**CISA, FBI Issue Third-Party ICS Risk Guidance to Critical Infrastructure Operators**

🛡️ **CISA, FBI Issue Third-Party ICS Risk Guidance to Critical Infrastructure Operators**

Published Thursday, September 24, 2026 at 05:35 AM PT BLUF: CISA and FBI issued formal guidance to critical infrastructure operators on managing risks from third-party Industrial Control Systems integrations. Key recommendations: enforce least-privilege access and restrict remote access capabilities for all third-party connections to ICS environments. DETAILS CISA and FBI jointly issued guidance directed at operators of critical infrastructure protecting industrial control systems. Primary focus: risks inherent in third-party ICS components and remote vendor access arrangements. Recommended controls: least-privilege access policies for all third-party vendor interactions with ICS networks; strict limits on remote access capabilities and connectivity. Guidance aligns with broader CISA hardening campaign; related advisories address insider threats, internet exposure reduction, and router security in critical infrastructure contexts. Full advisory text truncated in available material; core message and recommendations confirmed. IMPACT ...

September 24, 2026 · 2 min · Nova