Managing Contractors With Access to Utility SCADA Systems

Published May 13, 2026

The utility manager at a mid-size water district in the Southeast asked us a straightforward question last year: “Who actually has access to my SCADA system?” The question came after a peer utility experienced a cybersecurity incident traced to a former integrator’s lingering credentials.

Getting him a complete answer took three days of investigation. The final list included:

  • The current SCADA integrator (two engineers with active accounts)
  • The previous SCADA integrator, whose credentials had not been disabled when the contract ended 18 months earlier
  • A control system OEM (original equipment manufacturer) with a cellular-based remote access gateway the utility knew about but had no visibility into
  • An HMI (human-machine interface) software vendor with a support VPN account
  • Two former utility staff members whose accounts were still active
  • An ERP integrator who, improbably, had credentials that worked on SCADA because of a mistake in Active Directory group membership made years earlier

Six parties with live access the utility manager did not know about. Some benign, some concerning. All of them potential paths into the operational environment.

Water utilities and the engineering firms supporting them have to treat contractor SCADA access as a specific risk category with specific controls. CISA’s ongoing advisories on water and wastewater sector threats consistently highlight third-party access as a leading vector in successful attacks.

The Problem: Access Gets Granted, Rarely Audited

Water utility SCADA environments are supported by a network of contractors that a typical utility did not design with security in mind:

  • Control system integrators who configure and maintain the SCADA platform
  • Equipment OEMs who support specific pumps, valves, treatment systems, or instrumentation
  • HMI and historian software vendors who provide patches and support
  • Engineering firms (often the same firm supporting AWIA work) who touch SCADA data for reporting and analysis
  • Emergency response contractors pre-positioned for after-hours incidents
  • Third-party managed services providers, for utilities that have outsourced portions of their IT

Each of these parties has a legitimate reason for access. The problem is not that access exists. The problem is that access is granted once, in a hurry, and then rarely reviewed, while the utility environment, the contractor’s staff, and the threat landscape all change around it.

Why It Matters to You Specifically

For the utility manager and the engineering partner supporting the utility, poorly managed contractor access creates four specific exposures:

Compromise of Any Contractor Becomes Your Compromise

Your operational security is the lowest-common-denominator of every contractor with active access. A phishing click at an integrator, a laptop theft from an OEM engineer, or a compromised remote access tool at a vendor becomes a direct path into your SCADA environment.

Former Contractor Access Is a Quiet Timebomb

Contractors whose relationships have ended still often have access. Terminated employees of current contractors may still have credentials. The common pattern is that access is created during a project, used during the project, and never revoked after the project. A year later, those credentials are still there, still working, possibly still shared among people who should not have them.

Regulatory Exposure Under AWIA

The America’s Water Infrastructure Act requires the RRA to address “electronic, computer, or other automated systems (including the security of such systems).” An RRA that does not address contractor access to SCADA has a compliance gap. An RRA that addresses it in one sentence has a credibility gap.

Insurance and Auditor Expectations

Cyber insurance underwriters and auditors increasingly ask specific questions about third-party access controls. “How many contractors have active SCADA access?” “Is MFA enforced on all of them?” “When was the access list last reviewed?” Utilities without good answers are at a pricing disadvantage.

What Good Looks Like

Mature contractor access management for water utility SCADA environments has several recognizable features.

A Single Source of Truth for Contractor Access

One list, maintained by one accountable person, covers every contractor and every external account with access to operational systems. The list includes: who, what they can access, why they have access, when access was granted, when it was last reviewed, and when it is scheduled for review or termination.

All Access Goes Through a Controlled Gateway

Contractors do not have general-purpose VPN accounts that drop them onto operational networks. Instead, they connect through a controlled remote access platform (a jump host, a vendor access management tool, or a zero trust network access platform) that authenticates the contractor, checks session posture, and grants time-limited access to specific systems for specific tasks.

This is a departure from the traditional “give them a VPN” approach. It is also the current standard of practice and the direction underwriters and auditors expect to see.

MFA Required Without Exception

Every contractor login requires multi-factor authentication. Contractors whose tooling does not support MFA connect through a gateway that adds MFA at the boundary.

Just-in-Time Access Granting

Long-lived always-on contractor credentials are being replaced by just-in-time access. A contractor requests access for a specific task, a specific system, and a specific window. The access is granted for that window. When the window closes, the access is automatically revoked.

This sounds like it adds friction, and it does slightly. It also dramatically reduces the window of opportunity for any compromised contractor credential to be useful to an attacker.

Session Recording for Critical Systems

Access to core SCADA systems, historians, and control system infrastructure is recorded in full. Recordings are retained per the utility’s records retention policy. Recording is disclosed to contractors as part of access agreements, which has a useful effect on contractor behavior and supports forensic investigations when needed.

Vendor Security Requirements in Contracts

Contracts with contractors who have SCADA access include specific security requirements: MFA use, prompt notification of personnel changes, prompt notification of cybersecurity incidents at the contractor, defined right-to-audit language, and defined obligations around handling of sensitive information. Older contracts are updated at renewal. New contracts never get signed without these provisions.

Quarterly Access Reviews

Every 90 days, the access list is reviewed. Active contractor accounts are confirmed as still needed. Accounts with no use in the past 90 days are candidates for removal. Personnel changes at contractors trigger account updates.

Documented Incident Response Coordination

When a security incident involves contractor access, the response plan identifies who communicates with the contractor, what information is requested (logs, forensics, affected systems), and how the utility coordinates its investigation with the contractor’s.

Practical Takeaways

  1. Inventory every contractor with access to operational systems today. Include every VPN account, every remote access tool, every cellular gateway, and every account in your directory that maps to a contractor. The list is almost always longer than expected.
  2. Identify accounts belonging to expired relationships. Former contractors, former employees of current contractors, and accounts from finished projects are high priority for deactivation.
  3. Require MFA on every contractor login. If there are exceptions today, develop a specific plan for closing them within 90 days.
  4. Implement a controlled remote access platform. Consolidating contractor access through a single controlled gateway is the highest-impact structural improvement available. The CISA industrial control systems guidance reinforces that controlled access is foundational.
  5. Update your RRA and ERP to address contractor access. Both documents should reflect your contractor access controls and your response plans for contractor-related incidents.

The utilities that take contractor access seriously are meaningfully harder targets. The ones who leave it unmanaged are carrying risk they did not consciously accept.

If you want a conversation about assessing or restructuring contractor access at a utility or with a utility client, the HVR Cloud team works with water utilities and their engineering partners on this kind of program. Get in touch and we can walk through what a review would look like for your environment.