THE Operational Technology Cybersecurity Coalition (OTCC) has urged the US Cybersecurity and Infrastructure Security Agency (CISA) to mandate a binding set of security requirements for operational technology (OT) across federal civilian agencies. In a report published on 6 October, the OTCC argues that currently there is no binding directive for federal OT, and that CISA lacks visibility into OT risk.
The coalition highlights that federal OT spans more than 8,000 General Services Administration–managed facilities, including labs, hospitals and ports of entry, where OT controls critical systems such as HVAC, power, access control, water and building automation.
The push follows a Government Accountability Office (GAO) report published on 30 September, which found that only seven of 22 civilian agencies examined had fully inventoryed their networked OT and IoT devices, with inventories due by September 2024 and no updated OMB guidance for fiscal year 2026.
The proposed directive would require agencies to appoint a senior official or office responsible for OT security and to integrate OT risk into enterprise risk management. It would establish a baseline for asset inventory, network segmentation, remote access, configuration management, incident preparedness and verified recovery. Critics, including John Gallagher of Viakoo, caution that inventory alone is not enough and warn of backlogs without automated patch and configuration management.
The OTCC’s controls emphasise changing default passwords, MFA, segmentation and backups, but stop short of mandating firmware updates or patching. Proponents argue that strong containment, alongside prevention, would help limit attacker movement and reduce the chance of OT compromise affecting physical operations, and that a federal baseline would influence private operators, vendors and procurement toward more secure-by-design products. The proposal links with CISA’s CI Fortify resilience initiative, aiming to prevent cascading damage from cyber incidents into physical systems.