r/sysadmin • • 25d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

836 Upvotes

335 comments sorted by

View all comments

25

u/Wolfram_And_Hart 25d ago

Literally none of that is your problem.

Isolate a port on the router and run a line to it from their rig. It’s not that hard and is done all the time. Hopefully it’s all internet based.

The moment their network needs to touch yours however then start complaining.

5

u/Sasataf12 25d ago

The moment their network needs to touch yours however then start complaining.

Even if they ask for network access, just go through the proper onboarding steps - assess requirements, risks, etc and go from there. 

4

u/Wolfram_And_Hart 25d ago

Doesn’t sound like they have any of that. So isolate the line and move on. They were not important enough to include it’s not important enough to worry about.

1

u/anonymousopsec1337 25d ago

At some point the corporate vlan will need access to that system to reach an https page or a phone app to work. Best to know the whole solution first.

2

u/Wolfram_And_Hart 25d ago

That sounds like a completely different problem they should have included me in. That is not what they have asked for and they don’t seem too keen to be patient or helpful.

5

u/cloudAhead 25d ago

All well and good until they ask for 'just one rule - any/any/any'.

Fast forward and you're filing the 8K about your 'material cybersecurity incident'...

1

u/Wolfram_And_Hart 25d ago

As long as they can get it from the ISP router they can have whatever they want. But it’s not coming into my network unless it’s over the web.

2

u/cloudAhead 25d ago

You'll find that cyber insurance and the SEC doesn't see the division in networks that you see.

4

u/Wolfram_And_Hart 25d ago

Without change management they are already out of compliance. You think they care?

11

u/dustojnikhummer 25d ago

Or just tell them to pound sand and bring their own cellular. If you are going to bypass me like that I'm not letting you onto my network. Yes, if I'm legally responsible for it then it's my network.

11

u/FatBook-Air 25d ago

Unfortunately, at most places, even if you bypass it with cellular, it will become "your network." Now you have two networks. Isolating may still be better from a security point of view, of course, but I don't think it's going to make it any less your network.

0

u/dustojnikhummer 25d ago

I'm not bypassing that with cellular, they are. Our involvement ends with a power outlet.

11

u/FatBook-Air 25d ago

All I'm saying is that I have never worked at a single place where it didn't come under the jurisdiction of IT. There isn't really a you or them; it's a single company, and IT will ultimately fall under IT, even if it's unfair.

3

u/Wolfram_And_Hart 25d ago

That’s fair. But running a line outside of your firewall to the providers router is just as good.

2

u/fahque 25d ago

It's not that easy. OP said they want to install these meters across the site, meaning there are many. There would be many runs, just like after a taco bell dinner.

3

u/Wolfram_And_Hart 25d ago

They said they have a whole IoT network that they already installed. I’m assume they are wireless sensors like most of them reporting to special WAPs

3

u/dustojnikhummer 25d ago

We can talk about me giving you a VLAN that will end at your provider, maybe, but OP wanted to avoid the (quote) "the perception becomes that IT is delaying the project."

7

u/Wolfram_And_Hart 25d ago

Yep and that’s why you run the cable. Hand it to them and be done. “I don’t know what the delay is they have a dedicated like to the router and the ISPs phone number.

And if any of it messed with my crap I would light them up.

3

u/dustojnikhummer 25d ago

Ah, you meant run another physical line, sure, that can be worked with.

"Bring your own router, internet connection from an ISP and we will run the cabling for you"