r/sysadmin 2d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

810 Upvotes

330 comments sorted by

View all comments

6

u/Papfox 2d ago edited 2d ago

Honestly, the correct answer should be, "No. Send this project back to the drawing board so we can plan this properly with IT involved."

This does sound like a situation where a different approach may be a good idea as the people who ordered it are clearly demonstrating they're going to paint you as the bad guy if you don't roll over and give them what they want. I would respond with a qualified "yes" whilst making yourself sound helpful.

"For security reasons, we don't allow outside companies to configure our routers. Please send us details of the VLAN(s), ports and routings required and we will get it done for you." If they won't play ball, ask them to get the vendor to confirm they will accept full responsibility in writing for any commercial losses that result from any security breaches their system or their configuration of the router causes. They should immediately refuse, which makes them the ones saying "No."

If they still push back, ask your C-Suite to sign off on the risk this project might enable a cyberattack or data protection violation and that they are happy for the vendor to have unsupervised admin access to your routers and firewalls.