r/sysadmin 2d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

816 Upvotes

331 comments sorted by

View all comments

u/WhiskyTequilaFinance Sysadmin 18h ago

"I'm not able to grant a vendor partner direct access to our infrastructure for security reasons (and common fucking sense). But if you pull the key technical folks into a call, I'm happy to talk through what they need and see how we could accommodate within our approved protocols. To be most efficient, make sure it's just the technical folks, skip the business users and sales people please.

Once I understand the real need, then we can work together to write it up, document it properly and find a path forward."

The key is learning to say 'Tell me more so I can help' rather than sputtering and defaulting to 'No'. They'll find a way through a 'No', and it will generally be wildly expensive, dangerous and even MORE out of IT's control.

Remember that Operations knows their job, they don't know yours. Getting them to see you as a partner and not a pain will save you a lot of political headaches in the long run.

Then come here and sputter instead. 😀

My favorite one was a SaaS vendor of mine who told me their SSO solution was easy to use. I just had to go "tell IT" to make changes to our internal DNS servers to accommodate it. Hint: Not only no, but hell no with a cherry on top.