OT Coalition Urges CISA to Mandate Federal OT Security

Written by

The Operational Technology Cybersecurity Coalition (OTCC) has urged the US Cybersecurity and Infrastructure Security Agency (CISA) to set mandatory security requirements for operational technology (OT) across federal civilian agencies.

In a report published on October 6, the coalition called for a binding operational directive (BOD), arguing that no directive sets minimum practices for federal OT and that CISA lacks visibility into the risks.

OTCC said agencies rely on OT in more than 8000 General Services Administration-managed facilities, including laboratories, hospitals and ports of entry, where it runs HVAC, power, access control, water and building automation systems.

The proposal follows a Government Accountability Office (GAO) report published on September 30, which found that only seven of 22 civilian agencies reviewed had fully met Office of Management and Budget (OMB) requirements to inventory their networked OT and Internet of Things devices.

The inventories were due by September 2024, and OMB had not issued updated guidance for fiscal year 2026, the GAO said.

What the Directive Would Require

The proposed directive would require agencies to designate a senior official or office responsible for OT security and bring OT risk into enterprise risk management. It would set a baseline for asset inventory, network segmentation, remote access, configuration management, incident preparedness and verified recovery.

John Gallagher, vice president at Viakoo, warned that an inventory alone would not be enough. "Missing from the OTCC's goals is remediation," he said, warning that without automated patch and configuration management, agencies would face backlogs that overwhelm operational teams.

OTCC's list of priority controls does include changing default passwords, multifactor authentication (MFA), segmentation and backups, which it asked CISA to emphasize alongside oversight of the OMB requirements, but the report does not call for patching or firmware updates.

Gallagher said attackers routinely get in through unmanaged default passwords and obsolete firmware.

Read more on OT security guidance: CISA and Partners Publish Zero Trust Guidance For OT Security

Containment Alongside Prevention

The coalition also said the directive would complement CISA's CI Fortify resilience initiative, which plans for operating through a compromise, by setting a pre-incident baseline to stop attacks cascading into physical consequences.

Louis Eichenbaum, federal CTO at ColorTokens, said containment matters because many industrial devices cannot be patched quickly without disrupting operations.

"Patching remains essential, but we cannot patch our way out of cyber risk," he said, arguing for segmentation to limit how far an attacker can move from a compromised controller.

OTCC noted that although private and local operators are not bound by BODs, a directive would signal what the government considers best practice.

"Although CISA's binding directives apply to certain Federal Civilian Executive Branch agencies, not privately operated critical infrastructure, a strong federal OT baseline would have influence far beyond government," Eichenbaum added.

"It would give critical-infrastructure owners a practical model, provide vendors with clearer security expectations and allow federal procurement to encourage secure-by-design products."

What’s Hot on Infosecurity Magazine?