← All articles

· Graybridge Software

OT Cyber Coalition Urges CISA to Issue a Binding OT Security Directive

On October 6, 2026, the OT Cybersecurity Coalition asked CISA for a binding operational directive covering US federal civilian agencies. The proposal applies only to the public sector, but its six-part framework is useful to any industrial operator.

OT securityCISAasset inventorysegmentationregulation

According to Industrial Cyber on October 7, 2026, the Operational Technology Cybersecurity Coalition (OTCC) has asked CISA to issue a binding operational directive (BOD) dedicated to OT security. The directive would cover civilian agencies of the US federal executive branch (FCEB). The coalition's statement was released on Tuesday, October 6.

The request is set out in the report "Know It. Control It. Contain It.: A Binding Operational Directive for OT Cybersecurity". It is worth stating up front that this is a proposal: CISA has made no commitment, and the directive, if it comes, would apply only to federal agencies.

The six components of the proposed baseline

The report proposes a prevention and containment baseline made up of six parts:

  • visibility into OT assets;
  • network segmentation;
  • enforceable remote access controls;
  • configuration baselines;
  • incident preparedness;
  • verified backup and recovery.

Other recommendations include appointing senior executives accountable for OT security, stronger CISA oversight of how agencies implement the requirements, prioritizing basic measures such as multi-factor authentication and replacing default passwords, and applying cyber-informed engineering principles to federal OT.

Why now

A GAO report dated September 30 found that only 7 of 22 civilian agencies had fully met OMB requirements for inventorying networked OT and IoT devices, with a deadline set for September 2024. According to the OTCC, existing directives (BOD 23-01, 23-02 and 26-04) cover OT only partially and none sets consistent minimum practices, leaving CISA with limited visibility into agencies' security posture.

The coalition also points to IT/OT convergence, Chinese actors pre-positioned in critical infrastructure, and the way artificial intelligence lowers the barrier to sophisticated attacks. In its view, these are reasons why an OT-specific directive is already overdue.

The scale is significant: agencies depend on more than 8,000 facilities owned or leased and managed by GSA, including laboratories, hospitals, research campuses and border points of entry. The systems involved cover energy, water, access control and building automation.

The accountability problem

Tatyana Bolton, executive director of the OTCC, stated:

"you can't secure what you can't see, and most federal agencies still can't see their OT."

Michael Garcia, policy director, noted that OT often falls into a gray area between the CIO's office and facilities management: "when no one owns it, no one secures it".

What industrial operators can take from it

Although the directive does not apply to private companies, the baseline works as a practical checklist for any plant or infrastructure. The GAO finding is a reminder that asset inventory remains the weak point even when a formal obligation exists. Some concrete steps:

  • build and maintain an up-to-date inventory of devices, controllers and connections;
  • separate networks into well-defined zones with explicit communication rules;
  • govern remote access with strong authentication and traceability;
  • document reference configurations so deviations can be detected;
  • actually test backups and recovery procedures, rather than just planning them;
  • assign a clear owner for OT security, bridging the divide between IT and operations.

Whether CISA will accept the proposal remains to be seen. In the meantime, the OTCC's message is useful beyond the federal perimeter: without visibility and clearly defined accountability, the other measures are unlikely to hold.