Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.

ICS/OT security

NIST has published a draft update to its operational technology security guide, and CISA and the FBI have issued a fact sheet on the risks of working with third-party ICS integrators. 

NIST seeks comment on revised OT guide

NIST this week released a draft of Special Publication 800-82 Revision 4, titled Guide to Operational Technology (OT) Security. Public comments are due by November 30, 2026. The document covers how to secure OT while accounting for the performance, reliability and safety demands specific to these systems.

The revision expands the guide’s sector coverage to include building automation, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and the convergence of industrial IoT and cloud. 

The guide is now organized around NIST Cybersecurity Framework 2.0, and the former risk management section has been reorganized to focus on the framework’s Govern function.

NIST also expanded its guidance on implementing OT security controls, including asset management and network monitoring and detection. 

The updated version also includes security architecture guidelines for protecting system management functions and applying zero trust principles.

Advertisement. Scroll to continue reading.

CISA and FBI urge scrutiny of ICS integrators

CISA and the FBI published the fact sheet for critical infrastructure owners and operators that work with third-party industrial control system (ICS) integrators. The agencies urge caution when giving integrators high levels of access or control over industrial processes. 

They recommend granting users, processes and systems “only the minimum access necessary to perform their assigned tasks, and no more.” Failing to apply the principle of least privilege could expose operators to malicious cyber actors, the agencies say.

The document cites FBI technical analysis of an intrusion at a US industrial automation solutions company. Between March and April 2025, malicious foreign cyber actors gained access to the company’s network. The company provided system integration, engineering consulting and SCADA programming to customers that included power utilities and transportation companies.

ICS Cybersecurity Conference

During the intrusion, foreign actors searched for SCADA and customer records and staged nine archive files containing 800 network schematics, device configurations, and customer details that could enable downstream disruptive attacks.

The agencies recommend that operators include cybersecurity and supply chain requirements in contracts and service agreements, covering areas such as data storage locations, remote access, and patch management. 

They also advise working with integrators to find out where devices are hosted and to reduce exposure, including by disconnecting devices from the public-facing internet. Operators should monitor and log remote access and, where possible, use on-demand remote access.

Related: Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Related: Only 13% of OT Network Segments Are Fully Isolated: Analysis

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Doppel has named Joey Rachid as Chief Security Advisor and Field Chief Information Security Officer.

Delinea has appointed Timothy Regan as Chief Financial Officer.

Gwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.