THE CRUNCH

A coalition of cybersecurity experts is pressing CISA to issue a binding operational directive requiring federal agencies to meet baseline security standards for operational technology, the systems used to monitor and control critical infrastructure. The Operational Technology Cybersecurity Coalition made the call in a white paper published on Tuesday, arguing that voluntary guidance has not closed the gap. It pointed to recent cyberattacks on hundreds of water systems in at least 12 US states as evidence that OT has become a target for both nation states and cybercriminals, with affected devices often connected to the internet, using default or missing passwords, and lacking network segmentation.

Federal civilian agencies operate more than 8,000 owned or leased buildings, including laboratories, hospitals, research facilities and ports of entry, all running HVAC, power, access control, water and building automation systems. Most agencies currently govern these systems themselves, leaving CISA with no visibility into their security posture. The coalition cited a Government Accountability Office study finding that only 7 of 22 civilian agencies reviewed had fully met White House requirements to inventory their networked OT and Internet of Things devices, with the inventories due in September 2024.

The proposed eight-page baseline covers visibility into OT assets, network segmentation, enforceable remote access controls, configuration baselines, incident preparedness and verified backup and recovery. OTCC also wants each agency to designate a senior official or unified office responsible for OT inventory, baselines and incident readiness. "Operational technology too often falls into a gray zone between the [Chief Information Officer's] office and facilities management, and when no one owns it, no one secures it," said Michael Garcia, the coalition's policy director.

Several outside OT security experts told the outlet that ownership is the paper's key element, since every other recommendation assumes someone is accountable to act. CISA declined to comment, though Garcia said the coalition engaged with the agency while drafting the paper and shared a final copy before publication. Binding operational directives apply to federal civilian agencies rather than private or local entities, but the coalition argues they still signal what the government considers best practice.

WHAT HAPPENS NEXT

CISA has not said whether it will act, having declined to comment on the paper.