The National Institute of Standards and Technology (NIST) has unveiled a draft update to its operational technology (OT) security guide, while the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a fact sheet addressing the risks associated with third-party industrial control system (ICS) integrators. These developments underscore the ongoing efforts to enhance cybersecurity in critical infrastructure sectors.
NIST Expands OT Security Guidelines
This week, NIST released a draft of Special Publication 800-82 Revision 4, titled ‘Guide to Operational Technology (OT) Security.’ The new draft is open for public comment until November 30, 2026. This document aims to enhance the security of OT systems by considering the unique performance, reliability, and safety requirements of these technologies.
The revised guide now broadens its sectoral focus, incorporating industries such as building automation, water and wastewater systems, food and agriculture, freight rail, and maritime operations, as well as the integration of industrial IoT and cloud technologies. The organization of the guide follows the NIST Cybersecurity Framework 2.0, with a shift in focus from risk management to the framework’s Govern function.
Additionally, the guide enriches its advice on implementing OT security controls, emphasizing asset management, network monitoring, and detection. It also introduces security architecture guidelines for safeguarding system management functions and applying zero trust principles.
CISA and FBI Caution on ICS Integrators
CISA and the FBI have published a fact sheet specifically aimed at owners and operators of critical infrastructure working with third-party ICS integrators. The agencies stress the importance of exercising caution when granting integrators significant access or control over industrial processes.
They recommend adhering to the principle of least privilege, ensuring that users, processes, and systems have only the access necessary to perform their tasks. The failure to implement this principle could leave operators vulnerable to cyber threats, according to the agencies.
The document references an FBI investigation into a 2025 incident where foreign cyber actors breached a U.S. industrial automation solutions company. The breach involved the theft of sensitive information, including network schematics and customer data, which could facilitate further cyberattacks.
Recommendations for Enhanced Cybersecurity
To mitigate these risks, CISA and the FBI advise operators to incorporate cybersecurity and supply chain requirements into contracts and service agreements, covering data storage, remote access, and patch management. Additionally, operators should collaborate with integrators to identify device hosting locations and minimize exposure by disconnecting devices from the public-facing internet when possible.
Operators are also encouraged to monitor and log remote access activities, employing on-demand remote access solutions wherever feasible. These proactive steps are crucial for protecting critical infrastructure from potential cybersecurity threats.
As the landscape of industrial technology continues to evolve, these guidelines and recommendations from NIST, CISA, and the FBI play a pivotal role in bolstering the cybersecurity defenses of critical infrastructure sectors. Staying informed and implementing these measures can significantly improve the resilience of these essential systems against cyber threats.
