Industrial control equipment lives for a long time. A controller, remote terminal unit or monitoring package bought this year may still be running in fifteen years. That means the security decisions you make at purchase, or fail to make, will outlast several IT refresh cycles. The cheapest moment to demand good security is before the purchase order, when you still have leverage.
Many operators do not ask because the request feels technical or because the engineering team and the IT team do not talk until after installation. A short set of requirements written into your RFP or purchase terms changes that.
Why the Purchase Is the Leverage Point
After a system is installed, asking the vendor to change default passwords, remove a remote-access tool, or provide patches becomes a favor. Before award, it is a condition of winning the work. Industry guidance such as ISA/IEC 62443 describes security expectations for both product suppliers and system integrators, and CISA has repeatedly urged manufacturers to ship products that are secure by default. You do not need to cite a standard in every RFP, but you can borrow its ideas.
Requirements to Put in the RFP
Accounts and Authentication
- No shared or hard-coded default credentials, and a documented process to change every default at commissioning
- Individual user accounts with role-based permissions rather than a single shared login
- Support for multi-factor authentication on any remote or administrative access where feasible
Remote Access
- A clear description of every remote-access method the vendor intends to use, including cellular modems and cloud portals
- No always-on remote connection without your approval; access should be initiated or approved by your team, time-limited and logged
- Disclosure of any vendor-operated cloud service that will receive data from your site
Network Design
- A network diagram showing how the equipment connects, which ports and protocols are required, and what traffic crosses zones
- Compatibility with segmentation: the equipment should work behind a firewall without requiring flat networks or open inbound ports
- No requirement to connect directly to the corporate network or the internet
Patching and Support
- A published or written policy for security updates, and how you will be notified
- The expected support lifetime of the product, and what happens when it reaches end of life
- A process for testing and applying patches that fits your operating windows, not a requirement to reboot at the vendor's convenience
Vulnerability Handling
- A named contact or process for reporting and receiving vulnerability information
- Willingness to disclose known vulnerabilities in delivered components
Documentation and Handover
- Complete documentation of software versions, configurations and passwords delivered at commissioning
- Backups of controller programs and configurations, delivered in a usable form
- Training for your staff on the security-relevant features
Evaluate the Answers
Score vendors on how specifically they answer, not on whether they say yes. A vendor that explains how remote access is controlled and logged is more credible than one that writes "fully secure" in every box. Ask for a short demonstration or reference where possible, and have both an engineer and whoever supports your IT review the responses.
Commissioning and Acceptance
Make security part of acceptance testing. Before you sign off, confirm that default accounts were changed, unnecessary services are disabled, the network matches the approved diagram, and the backup copy of the configuration exists and can be restored. Withhold final payment, or a retention amount, until these items are complete.
Do Not Forget the Contract
Put the key requirements in the contract itself, not just the proposal. Include obligations for notification when the vendor learns of a vulnerability or incident affecting your equipment, and clear terms on who may access your systems and under what conditions.
Where Ironfield Cyber Helps
Ironfield Cyber helps energy services firms, utilities and industrial operators translate security expectations into practical RFP language and review vendor responses with your engineers. If a purchase is coming up, we are happy to help you draft the requirements before you send it out.