Security1 publisher2 min readPublished
OT coalition urges CISA to make every federal agency name an owner for OT security
OT Cybersecurity Coalition urges CISA to issue a binding directive requiring each federal agency to name an OT security owner and meet minimum practices. The push follows GAO's finding that most civilian agencies have not enacted OMB's 2023 IoT and OT requirements.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The coalition grounds its case in CISA's limited visibility into federal OT devices, inconsistent OT security policy across agencies, and the severity of an attack on federal OT.
- Federal OT spans 8,000 GSA-owned and -leased properties, many with systems for power supply and for heating, ventilation and air conditioning.
- Under the proposal, CISA would check whether past NSA OT guidelines should apply to civilian agencies and align requirements with its 2022 cybersecurity performance goals.
- CISA did not respond to a request for comment on Monday, before the coalition published its paper.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Until each agency formally names an OT security officer, building controllers stay in what the coalition calls a government gray zone between CIOs and facilities managers.
- constraint Water utilities hit this summer gain nothing directly from a federal directive; the coalition itself does not claim one would have stopped those attacks.
- precedent A federal OT baseline would give private owners and operators a list to demand from their own providers, the second goal Garcia set for the directive.
- decision CISA has to decide whether an OT-only directive adds enough beyond the OT requirements already written into BODs 23-01, 23-02 and 26-04.
The Operational Technology Cybersecurity Coalition starts from inventory. Its paper says CISA "does not currently have a holistic view of the assets managed by the FCEB and the potential risks, such as connected programmable logic controllers, to which the government may be exposed." [10] Garcia acknowledged that some federal OT systems might be "trivial." [9]
The threat case is about speed. The paper argues that "as AI reduces the technical barriers to sophisticated cyber operations, enabling adversaries to identify weaknesses, accelerate reconnaissance, and move laterally through poorly segmented operational environments with greater speed and scale, it is time for an encompassing BOD solely focused on OT security." [15] The coalition offers that as a forecast. Its members are cyber firms and critical infrastructure operators. [1]
The firmer evidence is GAO's. Last month the watchdog concluded that most federal civilian executive branch agencies have not enacted the requirements OMB released in 2023 for networked IoT and OT devices. [4] A directive would go to the same agencies. [2] CyberScoop's account of the recommendations does not include deadlines or reporting milestones. [2] [12]
Michael Garcia, the coalition's policy director, until recently worked at CISA, and he gave two goals for the recommendations. [5] "One, it does make sure that the government is taking its own medicine," Garcia said. "You should practice what you preach." [6]
He has also been talking to the agency. In those discussions, Garcia said, "increasingly, I think they understand that there might be a need" for an OT directive. [17]
What to watch
- A CISA statement on whether it will draft a directive focused solely on OT security.
- Agency responses to GAO on enacting OMB's 2023 requirements for networked IoT and OT devices.
- Whether any draft directive extends NSA's OT guidance to civilian agencies or stays aligned with CISA's 2022 performance goals.