Operations has purchased and started deploying an IoT-based energy monitoring system across a large factory without involving IT. The project apparently has no agreed design for device connectivity, switches, cabling, VLANs, OT/IT segmentation, servers or virtual machines, databases, backups, monitoring, internet access, vendor remote access, firewall rules, or cybersecurity responsibilities. IT was simply asked to provide "access to the router" so the vendor can bring the system online. How would you handle this technically and organizationally without giving a third party access to a corporate firewall or placing unknown industrial devices on the production network?
4 Answers
Use this incident to fix the project process. Technology purchases should require IT, security, privacy, legal, and sometimes facilities or OT participation before contracts are signed. Add network and security requirements to procurement, require an approved change request and implementation plan, and assign a product owner who coordinates with the vendor. For the current project, cooperate where possible, but provide only least-privilege connectivity and keep every decision and exception documented.
If the vendor only needs independent internet connectivity, a separate business connection and router can keep the system completely outside the corporate and factory networks. That may be a reasonable temporary containment option, provided management understands the trade-offs and the vendor owns the equipment and service. Do not allow a separate connection to become an excuse for unmanaged remote access or a later unreviewed connection back into the company network.
Escalate this as a management and risk-acceptance issue rather than letting it become an argument between Operations and the IT technician. Put the concerns in writing, explain the red lines, and offer a safe path forward. If leadership insists on accepting the risk, the authorized executive should explicitly approve that decision and it should be recorded in the risk register. Also make it clear that IT cannot be accountable for an unsupported design that was purchased without its involvement.
The message should be framed as “we need time to implement the required security and reliability controls,” not simply “IT is blocking the project.” That keeps the focus on protecting the business while still being cooperative.
Treat direct router or firewall access as a hard no. Start by getting the vendor’s architecture, device list, required destinations, protocols, ports, authentication model, support process, and remote-access requirements. Then put the system in a dedicated, isolated VLAN or OT segment and allow only the minimum required traffic through ACLs or a firewall. Keep it separate from production and avoid exposing management interfaces to the internet. Document who owns support, security, backups, and incident response.
An isolated VLAN is only a starting point, not the whole change process. Security, architecture, privacy, risk, and change-management reviews may still be required before anything is connected.

A cellular or standalone connection can be useful for containment, but it should not replace proper oversight. The vendor still needs to provide security documentation, patching responsibilities, logging, and a remote-access design.