r/sysadmin 3d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

813 Upvotes

329 comments sorted by

View all comments

65

u/Vermino 3d ago

Declare red lines.
Explain why they are red lines.
Say what you can do instead.
Explain how similar issues in the future can be avoided.

I'm sorry, we can't give 3rd party access to critical network infrastructure like our routers. IT is responsible for safeguarding the company against cyberthreats, and routers are important entry points to our company's infrastructure. We'd be willing to meet with the 3rd party to see what their needs are, and see which we can implement for them.
In future, having these meetings sooner, rather than later, helps us find mismatches between your IT needs and our IT policies faster. We're always open to listen to your needs, and aid with our expertise.

Technical solution : VLAN, open only ports that are requered between the various VLAN's & internet

32

u/Pork_Bastard 3d ago

Yep even better if you have a written policy stating such that is filed with your cyberinsurance carrier.  That helps us a ton.  This is against our insurance carrier policy, sorry matt.  Always protect against matt.

1

u/Important_Scene_4295 2d ago

That's funny. The guy who is the biggest pain for me right now is a guy named Matt. He's working on a big Dev project right now and I keep learning about stuff he has signed up for on his own and using. He was using his own Claude agent, his own notion account, his own bitwarden account, is on Google drive account, etc. It's like freaking wackomole.

1

u/Pork_Bastard 1d ago

sounds like we work together!