The Operational Technology Cybersecurity Coalition (OTCC) released a white paper advocating for the Cybersecurity and Infrastructure Security Agency (CISA) to implement mandatory federal rules for operational technology (OT). These rules would establish baseline cybersecurity standards for OT systems owned by federal agencies, which are crucial for monitoring and controlling critical infrastructure.
OTCC cited recent cyberattacks on hundreds of water systems across at least 12 U.S. states as a critical warning sign. These attacks exposed vulnerabilities in OT, such as internet-connected devices with default or no passwords, and a lack of network segmentation. Such incidents demonstrate that OT has become a target for nation-states and cybercriminals.
A government watchdog study found that only 7 of 22 civilian agencies reviewed had fully met White House requirements to inventory their networked operational technology and Internet of Things devices. These inventories were due in September 2024. This lack of visibility into OT assets within federal agencies, which include laboratories, hospitals, and research facilities, makes securing them challenging.
Tatyana Bolton, executive director of OTCC, stated that current guidance has not closed the gap in OT security. A binding operational directive would provide every agency with a clear, enforceable baseline and give CISA the necessary visibility to ensure compliance. CISA has previously issued binding operational directives when voluntary measures proved ineffective, suggesting a precedent for this approach to drive consistent implementation and measure compliance across government.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Operational Technology Cybersecurity Coalition (OTCC) has called on the Cybersecurity and Infrastructure Security Agency (CISA) to establish mandatory cybersecurity standards for operational technology (OT) used by federal agencies. This initiative follows recent cyberattacks on water systems and a government watchdog report indicating federal agencies are not adequately inventorying their OT devices, highlighting a gap in current voluntary guidance.