NIST Expands OT Security Guidance to Broader Critical Infrastructure
NIST has released a draft revision of its OT security guide, expanding its scope to cover additional critical sectors. The update reflects evolving risks and regulatory changes affecting industrial and connected systems globally. Organizations are advised to review the draft guidance to align their security practices.
The draft revision of NIST SP 800-82 marks a notable shift from traditional industrial sectors to include building automation, water systems, agriculture, rail, maritime, and converged IT/OT cloud environments. It also aligns with the updated NIST Cybersecurity Framework 2.0, emphasizing asset visibility, continuous monitoring, and zero trust architectures. Separately, CISA and the FBI have highlighted risks from third-party ICS integrators, recommending strict access controls and contractual security clauses after a 2025 breach exposed SCADA data. Forescout’s analysis of over 200 organizations found that most network segments mix OT with IT, IoT, and IoMT devices, increasing lateral movement opportunities.
This guidance could reshape how critical infrastructure operators prioritize security investments, especially as IT/OT convergence widens attack surfaces. Smaller sectors like food and water may face new compliance pressures, while integrators might see stricter contractual obligations. The emphasis on zero trust and monitoring may improve resilience against ransomware and supply-chain attacks, but could also strain resources for organizations with legacy systems. Ultimately, broader adoption of these practices may reduce systemic risks, though uneven implementation could leave gaps.