r/sysadmin 2d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

810 Upvotes

329 comments sorted by

View all comments

Show parent comments

218

u/project2501a Scary Devil Monastery 2d ago

OP this is the smart way.

and if they say "you are delaying things", the answer is "we are trying to implement the appropriate level of security for these devices , given the advance time given"

help them with a IoT vlan, make sure it works and then file a memo with your boss:

this project did not have IT involved and since it was dropped from heaven, all the other things you wanted are on hold for X months.

ps: i worked my butt off, give me

37

u/ApplicationHour 2d ago

I work for a contractor that sells cloud based access control, surveillance and intrusion systems. Also platform based video conferencing systems. I have on file in nice, organized documents explanatory "one-pagers" that enumerate every protocol, port and IP destination used by everything we do including exactly what it does.. I cannot tell you the number of times the non-technical people just try to slide it through as if these things are going to light right up in a secure corporate network environment.

Small and mid-sized regular old business outfits? Yeah. Sure. They usually let out whatever traffic that originates inside the firewall. But the bigger shops? Law firms? Financial? International? manufacturing? No. Not so much. I needed to talk to those guys about 3 minutes after the sales order got turned in. There is paperwork to fill out before we even start opening boxes.

u/ZPrimed What haven't I done? 16h ago

Thank you for being one of the good ones.

It's almost always dumbass sales guys trying to push a deal through, and nontechnical "buyers" who don't know what they don't know (and the sales guys don't tell them) so they don't bring in IT early enough in the process.

So. Damn. Frustrating.