When an energy services company or small utility buys a skid, a controller package, a metering system, or a remote monitoring service, the purchase decision usually focuses on performance, price, and delivery. Security often appears as a line in the specification at best. Yet the equipment may stay on your network for fifteen years, and the vendor often controls how it can be updated, accessed, and supported.
Asking the right questions at purchase or renewal gives you leverage you will not have later. Here are ten that operations and procurement teams can use, with notes on what good answers sound like.
1. How will you access this system remotely, and can we control that access?
Good answer: remote access is optional, uses multi-factor authentication, goes through your managed access point, and can be turned off between sessions. Be wary of permanent, vendor-controlled connections you cannot see or disable.
2. What default accounts and passwords exist, and can we change them?
Good answer: documented defaults, a process to change every one, and no hidden service accounts. If a password is hardcoded and cannot be changed, you need to know now, so you can compensate with network controls.
3. How do you deliver and verify software and firmware updates?
Good answer: signed updates, a published schedule, release notes, and a way to verify integrity. You should also be able to defer updates to fit maintenance windows.
4. How long will this product be supported, and what happens afterward?
Good answer: a stated support life, security fixes for a defined period, and clear notice of end-of-life. Ask what operating system the software requires and when that operating system itself loses support.
5. How do you handle vulnerabilities, and how will we hear about them?
Good answer: a named contact or advisory process, and a commitment to tell customers about security issues. CISA publishes advisories on industrial control systems, and a responsible vendor should engage with that process.
6. What network ports and connections does the system need?
Good answer: a documented list of required ports, protocols, and destinations. That list lets your network team write tight firewall rules instead of guessing.
7. Does the product phone home to a cloud service, and what data does it send?
Good answer: a clear explanation of what is transmitted, where it goes, how it is protected, and who at the vendor can see it. Cloud connectivity is not inherently bad, but it should be a conscious decision.
8. What security features does it support?
Ask about role-based access, individual user accounts, logging, encrypted communication, and the ability to export logs. Ask about alignment with ISA/IEC 62443 or similar frameworks, and treat vague answers as information.
9. How do we back up and restore it?
Good answer: documented backup and recovery procedures for configurations, logic, and databases, and confirmation that you can restore without the vendor's help if necessary. This matters during an incident when a vendor engineer is hours away.
10. What are your own security practices?
Ask how the vendor protects its engineering laptops, remote tools, and customer data. A vendor compromised through its own weak practices becomes your problem. Ask whether they will notify you of an incident that could affect you.
Putting the answers to use
- Put key commitments in the purchase contract or statement of work, not only in sales emails.
- Keep the answers with your asset inventory so future staff know the history.
- Score vendors against each other, since security can be a tiebreaker between similar bids.
- Where an answer is weak, plan compensating controls such as segmentation, restricted remote access, and offline configuration backups.
What if the equipment is already installed?
You can still ask. Many vendors have security guides and hardening recommendations they do not volunteer. Request them at your next service visit, and ask for a written support lifecycle for each major component.
Getting a second opinion
Ironfield Cyber helps energy and industrial operators review vendor proposals, write security language for procurement documents, and compensate for older equipment. If a purchase is coming up, we can help you prepare your questions in an hour or two.