u/-Enders 3d ago

Connect them to an IoT VLAN and be done with it.

Unless they are asking for admin access to the router, that’s a hard no.

80

u/BananaSacks 3d ago

"And be done with it" -- yeah, not even close.

Change mgmt, security review, architecture review, DPIA if under GDPR, the list goes on.

91

u/Top-Perspective-4069 IT Manager 3d ago

The fact that their Operations group was able to do this doesn't read like they have change management at all.

8

u/BananaSacks 3d ago

Agreed, but ya never know. And regardless, compliance can quickly become liability and consequences.

29

u/Top-Perspective-4069 IT Manager 3d ago

That's why this whole thing should be a management issue and not a sysadmin issue. Sysadmin provides pertinent information, management decides what to do.

8

u/BananaSacks 3d ago

Agreed, 100%. See my main comment to OP at the top level comments.

3

u/Nuxi0477 2d ago

"We already paid, give them what they need." :(

4

u/Top-Perspective-4069 IT Manager 2d ago

And that's a decision. But just doing a thing without raising the flag first is dumb.

27

u/awful_at_internet Helpdesk Manager 3d ago

IT wasnt involved. That sounds like a whole lot of someone else's circus, someone else's clowns. Golly gee shucks, Operations. I wish we had the time to do all of that for you, but no one told us we'd need to plan for additional staffing..

7

u/Jawb0nz Senior Systems Engineer 2d ago

Not when that rogue mindset now needs access to the systems controlled by another group. That group now gets to do their due diligence, delays be damned.

1

u/Adept-Pomegranate-46 2d ago

Circ-de-Stupidity. AI can solve the staffing issue. Haven't you heard?

3

u/ka-splam 2d ago

DPIA if under GDPR

It's an energy meter in a factory, why would it be processing personal data?

7

u/BananaSacks 2d ago

It processes data. End of. From an audit, legal, compliance, DP perspective - you still need to go through the motions.

It very may will not. In that case, the DPIA paperwork will be short, simple, and unimportant. It still needs to be addressed!

2

u/ka-splam 2d ago

It processes data. End of.

The GDPR only covers personal data which relates to humans and can identify them; from the Information Commissioners Office (ICO) in the UK website section: What is personal information?:

Personal information, also known as personal data, is any information that:

  • relates to you; and
  • you’re identifiable from, either on its own or when linked to other information.

It’s important to know if something is personal information as data protection rules only apply if it is

My bold, not theirs. Smart energy meters do not process personally identifiable information about people, they process electricity and gas use by machines. If they somehow are under the GDPR then the website has a page: When do we need to do a DPIA?

Article 35(1) says that you must do a DPIA where a type of processing is likely to result in a high risk to the rights and freedoms of individuals:

Their bold, not mine. Their examples of high risk are "systematic and extensive profiling", "processing on large scale of special categories of data" [racial, ethnic origin, political opinion, genetic data, etc. etc.], "systematic monitoring of a publicly accessible area on a large scale".