The Operational Technology Cybersecurity Coalition (OTCC) has formally requested that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) implement mandatory security standards for operational technology (OT) across federal civilian agencies. The coalition's report, published on October 6, calls for a binding operational directive (BOD) to address what it identifies as a lack of minimum security practices for federal OT and insufficient visibility into associated risks by CISA.
The OTCC highlighted that federal agencies utilize OT systems in over 8,000 facilities managed by the General Services Administration. These facilities, which include laboratories, hospitals, and ports of entry, rely on OT for critical functions such as HVAC, power management, access control, water systems, and general building automation.
This proposal follows a Government Accountability Office (GAO) report from September 30, which revealed that only seven out of 22 civilian agencies reviewed had fully complied with Office of Management and Budget (OMB) requirements to inventory their networked OT and Internet of Things (IoT) devices. These inventories were originally due by September 2024, and the GAO noted that OMB had not yet issued updated guidance for fiscal year 2026.
The proposed directive would mandate several key actions for agencies. These include designating a senior official or office responsible for OT security and integrating OT risk into broader enterprise risk management frameworks. It would also establish baseline requirements for asset inventory, network segmentation, secure remote access, configuration management, incident preparedness, and verified recovery procedures.
While the OTCC's priority controls emphasize changing default passwords, implementing multifactor authentication (MFA), network segmentation, and regular backups, the report does not explicitly call for patching or firmware updates. One cybersecurity expert, John Gallagher, vice president at Viakoo, cautioned that asset inventory alone is insufficient without a focus on remediation, warning that a lack of automated patch and configuration management could lead to overwhelming backlogs for operational teams. He noted that unmanaged default passwords and obsolete firmware are common attack vectors.
The coalition also stated that the directive would complement CISA's CI Fortify resilience initiative, which focuses on maintaining operations during a compromise. By establishing a pre-incident security baseline, the directive aims to prevent attacks from escalating into physical consequences. Louis Eichenbaum, federal CTO at ColorTokens, supported the emphasis on containment, explaining that many industrial devices cannot be patched quickly without disrupting operations. He advocated for segmentation to restrict attacker movement within a compromised network.
Although CISA's binding directives primarily apply to Federal Civilian Executive Branch agencies and not to privately operated critical infrastructure, the OTCC believes a strong federal OT baseline would have a significant broader impact. Such a directive would serve as a practical model for critical-infrastructure owners, provide clearer security expectations for vendors, and encourage the procurement of secure-by-design products within the federal government.






