Today’s briefing covers significant developments in operational technology security, including updated guidance, risk assessments, and regulatory changes impacting industrial and connected systems worldwide.
NIST Drafts Updated OT Security Guide, Broadening Coverage Across Critical Sectors
NIST released a draft revision of SP 800-82, Guide to Operational Technology Security, expanding its scope to include sectors such as building automation, water and wastewater, food and agriculture, freight rail, maritime vessels, and industrial IoT/cloud convergence. The update aligns with NIST Cybersecurity Framework 2.0 and enhances sections on asset management, monitoring and detection, management-function architecture, and zero trust principles. Public comments on the draft are invited through November 30, 2026.
Source: SecurityWeek
CISA and FBI Urge Tighter Controls on Third-Party ICS Integrators
Following a 2025 intrusion targeting an industrial automation solutions company, CISA and the FBI issued guidance recommending critical infrastructure operators enforce least privilege access, cybersecurity and supply-chain clauses in contracts, comprehensive remote-access logging, and minimized internet exposure when working with third-party ICS integrators. The malicious actors accessed SCADA and customer data, highlighting risks associated with third-party integrator relationships. The agencies emphasize on-demand access controls and rigorous monitoring to mitigate threats.
Source: CISA
Forescout Finds IT, OT, IoT and IoMT Convergence Raising Lateral-Movement Risk
Forescout Vedere Labs analyzed network data from over 209 organizations, finding that only 13% of segments with OT devices were exclusive to OT, while most segments contained mixed device types averaging 54 devices each. Camera segments were predominantly mixed as well, with only 2% being camera-only. The convergence of IT, OT, IoT, and IoMT devices increases risks of lateral movement in cyberattacks, prompting recommendations for continuous visibility, clear identification of convergence zones, segmentation enforcement, and monitoring of segmentation drift.
Source: Industrial Cyber
Industrial Leaders Report a Cyber-Resilience Gap Despite Confidence in Containment
A study by Rockwell Automation involving over 1,500 manufacturing companies revealed that while nearly 90% of industrial security leaders are confident in their ability to contain cyber incidents, nearly 50% experienced breaches or attacks within the past year. More than half reported operational disruptions due to cyberattacks, with the most severe incidents causing over 16 hours of downtime at a cost exceeding $100,000 per hour. Complementary Honeywell data cited showed that only 20% of organizations have full visibility into OT assets.
Source: Cybersecurity Dive
EU Cyber Resilience Act Reporting Rules Take Effect for Connected Products
Effective September 11, 2026, the EU Cyber Resilience Act mandates that manufacturers of products with digital elements report actively exploited vulnerabilities or severe product-security incidents within 24 hours, with a detailed follow-up notification due within 72 hours. This regulation covers connected consumer and industrial devices, network equipment, embedded systems, software, IoT products, and certain remote processing services. Comprehensive cybersecurity and conformity requirements will apply from December 11, 2027, including obligations for vulnerability management, security updates, documentation, and ongoing support.
Source: Steptoe
These developments underscore an ongoing need for enhanced visibility, rigorous control of third-party access, and compliance with evolving regulatory mandates to strengthen operational technology security across diverse industrial sectors.