OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
NIST drafted an updated OT security guide while CISA and the FBI warned about risks from third-party ICS integrators.
NIST published a draft of Special Publication 800-82 Revision 4, Guide to Operational Technology (OT) Security, with comments due November 30, 2026. The revision broadens coverage to building automation, water, agriculture, freight rail, maritime, and industrial IoT-cloud convergence, and reorganizes guidance around NIST CSF 2.0, including zero trust and monitoring. CISA and the FBI separately warned operators to restrict third-party ICS integrator access. They cite a March–April 2025 intrusion at a US industrial automation company in which foreign actors staged nine archives containing 800 network schematics, device configurations, and customer records relevant to power and transportation customers.
- SP 800-82 Rev. 4 public comments are due November 30, 2026.
- Revision adds water, rail, maritime, and building-automation coverage.
- Guide is reorganized around NIST CSF 2.0 and zero trust.
- CISA and FBI say integrators should receive least privilege only.
- A 2025 intrusion staged 800 schematics and customer SCADA records.
Full article445 words · extracted from securityweek.com · click to collapse
NIST has published a draft update to its operational technology security guide, and CISA and the FBI have issued a fact sheet on the risks of working with third-party ICS integrators.
NIST this week released a draft of Special Publication 800-82 Revision 4, titled Guide to Operational Technology (OT) Security. Public comments are due by November 30, 2026. The document covers how to secure OT while accounting for the performance, reliability and safety demands specific to these systems.
The revision expands the guide’s sector coverage to include building automation, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and the convergence of industrial IoT and cloud.
The guide is now organized around NIST Cybersecurity Framework 2.0, and the former risk management section has been reorganized to focus on the framework’s Govern function.
NIST also expanded its guidance on implementing OT security controls, including asset management and network monitoring and detection.
The updated version also includes security architecture guidelines for protecting system management functions and applying zero trust principles.
Advertisement. Scroll to continue reading.
CISA and FBI urge scrutiny of ICS integrators
CISA and the FBI published the fact sheet for critical infrastructure owners and operators that work with third-party industrial control system (ICS) integrators. The agencies urge caution when giving integrators high levels of access or control over industrial processes.
They recommend granting users, processes and systems “only the minimum access necessary to perform their assigned tasks, and no more.” Failing to apply the principle of least privilege could expose operators to malicious cyber actors, the agencies say.
The document cites FBI technical analysis of an intrusion at a US industrial automation solutions company. Between March and April 2025, malicious foreign cyber actors gained access to the company’s network. The company provided system integration, engineering consulting and SCADA programming to customers that included power utilities and transportation companies.
During the intrusion, foreign actors searched for SCADA and customer records and staged nine archive files containing 800 network schematics, device configurations, and customer details that could enable downstream disruptive attacks.
The agencies recommend that operators include cybersecurity and supply chain requirements in contracts and service agreements, covering areas such as data storage locations, remote access, and patch management.
They also advise working with integrators to find out where devices are hosted and to reduce exposure, including by disconnecting devices from the public-facing internet. Operators should monitor and log remote access and, where possible, use on-demand remote access.
Related: Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Related: Only 13% of OT Network Segments Are Fully Isolated: Analysis