
The Operational Technology Cybersecurity Coalition (OTCC) is releasing Know It. Control It. Contain It.: A Binding Operational Directive for OT Cybersecurity, a report calling on the Cybersecurity and Infrastructure Security Agency (CISA) to issue a BOD setting mandatory, enforceable security requirements for operational technology (OT) across Federal Civilian Executive Branch (FCEB) agencies.
The report lays out a prevention and containment baseline built on visibility into OT assets, network segmentation, enforceable remote access controls, configuration baselines, incident preparedness, and verified backup and recovery.
CISA has folded some OT requirements into earlier directives, but no BOD yet sets consistent minimum security practices for federal OT. Agencies largely govern these systems on their own, leaving CISA without consistent visibility into their security posture. As AI lowers the barrier to sophisticated attacks, the report argues, it is time for a directive focused solely on OT.
OTCC's report recommends that CISA issue a BOD that:
- Establishes clear OT governance and accountability, requiring agencies to designate a senior official or unified office responsible for OT asset inventory, configuration baselines, backup and recovery, incident preparedness, and risk reporting, and to bring OT risk into enterprise risk management.
- Incorporates OT more broadly across existing guidance, building on the National Security Agency's BOD 2024-001 for national security systems, enforcing prior BODs that apply to OT, and giving CISA a role in overseeing agency implementation of OMB's networked device requirements.
- Aligns CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) to OT needs and prioritizes implementation, focusing on the controls most relevant to recent OT incidents, such as changing default passwords, multifactor authentication, network segmentation, and maintaining system backups.
Feedback on the proposal drew commentary from throughout the cybersecurity sector.
John Gallagher, VP at Viakoo
"This initiative has the correct aim, which is to create a set of security practices specific to OT systems at a time when AI has greatly reduced the barriers for OT and IoT systems to be compromised and exploited. Too often, OT/IoT security teams operate outside the CISO’s governance, meaning critical physical infrastructure escapes traditional IT compliance frameworks like BOD 26-04.
"Missing from the OTCC’s goals is remediation, which because of AI-driven threats should be the focus. In recent OT incidents, adversaries rarely need zero-days; they routinely breach networks through unmanaged default passwords and obsolete device firmware.
"A mandate requiring an OT inventory without enforcing automated patch, firmware, and configuration management will simply create massive, unactionable vulnerability backlogs that overwhelm operational teams. Historically, operators avoid touching OT endpoints out of fear of disrupting critical operational uptime.
"Any efforts on BOD’s should focus on automation and autonomous methods. Manual maintenance can’t address the scale that OT/IoT exists at, and also introduces more operational risk and human error than automation."
Louis Eichenbaum, Federal CTO at ColorTokens
"CISA should take a clear leadership role in establishing a consistent cybersecurity baseline for federal operational technology. Today, agencies operate OT environments that support buildings, laboratories, transportation systems, water, energy, and other essential government functions, yet there is no single Binding Operational Directive establishing minimum practices across those environments.
"Allowing every agency to address OT independently creates inconsistent defenses and prevents CISA from developing the visibility it needs to understand risk across the federal enterprise. The federal government must lead by example.
"A well-designed OT directive would establish measurable expectations around asset inventory, accountable leadership, secure remote access, configuration management, segmentation, incident preparedness, and verified recovery. These are foundational safeguards, not aspirational standards, and agencies should be able to demonstrate that they are implemented and effective.
"OT also requires a different operating model than traditional IT. Many industrial devices cannot be patched quickly, or sometimes at all, because updates may disrupt availability, affect safety certifications or require operational shutdowns.
"Patching remains essential, but we cannot patch our way out of cyber risk. Agencies need a strategy for containment as well as remediation. CISA’s own performance goals recognize compensating controls such as segmentation and monitoring when OT systems cannot be patched safely.
"That makes segmentation one of the most important elements of a potential directive. Agencies should understand their authorized OT communication flows and enforce policies that block everything else. If an adversary compromises one workstation, engineering system or controller, that foothold should not become an unrestricted pathway into the rest of the environment. Segmentation breaks up attack paths, limits lateral movement and reduces the blast radius helping essential operations continue while responders contain and remediate the incident.
"Although CISA’s binding directives apply to certain Federal Civilian Executive Branch agencies, not privately operated critical infrastructure, a strong federal OT baseline would have influence far beyond government. It would give critical-infrastructure owners a practical model, provide vendors with clearer security expectations and allow federal procurement to encourage secure-by-design products."




















