top of page

OTCC Calls on CISA to Issue a Binding Operational Directive to Secure Federal Operational Technology

7 hours ago
3 min read

New report, "Know It. Control It. Contain It.," lays out a mandatory security baseline for federal OT just a week after GAO finds most agencies still can't account for their OT devices

FOR IMMEDIATE RELEASE

WASHINGTON, D.C., October 6, 2026 — The Operational Technology Cybersecurity Coalition (OTCC) today released "Know It. Control It. Contain It.: A Binding Operational Directive for OT Cybersecurity," a report calling on the Cybersecurity and Infrastructure Security Agency (CISA) to issue a Binding Operational Directive (BOD) setting mandatory, enforceable security requirements for operational technology (OT) across Federal Civilian Executive Branch (FCEB) agencies. The report lays out a prevention and containment baseline built on visibility into OT assets, network segmentation, enforceable remote access controls, configuration baselines, incident preparedness, and verified backup and recovery.


CISA has folded some OT requirements into earlier directives, but no BOD yet sets consistent minimum security practices for federal OT. Agencies largely govern these systems on their own, leaving CISA without consistent visibility into their security posture. As AI lowers the barrier to sophisticated attacks, the report argues, it is time for a directive focused solely on OT.


New findings from the U.S. Government Accountability Office (GAO) underscore the urgency. In a September 30 report, GAO found that only seven of the 22 civilian agencies it reviewed had fully met the Office of Management and Budget's (OMB) requirements to inventory their networked OT and Internet of Things devices, inventories that were due in September 2024. GAO also found that OMB has not issued updated guidance for fiscal year 2026, leaving agencies "without a clear imperative to prioritize implementation of the requirements or a timeline for doing so."


"GAO just confirmed what OT practitioners have been warning about for years: you can't secure what you can't see, and most federal agencies still can't see their OT," said Tatyana Bolton, Executive Director of OTCC. "Guidance alone hasn't closed that gap. A binding operational directive would give every agency a clear, enforceable baseline and give CISA the visibility to make sure it actually gets done."


The OT behind federal operations is vast. Civilian agencies rely on more than 8,000 GSA-managed owned and leased facilities, including laboratories, hospitals, research campuses, and ports of entry, all supported by HVAC, power management, access control, water, and building automation systems. Yet CISA does not currently have a holistic view of these assets or the risks they carry. This summer's cyberattacks on water systems in at least 12 states showed how quickly exposed devices, default passwords, and poor network segmentation can turn into real-world disruption.


OTCC's report recommends that CISA issue a BOD that:

  • Establishes clear OT governance and accountability, requiring agencies to designate a senior official or unified office responsible for OT asset inventory, configuration baselines, backup and recovery, incident preparedness, and risk reporting, and to bring OT risk into enterprise risk management.

  • Incorporates OT more broadly across existing guidance, building on the National Security Agency's BOD 2024-001 for national security systems, enforcing prior BODs that apply to OT, and giving CISA a role in overseeing agency implementation of OMB's networked device requirements.

  • Aligns CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) to OT needs and prioritizes implementation, focusing on the controls most relevant to recent OT incidents, such as changing default passwords, multifactor authentication, network segmentation, and maintaining system backups.


"Operational technology too often falls into a gray zone between the CIO's office and facilities management, and when no one owns it, no one secures it," said Michael Garcia, Policy Director of OTCC. "Our recommendations are practical by design. Name an accountable official, build on requirements agencies already have, and prioritize the basics that matter most in the incidents we've seen, like changing default passwords and segmenting networks."


The report positions an OT BOD as the preventive and containment complement to CISA's CI Fortify resilience efforts, which OTCC strongly supports. Where CI Fortify plans for operating through a compromise, a BOD would set the pre-incident baseline to keep attacks from cascading into physical consequences. The report also urges CISA to work with the national labs and industry on cyber-informed engineering principles across federal OT.



About OTCC: The Operational Technology Cybersecurity Coalition (OTCC) is a diverse group of cybersecurity stakeholders dedicated to improving the cybersecurity of operational technology environments and strengthening public policy to secure critical infrastructure. Representing the full OT lifecycle, OTCC advocates for an open, vendor-neutral approach that supports diverse solutions and information sharing without compromising cybersecurity defenses. Learn more at www.otcybercoalition.org.



###


Comments


Interested in joining the OTCC?

We welcome organizations committed to advancing OT cybersecurity through collaboration and shared expertise. If you’re interested in becoming a member, please visit the Join the OTCC page. If you have any further questions, please reach out to info@otcybercoalition.org.

bottom of page