Most of us don’t think much about automatic door locks in buildings – except maybe when we forget our security badges at home and have to check in with Security to let us into our office suites. But in the event of a power failure, in most cases, building security teams want those locked doors to fail open. It’s a safety hazard if, say, in an emergency, locked doors prevent a timely exit.
But what about in a prison? Should a power failure alone cause otherwise automatically locked doors – to cells, to guard offices or control rooms – to fail open? And what happens if they do?
The context matters. To protect and secure Operational Technology (OT), it needs unique guidelines outside of general IT cybersecurity best practices. The considerations are similar for Zero Trust across IT and OT, but ultimately different.
New Guidance Defines the Fundamental Difference Between IT and OT
To address the growing concerns OT can have when it fails, CISA, in partnership with the Departments of Energy, State and War released the new Adapting Zero Trust Principles to Operational Technology. These guidelines are a reflection of the fundamental difference between IT and OT.
In creating the guidance, CISA consulted numerous OT experts to identify what would need to be different to implement Zero Trust principles around critical operational technology, and, just as important, what would not work. They funded pilots and built prototypes designed to inform the new guidance around Zero Trust for OT.
This approach is especially important and impactful because OT is integrated into our country’s critical infrastructure and is increasingly in the crosshairs of our adversaries. As our national security priorities continue to include everything from protecting critical infrastructure to creating a national missile defense system, securing OT takes center stage. It really is the nexus between our digital and physical worlds.
Streamlined Approach with No Security Tradeoffs
The new OT guidance remains organized by the same seven pillars of Zero Trust and includes 105 key activities specially designed for OT.
Relative to IT, these specific activities recognize that OT is generally lighter on the processing side; that modern OT is more bespoke and not general purpose; and that many OT systems can’t handle functions like identity certificates, meaning your approach to identity must be very different.
The guidance also accounts for the age of many operational technology environments, particularly in utilities, where both the OT and the surrounding systems are often decades old. It further emphasizes that some OT systems simply cannot go offline, so security fixes must be handled differently than they are in enterprise IT.
This is the right way to think about OT cybersecurity. The life, health and safety risks around a breach of OT systems can be massive. The new guidance adopts context-based, lighter weight implementation guidelines for Zero Trust but with the same heavyweight impact needed for Zero Trust missions.
The Current Threat Environment Demands both Vigilance and Creativity
Without question, the current threat environment is making it impossible for us to continue to treat OT and IT the same. Meeting this moment from a cybersecurity perspective requires the vigilance that a Zero Trust approach provides and the creativity that will be necessary to make Zero Trust for OT a reality. It starts with aligning OT operators and cybersecurity teams and removing the traditional barriers that keep them siloed.
When the stakes are as high as they are with OT and critical infrastructure in the current environment, cyber and OT teams can serve as force multipliers for one another and for our overall national security posture.





