r/sysadmin 1d ago

Question Operations bought an EMS/IoT system without involving IT — now they just need “access to the router

Hi there :) ,

Need some advice from people who have dealt with similar situations.

Our Operations Dept decided to install IoT system/digital energy meters across a fairly large factory site.

They found the vendor, agreed on the solution, signed the contract and started the project.

IT was not involved at all.

Apparently nobody discussed things like:

  • How these devices spread across a large factory are actually going to communicate
  • Network infrastructure, switches, fiber/cabling, VLANs, etc.
  • Network/security segmentation
  • Server/VM requirements
  • Database requirements
  • Backup and monitoring
  • Internet connectivity
  • Vendor remote access
  • Firewall rules
  • Cybersecurity

Now that the project is already moving forward, IT gets an email saying they need “access to the router” so they can put the system online.

That's it. Access to the router. :)

And somehow, when IT starts asking questions about architecture, security, server requirements, ports, protocols and who is responsible for what, the perception becomes that IT is delaying the project.

I don't want to become the guy who simply says “No”, but I'm also not going to give a third-party vendor access to our corporate router/firewall and connect a bunch of unknown industrial/IoT devices to the production network just because someone already signed a contract , the IT network must be always separate from OT network.

How do you handle situations like this?

Interested in both the technical approach and the organizational/process side of this.

775 Upvotes

318 comments sorted by

View all comments

Show parent comments

2

u/GingerPale2022 1d ago

This just kicks the can down the road and implies that anything in the future is fair game. Reality and experience tells me that this poor soul will be told to “just do it”, but stinks need to be raised, at the very least, to them give pause for something like this in the future. At the bare minimum, it shows someone’s paying attention to the stewardship of the company’s infrastructure security.

Like I said, it probably won’t amount to squat and one does need to pick their battles, but rolling over and just tossing them in a VLAN and being done with it sets a precedent that will cause SO MUCH heartburn in the future.

1

u/-Enders 1d ago

What can is being kicked down the road? You should already have an IoT VLAN built out, I’d question anyone’s network that doesn’t have this built out already.

They absolutely should have checked with IT first, so tell them that in an email and CC the appropriate people.

“Hey Operations, I got this connected to the switch and the IoT VLAN, so you should be good to go. In the future, blah blah blah”

It’s really not hard to be firm and assertive without coming off as difficult to work with. Too many people let their egos get in the way though

1

u/GingerPale2022 1d ago

OP’s post had a vibe that an IoT VLAN isn’t set up, but that just an assumption I’m making. The can being kicked down the road is not holding something like this accountable. It’s not being difficult to work with in nipping this kind of stuff in the bud. Of course, it usually falls on deaf ears, but at the very least, having a conversation about shadow IT like this sets a precedent on IT’s side that it’s being watched and noted, even if there’s no teeth in those conversations. This way, when something goes sideways and they blame IT, you’ve got history to lean on that you’ve addressed things like this multiple times in the past.

1

u/-Enders 1d ago

You said adding it to the IoT VLAN is kicking the can down the road, which implies you’re saying to NOT add it to the VLAN, which also means you’re not helping them and thus you are being difficult. I’m saying to help them first, and then also address the problem of them not checking with IT before they buy these things.

This isn’t a difficult problem and doesn’t require a difficult solution. Research it, make sure it’s safe, and then do what they’re asking you to do. Shoot them an email saying it’s done, and also letting them know in the future they need to talk with IT about this before any purchases are made(explaining why, and lean hard into the security risks it can pose). CC your supervisor, their supervisor, and depending on the size of the company I’m CCing the CEO too. You’ve helped get them online quickly, addressed the issue and informed the higher ups of what happened in a way that leaves a paper trail. You’re golden at this point.

If the same people continue to do it after the email, then you can start being difficult to work with and push back on it.

1

u/GingerPale2022 1d ago

I see where you think I said that because I wasn’t clear enough in my original statement. “Be done with it” after adding to IoT is the kicking of the can. Not following up is the issue I had. Sure, digging heels in and not helping at all is counterproductive. Not rattling some cages after helping is counterproductive, too, because it encourages future behavior to continue. I know I don’t want to be caught by surprise each time someone decides to go outside IT and then dump it in my lap to support it.

I see your point of following up after the fact. It wasn’t entirely clear in your first statement (or I just missed it).

u/-Enders 21h ago

That’s fair, I did say be done with it. I meant just the work, but I wasn’t clear so that’s my bad