The Operational Technology Cybersecurity Coalition (OTCC) announced that Copia Automation has joined the coalition, bringing a backup-and-recovery lens to OTCC’s growing network of organizations working to secure the nation’s critical infrastructure.
Copia builds automated, versioned backups of PLC and controller code, paired with version control designed specifically for the plant floor: baseline integrity, full change history, drift detection, and a verified last known good state operators can restore to with confidence. The company describes its focus as closing the “recovery gap,” the window between when an incident is detected and when operations are fully restored.
“Too much of the conversation around OT security stops at prevention and detection, but the moment that actually determines the outcome of an incident is recovery,” said Tatyana Bolton, executive director of OTCC. “Copia has built real depth on that side of the problem, and their perspective rounds out the kind of end-to-end thinking this coalition is trying to bring to policymakers.”
“Collaboration with peers in the industry is paramount to securing our critical infrastructure. Copia’s primary focus is bridging the recovery gap, the space between ‘we’ve detected an incident’ and ‘we’ve successfully restored operations,’” said Adam Gluck, CEO and founder of Copia Automation. “Through the OTCC, we will be able to provide insights and contributions that can help protect our nation’s critical infrastructure. This mission takes a village; no single organization can do it alone.”
With Copia’s addition, OTCC continues to grow a membership spanning the full OT security lifecycle, united around advancing sound public policy for critical infrastructure.
Copia Automation addresses the recovery gap for industrial organizations by providing automated, versioned backups of PLC and controller code that are verified for restoration. Its version-control capabilities are designed for plant-floor environments and include baseline integrity, change history, drift detection, and a verified last known good state. These capabilities are intended to help organizations restore operations following disruptions caused by cyber threats or configuration changes, rather than rebuilding control-system configurations from scratch. As adversaries increasingly target critical infrastructure, reducing the time required to recover industrial operations can help limit the operational impact of an incident.
From the perspective of OT backup and recovery, the pattern is consistent. Operators know they need validated, recoverable backups for their assets. What they often lack is the budget line and staff hours to establish those capabilities and keep them current. Clear requirements are the right starting point, while pairing them with funding is what makes them sustainable.
Most critical infrastructure owners and operators run lean teams, so support needs to accompany the expectation. Copia detailed that tax breaks, incentives, and direct financial aid could move OT security and recovery readiness from an aspiration to something these organizations can realistically achieve. Federal agencies conducting their own operational technology work face the same constraint, which is why any requirement directed at them is most effective when supported by appropriated dollars rather than absorbed into an existing operating budget.
Recovery also deserves to be named explicitly in any mandates. Prevention and detection tend to receive the most attention, but the question that determines how an incident ends is how quickly a plant, substation, or treatment facility can restore last known-good configurations and resume safe operations. Requirements calling for tested, offline-capable, regularly validated OT backups, along with documented and exercised recovery time objectives, give operators something concrete to fund and demonstrate.
Funding goes further when operators have a clear picture of what is being asked of them. Many answers to sector-specific regulators, state authorities, and several federal agencies at once, and consolidating those expectations into a coherent framework could free up scarce staff capacity for the work itself. One clear set of obligations that a lean team can understand, implement, and demonstrate compliance with, paired with the funding needed to carry them out.


