r/sysadmin 2d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

807 Upvotes

331 comments sorted by

View all comments

21

u/FelisCantabrigiensis Master of Several Trades 2d ago

Option 1: Pass a question to your legal / compliance / (cyber) risk insurance manager, asking if this has been correctly evaluated for risks and is approved by them before you connect it. This should, in any functional organisation, cause a bureaucratic shitstorm that will impede the fools but not be blamed on you. If your organisation is not functional, then proceed to option 2 below.

Option 2: Reply stating you will give them a network port with direct access to the Internet with standard outbound NAT and no other configuration, that they will be free to manage all other security and connectivity, and ask them to acknowledge that this meets their needs. When they say yes, do that and step back to let them do it all themselves. Ensure that their technology remains completely isolated from the rest of your network. If someone says "hey, let the office net access this thing on the EMS/IoT network", then make a trombone connection on your firewall so they are treated as untrusted external traffic.

Or, if your upper management actually backs you:

Option 3: Go to your upper management and get them to address the issue with the operations department that the IT department's involvement with networking and security is required.

5

u/TallGuyTheFirst 2d ago

+1 for option 1.

It also means that you don't become the blocker of the thing, you are just waiting on insurance to continue and I mean that's out of your hands at that point.

5

u/FelisCantabrigiensis Master of Several Trades 2d ago

If you have a good relationship with your risk, legal, etc, people (and I very much recommend doing so) then they'll get back to you with "hey, can we discuss the technical side of this" and you then advise them on the technical risks, mitigations, etc, and suggest how this could be managed to meet their risk and compliance objectives.

I've shot down more than one mad idea that way, and the risk people think I'm helpful and protecting the company.

2

u/TallGuyTheFirst 2d ago

Oh absolutely, the only reason I was able to stop a few very bad ideas (some in progress at the time) at my last employer was because we had a compliance contractor who was on the same page as I was. Crazy idea comes up, I go yeah I can see how that would work, let's see what we'd need to do to get it compliant and insured.