Global cybersecurity agencies have issued a joint call for critical infrastructure operators to conduct comprehensive mapping of their operational technology (OT) environments. The guidance, supported by the United Kingdom's National Cyber Security Centre, the U.S. Cybersecurity and Infrastructure Security Agency, and other allied partners, emphasizes the urgent need for exhaustive OT inventories to combat evolving cyber-physical threats. Operators of essential services such as power grids, water systems, and manufacturing plants are being instructed to catalogue all assets by their criticality, ensuring that every component of their OT environment is accounted for. The framework outlined by these agencies includes documenting system connectivity, validating and maintaining records through structured change management, and rigorously managing third-party access and contractual risks. Security experts highlight that while creating a definitive record of OT assets is both feasible and necessary, it presents significant challenges, particularly for organizations with sprawling, decades-old networks. Legacy systems often lack the real-time visibility required for effective inventory, making the process complex and resource-intensive. Despite these obstacles, the increasing sophistication of cyber-physical threats means that organizations can no longer afford to operate with blind spots in their OT environments. The guidance stresses the importance of asset visibility as a foundational element of OT security, enabling organizations to identify vulnerabilities and respond more effectively to incidents. Agencies recommend that operators implement structured change management processes to ensure that asset records remain accurate and up to date. The guidance also calls for robust management of third-party access, recognizing that supply chain and contractor relationships can introduce additional risks. By following the principles-based framework, critical infrastructure operators can reduce the likelihood of undetected vulnerabilities and improve their overall security posture. The agencies warn that failure to maintain comprehensive OT inventories could leave organizations exposed to major cyber incidents. The call to action reflects a growing consensus among global cyber authorities that asset management is a critical defense against increasingly complex threats targeting industrial control systems. The guidance is intended to drive a cultural shift in how OT operators approach security, moving from reactive measures to proactive risk management. Experts agree that while the task is daunting, the benefits of improved visibility and control far outweigh the challenges. The initiative underscores the need for ongoing collaboration between government agencies, industry stakeholders, and security professionals to protect critical infrastructure from cyber threats. Ultimately, the guidance aims to ensure that operators are not caught off guard by attacks that exploit unknown or unmanaged assets within their OT environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
US government agencies led by CISA released a joint guide, Adapting Zero Trust Principles to Operational Technology, to help critical infrastructure operators apply zero-trust concepts in OT environments. The guidance recommends OT-specific measures such as passive asset inventory, segmentation, adapted identity controls, secure remote access, supply chain risk management, and coordinated incident response.
Australia's cyber authorities published a CI Fortify resource focused on securing operational technology environments. The release provided official guidance for critical infrastructure operators on OT security as a distinct government initiative.
An industry report published on 2025-09-29 warned operational technology operators that inadequate network mapping can create major visibility gaps and increase security risk. The two references appear to be duplicate coverage of the same advisory rather than separate events.
7 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcecybersecuritydive.com
Open sourcecyber.gov.au
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcecontent.govdelivery.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.