The Operational Technology Cybersecurity Coalition (OTCC) called on the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to issue a binding operational directive establishing mandatory, enforceable cybersecurity requirements for operational technology (OT) across Federal Civilian Executive Branch (FCEB) agencies. The coalition proposed a security baseline covering OT asset visibility, network segmentation, remote access controls, configuration baselines, incident preparedness, and verified backup and recovery. OTCC said existing directives address some OT security requirements but do not establish consistent minimum practices across federal agencies, limiting CISA’s visibility into their security posture.
In a report titled ‘Know It. Control It. Contain It.: A Binding Operational Directive for OT Cybersecurity,’ the OTCC suggests a prevention and containment baseline built on visibility into OT assets, network segmentation, enforceable remote access controls, configuration baselines, incident preparedness, and verified backup and recovery. CISA has folded some OT requirements into earlier directives, but no BOD yet sets consistent minimum security practices for federal OT. Agencies largely govern these systems on their own, leaving CISA without consistent visibility into their security posture. As AI lowers the barrier to sophisticated attacks, the report argues, it is time for a directive focused solely on OT.
The coalition’s call follows a Sept. 30 report by the U.S. Government Accountability Office (GAO), which found that only seven of 22 civilian agencies reviewed had fully met Office of Management and Budget requirements to inventory their networked OT and Internet of Things devices, despite a September 2024 deadline.
OTCC said federal agencies rely on more than 8,000 General Services Administration-managed owned and leased facilities, including laboratories, hospitals, research campuses and ports of entry, supported by systems for power management, water, access control and building automation. Its recommendations include assigning senior officials responsibility for OT security, strengthening CISA oversight of agency implementation, prioritizing controls such as multifactor authentication and changing default passwords, and applying cyber-informed engineering principles across federal OT.
“GAO just confirmed what OT practitioners have been warning about for years: you can’t secure what you can’t see, and most federal agencies still can’t see their OT,” Tatyana Bolton, executive director of OTCC, said in a Tuesday media statement. “Guidance alone hasn’t closed that gap. A binding operational directive would give every agency a clear, enforceable baseline and give CISA the visibility to make sure it actually gets done.”
“Operational technology too often falls into a gray zone between the CIO’s office and facilities management, and when no one owns it, no one secures it,” said Michael Garcia, policy director of OTCC. “Our recommendations are practical by design. Name an accountable official, build on requirements agencies already have, and prioritize the basics that matter most in the incidents we’ve seen, like changing default passwords and segmenting networks.”
The OT Cyber Coalition argues that CISA should issue a binding operational directive focused solely on operational technology security. It acknowledges that CISA has folded OT requirements into earlier directives, such as BODs 23-01, 23-02, and 26-04, along with extensive technical guidance. But it says that as IT and OT converge, Chinese actors remain pre-positioned in critical infrastructure, and AI lowers the technical barriers to sophisticated attacks; a dedicated OT directive is now overdue. The concern is that adversaries can find weaknesses, speed up reconnaissance, and move laterally through poorly segmented operational environments faster and at greater scale.
The Coalition lays out three systemic challenges that justify the directive. The first is widespread risk: the Federal Civilian Executive Branch relies on more than 8,000 GSA-managed owned and leased facilities, including laboratories, hospitals, research campuses, warehouses, and ports of entry. The OT in these facilities, such as HVAC, power management, access control, water systems, and building automation, is essential to safety and mission continuity during cyber incidents. Yet CISA currently lacks a holistic view of the assets agencies manage and the risks they face, including connected programmable logic controllers.
The second challenge is inconsistent implementation. Federal agencies retain broad discretion over how they secure OT, and no existing BOD sets consistent minimum practices or requires agencies to demonstrate implementation. As a result, CISA lacks visibility into the security posture of federal OT. The Government Accountability Office recently found that most agencies have not implemented the Office of Management and Budget’s 2023 security requirements for network devices for OT systems. GAO warned that these agencies may continue to struggle to apply appropriate controls, make informed risk-based decisions, and respond to incidents.
The third challenge is unacceptable consequences. Cyber incidents affecting OT can threaten safety, disrupt essential government services, endanger personnel, and undermine continuity of operations, as attacks on U.S. water and wastewater systems have shown. The National Security Agency judged this risk unacceptable and, in 2024, issued BOD 2024-001 as National Manager for National Security Systems, setting OT security implementation, reporting, inventory, and minimum-control requirements. The Coalition says an OT-focused BOD would also help CISA advance President Trump’s National Resilience Strategy by reducing risk and improving reliability of infrastructure and key services.
Finally, the Coalition says federal policy must pair operational continuity during an attack with proactive defense before an intrusion occurs. Recent policy discussion has leaned toward resilience initiatives meant to keep critical functions running under fire, which is essential but covers only half of a complete cybersecurity architecture. For that reason, it endorses the CI Fortify approach, which prepares for assumed compromise, telecommunications disruption, isolation, continued operations, and recovery.
The Coalition recommends that CISA establish an OT BOD requiring Federal Civilian Executive Branch entities with OT systems and assets to achieve specific cybersecurity goals. Its first recommendation is to establish clear organizational ownership and accountability for OT environments. Because operational technology often falls into a governance gray zone between Chief Information Officers and physical facilities managers, the Coalition argues that CISA must mandate clear administrative ownership.
To do this, the directive should require agencies to formally designate a senior official or unified office responsible for the cybersecurity governance of all agency-managed and GSA-leased OT systems. That responsibility would cover asset inventory validation, configuration baselines, backup and recovery, incident preparedness, and risk reporting. The directive should also require agencies to integrate OT risk registers into their overarching enterprise risk management frameworks, so that critical infrastructure dependencies are no longer siloed from traditional IT security oversight. Finally, it should ensure coordination between CIOs and those responsible for OT security and resilience.
The Coalition also recommends that CISA review existing federal requirements for inclusion in the BOD. First, CISA should examine the requirements in the National Security Agency’s BOD 2024-001 to determine which of them apply to the Federal Civilian Executive Branch. Second, it should enforce compliance with previously issued BODs that apply to OT environments.
Third, CISA should require implementation of OMB Memo 24-04, the Fiscal Year 2024 Guidance on Federal Information Security and Privacy Management Requirements. A 2026 GAO report found that poor implementation of the memo, combined with a lack of further guidance, left agencies without a clear imperative to prioritize the requirements or a timeline for doing so. OMB also did not oversee implementation of the memo. The Coalition suggests that CISA, through the BOD, could ensure that FCEB agencies comply with the OMB memo and oversee its implementation.
The Coalition also recommends that the BOD align its requirements with the Cybersecurity Performance Goals (CPGs) and help agencies prioritize their implementation. It suggests that CISA could take a page from BOD 26-04, Prioritizing Security Updates Based on Risk, and develop a similar process for entities to prioritize CPG implementation. CISA could also create OT-specific CPGs, similar to the existing sector-specific ones.
In lieu of OT-specific CPGs, the Coalition says CISA should review previous OT cyber incidents and causes of disruption, then recommend that the FCEB prioritize a defined set of CPGs. The first group covers managing risks from managed service providers, managing organizational assets, and obtaining independent validation of cybersecurity controls.
The second group focuses on identity and access management. It includes changing default passwords, establishing minimum password strength, creating unique credentials, implementing multifactor authentication, monitoring unsuccessful automated login attempts, and implementing the principles of least privilege. The third group consists of CPGs that would put CI Fortify principles into practice. These are managing incident response plans, implementing logical and physical network segmentation, maintaining system backups and restoration capability, and formalizing incident planning and preparedness.


