ICS/OT

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30.

ICS/OT security

NIST has published a draft update to its operational technology security guide, and CISA and the FBI have issued a fact sheet on the risks of working with third-party ICS integrators. 

NIST seeks comment on revised OT guide

NIST this week released a draft of Special Publication 800-82 Revision 4, titled Guide to Operational Technology (OT) Security. Public comments are due by November 30, 2026. The document covers how to secure OT while accounting for the performance, reliability and safety demands specific to these systems.

The revision expands the guide’s sector coverage to include building automation, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and the convergence of industrial IoT and cloud. 

The guide is now organized around NIST Cybersecurity Framework 2.0, and the former risk management section has been reorganized to focus on the framework’s Govern function.

NIST also expanded its guidance on implementing OT security controls, including asset management and network monitoring and detection. 

The updated version also includes security architecture guidelines for protecting system management functions and applying zero trust principles.

Advertisement. Scroll to continue reading.

CISA and FBI urge scrutiny of ICS integrators

CISA and the FBI published the fact sheet for critical infrastructure owners and operators that work with third-party industrial control system (ICS) integrators. The agencies urge caution when giving integrators high levels of access or control over industrial processes. 

They recommend granting users, processes and systems “only the minimum access necessary to perform their assigned tasks, and no more.” Failing to apply the principle of least privilege could expose operators to malicious cyber actors, the agencies say.

The document cites FBI technical analysis of an intrusion at a US industrial automation solutions company. Between March and April 2025, malicious foreign cyber actors gained access to the company’s network. The company provided system integration, engineering consulting and SCADA programming to customers that included power utilities and transportation companies.

During the intrusion, foreign actors searched for SCADA and customer records and staged nine archive files containing 800 network schematics, device configurations, and customer details that could enable downstream disruptive attacks.

The agencies recommend that operators include cybersecurity and supply chain requirements in contracts and service agreements, covering areas such as data storage locations, remote access, and patch management. 

They also advise working with integrators to find out where devices are hosted and to reduce exposure, including by disconnecting devices from the public-facing internet. Operators should monitor and log remote access and, where possible, use on-demand remote access.

Related: Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

Related: Only 13% of OT Network Segments Are Fully Isolated: Analysis

Related Content

Government

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. 

ICS/OT

Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature.

Data Breaches

The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. 

ICS/OT

Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets.

Nation-State

The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign.

ICS/OT

The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. 

ICS/OT

The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.

Government

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version