The Operational Technology Cybersecurity Coalition urged the Cybersecurity and Infrastructure Security Agency (CISA) to issue a binding operational directive establishing minimum security requirements for operational technology (OT) owned by federal civilian agencies. The proposal addresses incomplete asset visibility, inconsistent security practices and accountability gaps between IT and facilities teams. A Government Accountability Office review found that only seven of 22 civilian agencies fully met requirements to inventory networked OT and Internet of Things devices. Recent attacks on hundreds of water systems across at least 12 U.S. states provided context, but the coalition did not claim its proposed directive would have prevented those incidents. CISA declined to comment, and the references do not report that a directive has been issued.
The recommended baseline includes asset inventories, network segmentation, stronger remote-access controls, secure configurations, incident preparedness, and verified backup and recovery. The coalition also called for a senior official or unified office accountable for OT security, integration with enterprise risk management, and alignment with existing federal guidance and CISA cybersecurity performance goals. The proposal does not explicitly require patching or firmware updates; industry commentators emphasized automated remediation and containment where patching could disrupt industrial operations. A directive could complement CISA’s CI Fortify resilience initiative and influence private critical-infrastructure security practices, but would not bind private operators.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
OTCC released a white paper urging CISA to issue an OT-specific binding operational directive for federal civilian agencies. It proposed accountable leadership and minimum controls for asset visibility, segmentation, remote access, configurations, incident preparedness, and verified backup and recovery.
GAO published a report finding that only seven of 22 reviewed civilian agencies fully met OMB requirements to inventory networked OT and IoT devices. GAO also reported that OMB had not issued updated inventory guidance for fiscal year 2026.
The incoming Trump administration renewed and refreshed the existing OMB memorandum on connected IoT and OT device requirements in 2025, according to OTCC policy director Michael Garcia.
The Office of Management and Budget issued requirements covering networked Internet of Things and operational technology devices, including agency device inventories. These requirements subsequently became the basis for GAO's review of federal agency compliance.
CISA first issued its cybersecurity performance goals in 2022. OTCC later recommended aligning a federal operational technology directive with these goals.
CISA declined to comment on the coalition's proposed federal OT cybersecurity directive.
OTCC cited attacks on hundreds of U.S. water systems as evidence of threats to operational technology. Many affected devices were unnecessarily internet-connected, used default passwords or no passwords, and lacked network segmentation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourceinfosecurity-magazine.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourceotcybercoalition.org
Open sourceotcybercoalition.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.