top of page

November 19, 2025

The Zero Trust Mandate:
Translating the Philosophy for OT/ICS

Zero Trust has become the leading security model for IT environments, but applying it directly to operational technology (OT) without adaptation can introduce real risks to safety and operations. This paper explains why: OT systems prioritize safety and availability over confidentiality, assume physical access rather than ruling it out, and can't tolerate the disruption that IT-style continuous verification and rapid patching often require.


Rather than rejecting Zero Trust for OT, the OTCC argues it needs to be adapted, not replace, existing OT security frameworks like ISA/IEC 62443 and NIST SP 800-82. The paper lays out three key modifications: scoping any element excluded from a Zero Trust Enterprise into established OT guidance, acknowledging the fundamental "delta" between IT and OT environments, and building Zero Trust on top of existing OT standards rather than starting from scratch.

bottom of page