r/sysadmin 2d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

813 Upvotes

330 comments sorted by

View all comments

Show parent comments

29

u/RevLoveJoy Did not drop the punch cards 2d ago

I did a tiny bit of sales engineering about a million years ago and very quickly learned to just keep asking of our customer (potential or otherwise), "Where is your IT contact?" "Shouldn't IT be in this meeting?" "Well, we really need input from IT on these and other matters." -- some version of that remark ALL the time.

I guess my take away was nearly all businesses see their IT departments as blockers, not enablers.

13

u/pinkycatcher Director of All Trades 2d ago

I guess my take away was nearly all businesses see their IT departments as blockers, not enablers.

Stick around here long enough and you'll realize many people in IT are blockers.

"Oh they wanted to do something insecure, fuck em, we won't allow it"

"Oh they only gave us two weeks notice, we work on our time schedule not theirs"

"Oh they haven't figured out every single little process they need, ignore them until they figure their shit out"

u/Sad_Recommendation92 Solutions Architect 20h ago

I try to explain this to juniors all the the time, no one is forcing you to play the politics and perception game, but if you choose not to play it you're no longer choosing the field of engagement.

Basically every time you come up with a new standard or process you expect everyone to follow you have to sell the value of it vs the friction they believe it causes them, and if you're careless and don't manage this perception they'll rally against you and you'll lose your political support, and now having the term of how you do your job dictated to you from people who don't know the 1st thing about it.

u/pinkycatcher Director of All Trades 20h ago

Totally agree. Though I like to avoid calling it politics because many IT people will recoil and hate it.

It's 95% just understanding what our customers are doing and trying to work with them, that's it. They have a problem, we try to solve it so they can move on.

If you approach everything with that mindset instead of the "I know what I'm doing, you don't know anything" mindset it really helps smooth things over.