NIST has released a draft of Special Publication 800-82 Revision 4, titled "Guide to Operational Technology (OT) Security," for public comment until November 30, 2026. This revision aims to provide updated guidance on securing OT systems while considering their specific performance, reliability, and safety requirements.
The updated guide expands its coverage to include sectors such as building automation, water and wastewater systems, food and agriculture, freight rail, and maritime vessels. It also addresses the convergence of industrial IoT and cloud technologies. The document is now structured around the NIST Cybersecurity Framework 2.0, with the risk management section reorganized to focus on the framework’s Govern function. Additionally, NIST expanded guidance on implementing OT security controls, including asset management, network monitoring, and detection, and incorporated security architecture guidelines for system management and zero trust principles.
CISA and the FBI have published a fact sheet for critical infrastructure owners and operators regarding the risks of working with third-party industrial control system (ICS) integrators. The agencies recommend caution when granting integrators extensive access or control over industrial processes, emphasizing the principle of least privilege.
The guidance follows an FBI technical analysis of an intrusion at a U.S. industrial automation solutions company between March and April 2025. Malicious foreign cyber actors accessed the company’s network, which provided services to power utilities and transportation companies. During the intrusion, actors searched for SCADA and customer records, staging nine archive files containing network schematics, device configurations, and customer details that could facilitate future disruptive attacks. CISA and the FBI recommend that operators include cybersecurity and supply chain requirements in contracts and service agreements with integrators.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
NIST released a draft update to its operational technology security guide, expanding sector coverage and aligning with Cybersecurity Framework 2.0. Separately, CISA and the FBI issued a fact sheet advising critical infrastructure operators on the risks associated with third-party ICS integrators, following a cyber intrusion at an industrial automation company.