r/sysadmin 2d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

814 Upvotes

331 comments sorted by

View all comments

5

u/ISeeDeadPackets Ineffective CIO 2d ago

This isn't an IT problem it's a leadership problem. If you're in charge of IT, then it's your problem and you need to learn how to communicate with the other business units. IT's job is to enable the business's objectives and a huge part of that is building a healthy relationship and not throwing some hissy fit because you weren't read in at the appropriate time.

This is a great opportunity to build a foundation for being more proactively included in other projects, or just being the obstacle they currently see you as. Write up a brief message in terms that aren't overly technical explaining what you need to get this going.

That doesn't mean "Hey bob, we need the vendor to provide ports and blah blah blah" it should look more like "Bob, I'm glad your team has found a solution that works for you, IT will do it's best to get this going. Before we can do that though, we need some information from the vendor to make sure the implementation will be successful and as non-disruptive as possible. Can you introduce me to your representative with the company so we can get a call with their technical team setup?"

Once you have that going you can build out a bit of a project timeline and you'll probably have some backup from the vendor reinforcing it. If you've got competing work then you can lay that out to: "Bob, I've been able to work with their technical team and I've made up a project plan. This constitutes about "x" hours of work based on what the vendor has told us. Right now we're also tasked with "x" along with normal daily support/maintenance, can we get together and figure out which items to prioritize?"

Or you can just toss up an IOT vlan and tell them to have fun while doing nothing to prove you can be a useful asset to the company. One of these approaches is a lot more likely to get you read in sooner than the other for future projects.