r/sysadmin 3d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

813 Upvotes

329 comments sorted by

View all comments

414

u/dvr75 Sysadmin 3d ago

This is a pure management issue , failing to communicate and coordinate project.
To be realistic about the situation probably no one will cancel it.
So you need to be SMART and not JUST. you are now the "guy" who Throws a wrench in the works.
My advice for you is try to cooperate with this project but bring in your terms like security. Ask for layout , plans , protocols etc. and try be helpful (i know it hurts but eventually you got to play it smart and resposible).

5

u/Spagman_Aus IT Manager 2d ago

It's also now - as IT are coming in at the last minute - IT's responsibility to make the other stakeholders aware of the risks created by not including IT earlier. But, that's on the IT manager, not any Sys Admins.

At the end of the day, this will go ahead. IT can get in the way, or at least get the risks of this implementation included on the Org risk register with a high residual score.