The Operational Technology Cybersecurity Coalition has pressed the US Cybersecurity and Infrastructure Security Agency to impose mandatory security standards for operational technology across federal civilian agencies, arguing that current oversight leaves critical systems exposed. In a report released on October 6, the coalition requested a binding operational directive, stating that no existing directive establishes minimum security practices for federal OT and that CISA has insufficient visibility into the associated risks. The coalition emphasized that agencies depend on OT across more than 8,000 facilities managed by the General Services Administration, spanning laboratories, hospitals, and ports of entry, where these systems control HVAC, power, access control, water, and building automation.
The coalition's proposal follows a Government Accountability Office report published on September 30, which revealed that just seven of 22 civilian agencies examined had fully satisfied Office of Management and Budget requirements to catalog their networked OT and Internet of Things devices. The inventories were due by September 2024, and OMB had not released updated guidance for fiscal year 2026, according to the GAO. The proposed directive would mandate that agencies appoint a senior official or office responsible for OT security and integrate OT risk into enterprise risk management. It would establish a baseline covering asset inventory, network segmentation, remote access, configuration management, incident preparedness, and verified recovery.
The coalition's list of priority controls includes changing default passwords, multifactor authentication, segmentation, and backups, which it asked CISA to highlight alongside monitoring of the OMB requirements, though the report does not call for patching or firmware updates. John Gallagher, vice president at Viakoo, cautioned that an inventory by itself would be insufficient, warning that "without automated patch and configuration management," agencies would confront backlogs overwhelming operational teams. Louis Eichenbaum, federal CTO at ColorTokens, noted that containment is important because many industrial devices can't be patched rapidly without interrupting operations, stating that "we cannot patch our way out of cyber risk."
The coalition stated that the directive would support CISA's CI Fortify resilience initiative, which prepares for operating through a compromise, by establishing a pre-incident baseline to prevent attacks from escalating into physical consequences. OTCC observed that although private and local operators aren't bound by binding operational directives, a directive would indicate what the government regards as best practice. Eichenbaum added that a robust federal OT baseline would carry influence far beyond government, offering critical infrastructure owners a practical model, supplying vendors with clearer security expectations, and enabling federal procurement to promote secure-by-design products. The report positions mandatory federal standards as a foundation that could reshape security expectations across both public and private sectors managing operational technology. If agencies fail to act, the gap between inventory requirements and actual implementation risks leaving industrial control systems vulnerable at facilities handling public health, border security, and essential services.

