When a contractor connects a laptop to a utility network, installs a remote monitoring device, or supports a control system, the utility inherits that contractor's security posture. The same is true in reverse: a contractor is exposed to the habits of every vendor they rely on. Third-party risk has become a central theme in energy security, including in the NERC CIP standards, which address supply chain risk management at a general level for entities subject to them.
This article offers a practical set of questions that small utilities and the contractors serving them can use. It is not a legal or compliance determination. It is a way to make vendor conversations specific.
Why Vendor Risk Is Hard
Vendors often need real access: to equipment, to networks, to data. They use their own staff, tools, and subcontractors. You cannot inspect all of it. What you can do is understand what access they have, ask structured questions, and limit the damage if something goes wrong.
Step 1: Inventory the Vendors That Matter
List the vendors with any of the following:
- Remote access to your systems or equipment
- Physical access to facilities or substations
- Software or firmware running on operational equipment
- Access to sensitive data, drawings, or configurations
- Responsibility for critical services such as hosting or telecommunications
Rank them by what could happen if they were compromised. A landscaping contractor and a control system integrator are not the same risk.
Step 2: Ask About Their Security Practices
Access and identity
- Do your technicians use individual accounts and multi-factor authentication?
- How do you remove access when staff leave?
- How are shared or privileged credentials protected?
Devices and software
- Are the laptops used on our systems managed and protected with current security tools?
- How do you manage updates to the products you supply, and how are customers told about vulnerabilities?
- Do you maintain a list of the software components in your products and can you share it?
Remote access methods
- What tools do you use to connect to our environment?
- Can access be time-limited and logged?
- Do you ever connect from personal devices?
Incident handling
- Do you have a documented incident response plan?
- How quickly would you notify us if your environment was compromised?
- Who is our contact, and is that person reachable at night?
Subcontractors
- Which subcontractors will touch our systems or data?
- Are they held to the same requirements?
Step 3: Put It in the Contract
Questionnaires are only a snapshot. Contracts create obligations. Work with counsel to include expectations such as:
- Notification of security incidents within a defined period
- Use of individual accounts and multi-factor authentication for remote access
- Prompt disclosure and remediation of known product vulnerabilities
- Restrictions on subcontracting without approval
- Return or secure destruction of your data at the end of the contract
- Right to ask for evidence of security practices
Step 4: Limit Access Technically
Do not rely on promises alone.
- Provide access through a controlled gateway rather than a direct network connection.
- Grant access only to the systems the work requires, and only for the time needed.
- Record and review remote sessions where possible.
- Segment vendor-supported equipment from the rest of your network.
Step 5: Review Periodically
Re-evaluate high-risk vendors at least annually and when something changes, such as a merger, a new remote tool, or a public security advisory affecting their products. CISA publishes advisories for industrial and enterprise products; make someone responsible for checking them against your vendor list.
For Contractors Serving Utilities
If you are the vendor, expect to be asked these questions. Prepare answers, keep documentation current, and treat customer requirements as a sales advantage. Contractors who can demonstrate individual accounts, managed devices, and a clear incident process tend to win trust and renewals.
Keep It Proportionate
A small co-op cannot run the same program as a large investor-owned utility. Focus on the vendors with the most access and the highest consequences, document what you did, and improve each year.
Working With Ironfield Cyber
Ironfield Cyber can help small utilities build a vendor inventory and a short questionnaire, and help contractors prepare to answer one. A clear, repeatable process saves time on both sides and reduces the chance that a vendor connection becomes the way in.