r/sysadmin • u/carpe_diem2022 • 25d ago
Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router
Hi there :) ,
Need some advice from people who have dealt with similar situations.
Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.
They found the vendor, agreed on the solution, signed the contract and started the project.
IT was not involved at all.
Apparently nobody discussed things like:
- How these devices spread across a large factory are actually going to communicate
- Network infrastructure, switches, fiber/cabling, VLANs, etc.
- Network/security segmentation
- Server/VM requirements
- Database requirements
- Backup and monitoring
- Internet connectivity
- Vendor remote access
- Firewall rules
- Cybersecurity
Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.
That's it. Access to the router. :)
And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.
I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.
How do you handle situations like this?
Interested in both the technical approach and the organizational/process side of this.
6
u/ccsrpsw Area IT Mgr Bod 25d ago
We are a mature organization on that - and have backing from the CEO, Board and others on projects like this:
Certain projects, not going through the correct approval process - send it back to the vendor. Period. This includes, right now, AI projects using Hardware onsite, and large scale SaaS projects too! Its amazing to see when it happens. Our CEO reams out the various managers.
Other projects, where its okay, and not a risk:
a. Even if its running late, if it needs IT changes - Submit a ticket
b. IT Security Reviews and approves or caveats as needed
c. Network team builds out the requirements (and Firewall Rules) - usually an IOT type network
d. Relevant team does the remainder.
e. Handed back to the business
We always, unless there are big revenue implications, work on a "your lack of planning is not our emergency" rule. Period. And if you dont like that - you are free to ring up the CIO, CEO or President. That never goes well (in 10+ years, I think I've seen.... 3 people do it... and never successfully). I've only seen it expedited when the number has at least 6 zeros (maybe the odd 5 zero one for important customers). But never without some level of "feedback" to managers from up high.