NIST has published a draft update to its operational technology security guide, and CISA and the FBI have issued a fact sheet on the risks of working with third-party ICS integrators.
NIST this week released a draft of Special Publication 800-82 Revision 4, titled Guide to Operational Technology (OT) Security. Public comments are due by November 30, 2026. The document covers how to secure OT while accounting for the performance, reliability and safety demands specific to these systems.
The revision expands the guide’s sector coverage to include building automation, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and the convergence of industrial IoT and cloud.
The guide is now organized around NIST Cybersecurity Framework 2.0, and the former risk management section has been reorganized to focus on the framework’s Govern function.
NIST also expanded its guidance on implementing OT security controls, including asset management and network monitoring and detection.
The updated version also includes security architecture guidelines for protecting system management functions and applying zero trust principles.
CISA and FBI urge scrutiny of ICS integrators
CISA and the FBI published the fact sheet for critical infrastructure owners and operators that work with third-party industrial control system (ICS) integrators. The agencies urge caution when giving integrators high levels of access or control over industrial processes.
They recommend granting users, processes and systems “only the minimum access necessary to perform their assigned tasks, and no more.” Failing to apply the principle of least privilege could expose operators to malicious cyber actors, the agencies say.
The document cites FBI technical analysis of an intrusion at a US industrial automation solutions company. Between March and April 2025, malicious foreign cyber actors gained access to the company’s network. The company provided system integration, engineering consulting and SCADA programming to customers that included power utilities and transportation companies.
During the intrusion, foreign actors searched for SCADA and customer records and staged nine archive files containing 800 network schematics, device configurations, and customer details that could enable downstream disruptive attacks.
The agencies recommend that operators include cybersecurity and supply chain requirements in contracts and service agreements, covering areas such as data storage locations, remote access, and patch management.
They also advise working with integrators to find out where devices are hosted and to reduce exposure, including by disconnecting devices from the public-facing internet. Operators should monitor and log remote access and, where possible, use on-demand remote access.
Related: Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Related: Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
Related: Only 13% of OT Network Segments Are Fully Isolated: Analysis


