A coalition of cybersecurity experts is urging the Cybersecurity and Infrastructure Security Agency (CISA) to establish mandatory cybersecurity standards for operational technology (OT) used by federal agencies. The Operational Technology Cybersecurity Coalition (OTCC) released a white paper on Tuesday, October 7, 2026, advocating for a new binding operational directive (BOD) specifically addressing OT, which controls critical infrastructure systems.
The OTCC highlighted recent cyberattacks on hundreds of U.S. water systems across at least 12 states as a critical warning. These incidents frequently involved internet-connected devices that should have been isolated, often protected by default or nonexistent passwords, and lacked proper network segmentation. Such vulnerabilities underscore the increasing targeting of OT by both nation-states and cybercriminals.
Federal civilian agencies operate or lease over 8,000 buildings, including laboratories, hospitals, research facilities, and ports of entry. These facilities rely on various OT systems for HVAC, power, access control, water management, and building automation. A recent government watchdog study found that only 7 of 22 reviewed civilian agencies had fully complied with White House requirements to inventory their networked OT and Internet of Things (IoT) devices, a task due in September 2024.
According to Tatyana Bolton, executive director of OTCC, this finding confirms long-standing concerns among OT practitioners that "you can't secure what you can't see." She emphasized that current guidance has proven insufficient, and a binding directive would provide a clear, enforceable baseline for agencies while giving CISA the necessary visibility to ensure compliance. Most federal civilian agencies currently manage their OT systems independently, leaving CISA unaware of their security posture.
The OTCC's 8-page report proposes a prevention and containment framework built on several key pillars: comprehensive visibility into OT assets, robust network segmentation, enforceable remote access controls, established configuration baselines, incident preparedness, and verified backup and recovery plans. The coalition recommends that CISA mandate agencies to appoint a senior official or establish a dedicated office to manage OT asset inventory, configure baselines, and prepare for potential incidents. Risk reports should also be developed alongside backup and recovery strategies.
Michael Garcia, policy director of OTCC, noted that OT often falls into a "gray zone" between Chief Information Officers (CIOs) and facilities management, leading to a lack of clear ownership for cybersecurity. He stated that the coalition's recommendations are practical, focusing on designating accountable officials, building upon existing agency requirements, and prioritizing fundamental security measures like changing default passwords and segmenting networks.
The OTCC engaged with CISA during the development of the paper and shared a final copy before its publication, though CISA declined to comment on the report. Several OT cybersecurity experts agree that clear ownership is a crucial aspect of the paper's recommendations. Dave Williams, an OT security leader at Elisity, explained that in many facilities, systems like chillers, badge readers, and power are managed by facilities teams, while the network falls under the CIO. He stressed that without clear accountability, other security recommendations, from asset inventory to segmentation, cannot be effectively implemented. A directive, he suggests, could compel agencies to assign this responsibility, which would be more impactful than additional guidance.






