More than 8,000 General Services Administration-managed facilities — including laboratories, hospitals and ports of entry — rely on operational technology (OT) to run HVAC, power, access control, water and building automation systems, the Operational Technology Cybersecurity Coalition (OTCC) told the Cybersecurity and Infrastructure Security Agency (CISA) on October 6.
OTCC urges CISA to issue a binding operational directive
In a report published October 6, the Operational Technology Cybersecurity Coalition (OTCC) asked CISA to set mandatory security requirements for OT across federal civilian agencies by issuing a binding operational directive (BOD). The coalition argued that "no directive sets minimum practices for federal OT" and that CISA currently "lacks visibility into the risks."
Inventory shortfalls: GAO findings and the OMB timeline
The call follows a Government Accountability Office (GAO) report published September 30 that found only seven of 22 civilian agencies reviewed had fully met Office of Management and Budget (OMB) requirements to inventory their networked OT and Internet of Things devices. Those inventories were due by September 2024, and the GAO noted that OMB had not issued updated guidance for fiscal year 2026.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWhat the proposed directive would require
OTCC outlined a set of baseline requirements it wants codified. The proposal would require agencies to designate a senior official or office responsible for OT security and to bring OT risk into enterprise risk management. It would also set a baseline for asset inventory, network segmentation, remote access, configuration management, incident preparedness and verified recovery.
Security experts: remediation, segmentation and the limits of patching
OTCC's priority controls include changing default passwords, multifactor authentication (MFA), segmentation and backups — items the coalition asked CISA to emphasize alongside oversight of the OMB requirements. But the OTCC report does not call for patching or firmware updates, a gap that drew criticism from industry practitioners.
John Gallagher, vice president at Viakoo, warned that an inventory alone would not be enough. "Missing from the OTCC's goals is remediation," he said, cautioning that without automated patch and configuration management, agencies would face backlogs that overwhelm operational teams. Gallagher added that attackers routinely gain entry "through unmanaged default passwords and obsolete firmware."
Louis Eichenbaum, federal CTO at ColorTokens, framed the problem around containment as well as prevention. "Patching remains essential, but we cannot patch our way out of cyber risk," he said, arguing that many industrial devices cannot be patched quickly without disrupting operations and that segmentation is necessary to limit lateral movement from a compromised controller.
How technologists, policymakers, and critical-infrastructure owners will respond
- Technologists and security teams: Will need to reconcile inventories with remediation capacity. Gallagher's warning about backlogs points to an operational gap — agencies that establish asset lists but lack automated patch and configuration tools face mounting work for operational teams.
- Policymakers and regulators: Will see the OTCC request as a direct appeal for a formal CISA mandate. The proposal specifically asks CISA to use a BOD to create a federal baseline and to exercise oversight over OMB inventory requirements that were due in 2024 and lack updated guidance for FY2026.
- Critical-infrastructure owners and vendors: Would receive a federal signal of best practice. Eichenbaum argued a strong federal baseline "would have influence far beyond government," giving owners "a practical model," providing vendors "with clearer security expectations" and allowing federal procurement to "encourage secure-by-design products."
OTCC also positioned the proposed directive as complementary to CISA's CI Fortify resilience initiative, saying a pre-incident baseline would help stop attacks from cascading into physical consequences even as CI Fortify plans for operating through a compromise.
The report sets a clear choice for CISA: codify a minimum federal OT posture through a BOD or leave the federal approach guided primarily by existing, non-binding guidance and uneven agency inventories. The coalition's recommendations and the GAO's audit together frame the near-term decision point — whether the federal government will formalize those minimums and how it will ensure agencies can follow them without creating unmanageable remediation backlogs.
https://www.infosecurity-magazine.com/news/ot-coalition-cisa-mandate-federal/




