← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

NIST Updates OT Security Guide; CISA/FBI Warn on ICS Integrator Risks

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • NIST published draft SP 800-82 Revision 4 for public comment.
  • The updated guide expands OT sector coverage and aligns with NIST CSF 2.0.
  • CISA and FBI warned about risks from third-party ICS integrators.
  • Agencies recommend least privilege and contract cybersecurity requirements.

NIST Updates Operational Technology Security Guide

NIST has released a draft of Special Publication 800-82 Revision 4, titled "Guide to Operational Technology (OT) Security," for public comment until November 30, 2026. This revision aims to provide updated guidance on securing OT systems while considering their specific performance, reliability, and safety requirements.

The updated guide expands its coverage to include sectors such as building automation, water and wastewater systems, food and agriculture, freight rail, and maritime vessels. It also addresses the convergence of industrial IoT and cloud technologies. The document is now structured around the NIST Cybersecurity Framework 2.0, with the risk management section reorganized to focus on the framework’s Govern function. Additionally, NIST expanded guidance on implementing OT security controls, including asset management, network monitoring, and detection, and incorporated security architecture guidelines for system management and zero trust principles.

CISA and FBI Advise Caution with ICS Integrators

CISA and the FBI have published a fact sheet for critical infrastructure owners and operators regarding the risks of working with third-party industrial control system (ICS) integrators. The agencies recommend caution when granting integrators extensive access or control over industrial processes, emphasizing the principle of least privilege.

The guidance follows an FBI technical analysis of an intrusion at a U.S. industrial automation solutions company between March and April 2025. Malicious foreign cyber actors accessed the company’s network, which provided services to power utilities and transportation companies. During the intrusion, actors searched for SCADA and customer records, staging nine archive files containing network schematics, device configurations, and customer details that could facilitate future disruptive attacks. CISA and the FBI recommend that operators include cybersecurity and supply chain requirements in contracts and service agreements with integrators.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~24 min · 20 stories · Sep 24

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

NIST released a draft update to its operational technology security guide, expanding sector coverage and aligning with Cybersecurity Framework 2.0. Separately, CISA and the FBI issued a fact sheet advising critical infrastructure operators on the risks associated with third-party ICS integrators, following a cyber intrusion at an industrial automation company.