Policy · 5h ago

Coalition Pushes CISA to Assign OT Ownership

A coalition of cyber firms and critical infrastructure operators urged CISA on Tuesday to issue a binding operational directive for federal operational technology after this summer’s water-utility attacks. The group wants the agency to spell out who owns OT security at each agency, set minimum practices, and force clearer visibility into connected systems.

The push is about a gray zone, not a new flaw. The coalition says OT often sits between chief information officers and facilities teams, so no one has complete authority or inventory over controllers and other networked devices that can affect physical operations; it points to a recent GAO report saying most civilian agencies still had not carried out 2023 OMB requirements for networked IoT and OT devices.

If CISA turns guidance into a directive, the lasting change would be formal responsibility and baseline control in agencies that have treated OT as shared territory. For federal civilian shops and operators watching Washington, the open question is whether enforcement will finally match the risk that current voluntary rules have left scattered.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-10-07

Editions