A coalition of operational technology experts is pressing CISA to issue mandatory federal rules for securing OT systems. In a new white paper, the Operational Technology Cybersecurity Coalition argues that voluntary guidance has failed and that a binding operational directive would give agencies an enforceable baseline while giving CISA visibility into compliance.

The group points to recent cyberattacks on water systems across at least 12 states as a warning that OT is now a prime target. It also cites a government watchdog finding that only 7 of 22 civilian agencies fully met White House requirements to inventory networked OT and IoT devices, with inventories due in September 2024. Federal civilian agencies operate thousands of buildings with HVAC, power, access control, water, and building automation systems.

The paper recommends requiring agencies to name a senior official accountable for OT security, maintain asset inventories, segment networks, enforce remote access controls, and develop backup and recovery plans. "Operational technology too often falls into a gray zone between the CIO's office and facilities management," said Michael Garcia, OTCC policy director. Other experts echoed that ownership is the central issue, saying a directive could force agencies to assign responsibility in a way another round of guidance would not. CISA declined to comment on the paper.