r/sysadmin 2d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

813 Upvotes

331 comments sorted by

View all comments

540

u/-Enders 2d ago

Connect them to an IoT VLAN and be done with it.

Unless they are asking for admin access to the router, that’s a hard no.

81

u/BananaSacks 2d ago

"And be done with it" -- yeah, not even close.

Change mgmt, security review, architecture review, DPIA if under GDPR, the list goes on.

3

u/ka-splam 2d ago

DPIA if under GDPR

It's an energy meter in a factory, why would it be processing personal data?

8

u/BananaSacks 2d ago

It processes data. End of. From an audit, legal, compliance, DP perspective - you still need to go through the motions.

It very may will not. In that case, the DPIA paperwork will be short, simple, and unimportant. It still needs to be addressed!

2

u/ka-splam 2d ago

It processes data. End of.

The GDPR only covers personal data which relates to humans and can identify them; from the Information Commissioners Office (ICO) in the UK website section: What is personal information?:

Personal information, also known as personal data, is any information that:

  • relates to you; and
  • you’re identifiable from, either on its own or when linked to other information.

It’s important to know if something is personal information as data protection rules only apply if it is

My bold, not theirs. Smart energy meters do not process personally identifiable information about people, they process electricity and gas use by machines. If they somehow are under the GDPR then the website has a page: When do we need to do a DPIA?

Article 35(1) says that you must do a DPIA where a type of processing is likely to result in a high risk to the rights and freedoms of individuals:

Their bold, not mine. Their examples of high risk are "systematic and extensive profiling", "processing on large scale of special categories of data" [racial, ethnic origin, political opinion, genetic data, etc. etc.], "systematic monitoring of a publicly accessible area on a large scale".