NIST has released a draft update to its operational technology (OT) security guide, Special Publication 800-82 Revision 4, and is accepting public comments until 30 November 2026. The guide addresses securing OT while accounting for the performance, reliability and safety requirements of these systems. Its coverage now includes building automation, water and wastewater, food and agriculture, freight rail, maritime vessels, and industrial IoT and cloud convergence.
The draft is organised around the NIST Cybersecurity Framework 2.0, expands advice on controls including asset management and network monitoring, and adds guidance on protecting system-management functions and applying zero-trust principles.
Separately, CISA and the FBI have published advice for critical infrastructure operators that use third-party industrial control system (ICS) integrators. The agencies warn that excessive access or control granted to integrators could expose industrial processes to malicious cyber actors, and recommend applying least privilege. Their fact sheet cites FBI technical analysis of an intrusion at a US industrial automation company between March and April 2025.
The company provided system integration, engineering consultancy and SCADA programming to power and transport customers. During the intrusion, foreign actors searched for SCADA and customer records and staged nine archive files containing 800 network schematics, device configurations and customer details that could support disruptive attacks.
CISA and the FBI recommend defining cybersecurity and supply-chain requirements in contracts, reviewing where devices are hosted, removing unnecessary public-internet exposure, logging remote access and using on-demand access where possible.