The Integrator Still Has a Way In
Key Intel / TL;DR
  • Every OT security model assumes you know what connects to the plant network, and the integrator's remote link is usually not on the diagram.
  • These connections were installed for legitimate support reasons, by people doing their job, and outlived the contract that justified them.
  • The connection is frequently cellular, which means it bypasses your firewall entirely and never appears in network monitoring.
  • Walk the cabinets and look for hardware that does not match, because the inventory will not tell you and neither will the vendor.
  • Replace standing access with access you grant per visit, and make the vendor ask, because the ask is the control.

Walk an industrial control cabinet at almost any plant in the Valley and you will eventually find a small box that does not match anything else inside it. It is newer than the terminal blocks around it and made by a different manufacturer, wired in neatly by somebody who knew what they were doing, with a short antenna stub and no label.

That box is a cellular gateway. An integrator installed it during commissioning so they could dial in and troubleshoot without driving out, which was a completely reasonable thing to do at the time. It has been there for six years. Nobody in your IT department knows it exists, because it never touched your network.

The Diagram Is Not the Estate

We have written a fair amount about securing operational technology, including the Purdue model and the practical work of protecting PLCs and SCADA networks. Those pieces are correct and they describe an architecture with defined levels, defined conduits between them, and a clear boundary at the top.

They assume you know what connects to the plant. That assumption is where the whole model rests, and it is where these connections quietly sit outside it.

A cellular gateway in a control cabinet does not appear in your network diagram, because it is not on your network. It does not show up in firewall logs, because it never crosses your firewall. It carries no agent, generates no NetFlow you collect, and answers to a carrier account somebody else pays. You could run a full internal scan every night for a year and never see it.

The Purdue model draws a boundary at the top of the stack. This connection enters at the bottom.

How It Gets There, and Why Nobody Was Wrong

Nobody smuggled this in. Understanding how it arrived is what tells you where else to look.

A production line gets commissioned. The contract includes remote support, because remote support is cheaper than a truck roll and the machine builder is four states away. The integrator’s engineer needs a path to the controller, and the plant’s IT group either cannot provide one inside the schedule or does not want the liability of opening it. So the integrator brings their own connectivity, which is a cellular modem they buy by the dozen, and the problem is solved in an afternoon.

The line goes into production and the warranty period ends. The support contract lapses or gets renegotiated with somebody else. The engineer who installed it moves on. The box keeps working, because cellular modems are reliable and nobody has a reason to touch it.

Now count what is still true. The integrator’s platform can still reach a controller on your plant floor. Their credential list is whatever it was six years ago, and their offboarding process governs who on their side still has access. That company has since been acquired twice.

What Makes This Different From Ordinary Vendor Risk

Most third-party risk gets managed through the contract, and this category does not respond well to that, for three reasons worth separating. Each one changes where you have to go looking.

It is physical, so it is found by walking. The evidence is a box in a cabinet, and no software inventory will produce it. That makes this a converged problem in the literal sense: the finding comes from a physical walkthrough and the consequence is a cyber one.

It reaches equipment that moves. A compromised office endpoint is a data problem. A compromised controller adjusts a setpoint on machinery that is capable of injuring somebody, which is why the same site that has a machine guard bolted onto every press has an unexamined remote path to the logic controlling it.

The vendor is not the threat. Almost nobody in this picture is acting badly. The exposure is that a small integrator with eleven employees and no security function holds standing access to your plant, and their credential hygiene is now your risk. This is the cyber poverty line problem sitting directly on top of physical equipment.

Find Them, Which Means Walking

There is no scan for this. The discovery method is a person with a flashlight, and it takes a day.

Open every control cabinet and photograph the inside

Every panel on the floor, including the ones belonging to equipment nobody has opened since installation. You are looking for anything with an antenna, anything with an ethernet port that does not lead where the rest of the wiring leads, and anything whose housing does not match the vintage of what surrounds it. Photograph it all, because the photographs become the baseline you compare against next year.

Ask Maintenance Before You Ask IT

The people who keep the equipment running know which vendor dials in, because they are the ones who call and ask them to. Ask which suppliers provide remote support, how they connect, and who they phone when a machine faults. Twenty minutes with a maintenance supervisor produces a better list than a month of network analysis.

Read the original commissioning contracts

Remote support provisions are written into the purchase agreement for the equipment, which sits in procurement and not anywhere security would think to look. The contract will frequently describe the connection method in enough detail to tell you what you are looking for before you find it.

Check the phone bill

Cellular gateways sit on an account that somebody pays every month. If the integrator pays it, you may never see it. If your organization pays it, the line item is in accounts payable under a description nobody has questioned in years.

Fixing It Without Stopping the Line

The instinct is to disconnect everything you find, and that instinct will take a production line down and make security the department that stopped the plant. The sequence matters.

Inventory before you disconnect. Write down what each connection reaches and who uses it, and confirm with maintenance whether it is live. Some are genuinely dead and can be pulled the same day, which is a fast and satisfying start.

Give the legitimate ones a supervised path. Where a vendor genuinely needs remote support, route it through a jump host you control, with session recording and an account you own, and turn off their independent path. Our secure remote access guide covers the mechanics, and the OT variant differs mainly in that the session should be attended by somebody on your side.

Replace standing access with access on request. The vendor calls, you enable the path, they do the work, you disable it. This sounds like friction and it is the entire control, because a connection that requires somebody to ask produces a record of every time it was used and a conversation when the reason is thin.

Write the removal into the next contract. Every new piece of equipment arrives with a remote support clause, and that clause is negotiable at the point of purchase and almost impossible to change afterward. Specify the connection method you will accept before you sign.

The Part Worth Saying to a Plant Manager

The reason this gets deferred is that it reads like an IT problem arriving to complicate a working production line, and the person being asked to care about it is measured on uptime.

So the argument that works is the one about who can reach the machinery. A remote path into a controller is a person you have never met being able to change how equipment behaves while your operators are standing next to it, and the OT security guidance that covers this treats it as a safety concern and not a data one. That framing is accurate and it is also the version a plant manager will act on, because it is the same reasoning behind every guard and interlock already on the floor.

If you want an outside read on what still connects to your plant, contact Grab The Axe, and we will start by opening cabinets instead of asking for a network diagram. You can also take our free Human Attack Surface Score to see where the people-shaped gaps sit.

Dusten Trounce is Director of Physical Security at Grab The Axe.

Distribute Intel
Dusten Trounce
Director of Physical Security
Dusten Trounce
The Growth Architect.

A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability. He leverages high-logic strategies to pinpoint high-ROI vulnerabilities, ensuring defense measures actually scale with the business.

View Author Page →