
Federal civilian agencies would gain a uniform, enforceable cybersecurity baseline for operational technology under a binding operational directive that a coalition of experts is asking the Cybersecurity and Infrastructure Security Agency (CISA) to issue. The proposal follows repeated attacks on US water systems and a government watchdog finding that only a small minority of federal agencies had completed required inventories of their OT and Internet of Things devices.
What the coalition is asking for
The Operational Technology Cybersecurity Coalition released a white paper urging CISA to create a new directive focused on operational technology, the hardware and software used to monitor and control physical equipment in critical infrastructure. The 8-page report lays out a prevention and containment baseline built on six elements: visibility into OT assets, network segmentation, enforceable remote access controls, configuration baselines, incident preparedness, and verified backup and recovery.
The paper also asks CISA to require agencies to designate a senior official or unified office to manage OT asset inventory, configure baselines, and prepare for potential incidents. Backup and recovery plans would be created alongside risk reports.
The case: attacks on water systems and missing inventories
The coalition cited recent cyberattacks on hundreds of water systems in at least 12 US states as a clear warning sign that operational technology has become a target for nation-state actors and cybercriminals. Much of the technology within the affected water systems included devices that should not have been connected to the internet, used default passwords or no passwords at all, and were not segmented from other non-operational parts of the network.
Federal civilian agencies rely on more than 8,000 owned or leased buildings that include laboratories, hospitals, research facilities, and ports of entry, all with HVAC, power, access control, water, and building automation systems. A recent study from a government watchdog found that only 7 of the 22 civilian agencies reviewed had fully met White House requirements to inventory their networked operational technology and Internet of Things devices. Those inventories were due in September 2024.
Most federal civilian agencies currently govern OT systems on their own, leaving CISA without a complete view of their security posture. AI has made sophisticated attacks easier to launch, exposing OT systems to threats they have not encountered before.
Why a directive and not more guidance
The paper argues that a binding operational directive would allow CISA to drive consistent implementation and measure compliance across the government. CISA has issued multiple binding operational directives in the past after voluntary measures proved insufficient.
The value of a BOD is to establish a uniform, government-wide baseline so that CISA can understand, measure, and manage cyber risk consistently across the federal civilian executive branch. While private or local entities are not required to implement BODs, they still provide a strong demand signal of what the government views as a cybersecurity best practice, according to the coalition.
Operational technology often sits between the Chief Information Officer’s office and facilities management with no clear owner, leaving it unsecured. The paper’s OT cybersecurity practitioners identify clear ownership as their top recommendation, since it predetermines how priorities and resource constraints are reconciled.
How ownership changes the rest of the list
In most facilities, chillers, badge readers, and power systems belong to a facilities team, and the network belongs to the CIO. Every other recommendation on the list, from asset inventory to segmentation to remote access, assumes someone is accountable to act on it. A directive can force an agency to put a name on that responsibility, and that alone would do more than another round of guidance.
The recommendations are practical by design: name an accountable official, build on requirements agencies already have, and prioritize the basics that matter most in the incidents already observed, such as changing default passwords and segmenting networks.
What happens next
CISA declined to comment on the paper. The coalition’s policy lead confirmed the group engaged with CISA while creating the paper and shared a final copy of the report before publication.
FAQ
What is a binding operational directive for federal OT?
A binding operational directive (BOD) is an enforceable instruction CISA issues to federal civilian agencies. The proposed OT directive would set a uniform baseline for asset inventory, network segmentation, remote access, configuration, incident preparedness, and backup and recovery across the federal civilian executive branch.
Why are experts asking CISA for an OT directive now?
The request follows cyberattacks on water systems in at least 12 US states and a government watchdog finding that only 7 of 22 reviewed federal civilian agencies had fully met required inventories of their networked OT and IoT devices. Voluntary measures have not closed the gap, the coalition argues.
What would change under a federal OT directive?
Agencies would be required to designate a senior accountable official for OT, complete an asset inventory, segment OT networks, enforce remote access controls, apply configuration baselines, prepare incident response, and maintain verified backup and recovery plans. CISA would gain visibility and a way to measure compliance across the federal civilian government.
This article summarizes reporting from therecord.media.
