CISA urged to issue binding OT security directive
The Operational Technology Cybersecurity Coalition (OTCC) wants the US Cybersecurity and Infrastructure Security Agency (CISA) to set mandatory minimum security standards for operational technology (OT) run by federal agencies. OT is the hardware and software used to monitor and control physical infrastructure.
The group published a white paper on Tuesday. It asks CISA to issue a new binding operational directive (BOD) focused on OT. A BOD is an order from CISA that federal civilian executive branch (FCEB) agencies must follow.
Water attacks as a warning
OTCC pointed to recent attacks on hundreds of water systems in at least 12 US states. In its view, these attacks show that OT now attracts both nation-state actors and cybercriminals.
Many of the affected devices in those water systems should never have been reachable from the internet. Some used default passwords or had no password at all. Many were also not separated from the non-operational parts of the network.
Federal civilian agencies use more than 8,000 owned or leased buildings. These include laboratories, hospitals, research facilities and ports of entry. Each one relies on HVAC, power, access control, water and building automation systems.
The coalition also cited a recent report from the Government Accountability Office (GAO), the US Congress's audit agency. The GAO reviewed 22 civilian agencies. Only 7 of them had fully met White House requirements to inventory their networked OT and Internet of Things devices. The deadline for those inventories was September 2024.
"[The Government Accountability Office] just confirmed what OT practitioners have been warning about for years: you can't secure what you can't see, and most federal agencies still can't see their OT," said Tatyana Bolton, executive director of OTCC. "Guidance alone hasn't closed that gap. A binding operational directive would give every agency a clear, enforceable baseline and give CISA the visibility to make sure it actually gets done."
Most civilian agencies manage their OT systems on their own, so CISA has little insight into how well they are protected. The paper also argues that artificial intelligence has made sophisticated attacks much easier to carry out, which puts OT systems at greater risk than before.
Why a directive
CISA has issued several BODs in the past after voluntary measures failed to work. According to the paper, a directive would let CISA "drive consistent implementation and measure compliance across the government."
The authors note that private companies and local entities are not bound by BODs. Even so, they say a directive still sends "a strong demand signal of what the government views as a cybersecurity best practice."
CISA declined to comment. Michael Garcia, OTCC's policy director, told Recorded Future News that the coalition consulted CISA while drafting the paper. It also sent the agency a final copy before publication.
Who owns the OT
The 8-page report proposes a baseline for prevention and containment. It rests on six pillars:
- visibility into OT assets
- network segmentation
- enforceable remote access controls
- configuration baselines
- incident preparedness
- verified backup and recovery
Agencies would have to name a senior official or a unified office in charge of OT asset inventory, configuration baselines and incident planning. Backup and recovery plans would be drawn up together with risk reports.
"Operational technology too often falls into a gray zone between the [Chief Information Officer's] office and facilities management, and when no one owns it, no one secures it," Garcia said. He added that the recommendations focus on basics such as changing default passwords and segmenting networks.
Dave Williams, OT security leader at Elisity, also said accountability is the core of the paper. "In most facilities, the chillers, badge readers, and power systems belong to a facilities team, and the network belongs to the CIO," he said. In his view, forcing an agency to put a name on that responsibility "would do more than another round of guidance."
Our Take
The OTCC proposal centres less on new technology and more on assigning responsibility. The failures it describes are basic ones, such as exposed devices, default credentials and flat networks. This suggests that the main gap is governance, and that a lack of tools is a smaller part of the problem. That fits a wider pattern we have covered, where OT visibility remains a struggle for many organisations. Attacks on water utilities keep showing what happens when these basics are missing.
Readers outside the federal government should not dismiss the proposal. As the authors note, BODs often shape what counts as best practice more broadly. It is worth watching whether CISA takes up the recommendation. If it does, the next question is whether agencies that missed the 2024 inventory deadline can meet an enforceable one.
