Policy · 5h ago
A coalition of cyber firms and critical infrastructure operators urged CISA on Tuesday to issue a binding operational directive for federal operational technology after this summer’s water-utility attacks. The group wants the agency to spell out who owns OT security at each agency, set minimum practices, and force clearer visibility into connected systems.
The push is about a gray zone, not a new flaw. The coalition says OT often sits between chief information officers and facilities teams, so no one has complete authority or inventory over controllers and other networked devices that can affect physical operations; it points to a recent GAO report saying most civilian agencies still had not carried out 2023 OMB requirements for networked IoT and OT devices.
If CISA turns guidance into a directive, the lasting change would be formal responsibility and baseline control in agencies that have treated OT as shared territory. For federal civilian shops and operators watching Washington, the open question is whether enforcement will finally match the risk that current voluntary rules have left scattered.
2 sources covering this story
OT Cyber Coalition calls on CISA to issue binding directive establishing federal OT cybersecurity requirements.
Here’s how experts think CISA should tell agencies to protect OT
A coalition is urging CISA to issue a binding operational directive focused on federal operational technology security as AI elevates cyber threats.
Part of the PlainSec briefing for 2026-10-07