VYPR
advisoryPublished Oct 6, 2026· 1 source

Experts Urge CISA to Mandate Operational Technology Security for Federal Agencies

A coalition of cybersecurity firms and critical infrastructure operators is pushing CISA to issue a binding operational directive (BOD) for federal agencies to bolster the security of their operational technology (OT) systems.

A coalition of cyber firms and critical infrastructure operators has proposed that the Cybersecurity and Infrastructure Security Agency (CISA) issue a binding operational directive (BOD) specifically for operational technology (OT) security within federal agencies. This initiative, detailed in a recent proposal, aims to address critical gaps in visibility, policy, and security practices concerning OT systems, particularly in light of escalating threats and recent attacks on vital infrastructure.

The proposed BOD would clarify responsibilities for OT security at each federal agency, drawing upon existing federal guidelines and establishing minimum cybersecurity standards. The coalition argues that such a directive is necessary due to CISA's current lack of a comprehensive view of federal OT assets and the inconsistent application of security policies across agencies. This is especially pertinent given the increasing sophistication of cyber threats, including those enabled by artificial intelligence, which can accelerate reconnaissance and exploitation of poorly segmented environments.

Recent reports, such as one from the Government Accountability Office (GAO), have highlighted that many federal civilian executive branch agencies (FCEBs) have not fully implemented existing requirements for networked Internet of Things and OT devices. The coalition's proposal seeks to ensure that federal agencies not only practice what they preach regarding cybersecurity but also send a strong signal to the private sector about the importance of OT security.

Michael Garcia, policy director for the coalition, emphasized that the directive would serve a dual purpose: ensuring internal government compliance and influencing private sector expectations. He noted that many federal facilities, from power supply to HVAC systems, rely on OT, and while some systems may be minor, the potential risks associated with compromised OT can be severe. CISA currently lacks a holistic understanding of these assets and the potential vulnerabilities, such as connected programmable logic controllers.

To bridge this gap, the coalition recommends that CISA mandate the formal designation of an officer responsible for OT cybersecurity within each agency. The proposed directive should also evaluate the applicability of past OT security guidelines issued by the National Security Agency (NSA) to federal civilian agencies and align any new requirements with CISA's existing cybersecurity performance goals.

While acknowledging that CISA has previously incorporated OT security into other directives and provided technical guidance, the coalition stresses the need for a dedicated, encompassing BOD. They argue that the evolving threat landscape, particularly the role of AI in lowering technical barriers for adversaries, necessitates a singular focus on OT security to address the speed and scale of potential attacks.

The proposal comes at a critical time, with recent attacks on water utilities underscoring the vulnerability of critical infrastructure. Although the coalition does not claim a BOD would have prevented past incidents, they believe it is a crucial step towards fortifying federal OT systems against future threats. Discussions with CISA suggest a growing recognition within the agency of the potential need for such a directive.

Synthesized by Vypr AI