cisatrade-pressNewsThe Broadside2 min read

OT coalition demands CISA binding directive on agency OT security

When private-sector OT vendors formally ask the government to compel the government to secure its own operational technology, the voluntary-guidance era has run out of road.


TL;DR

The Operational Technology Cybersecurity Coalition on Friday asked CISA to issue a binding operational directive establishing baseline OT security requirements for federal civilian agencies. The request follows Iran-linked attacks on more than 30 water utilities across seven states, and comes one day after CISA warned utilities to take exposed PLCs offline. The coalition also called on Congress to renew the State and Local Cybersecurity Grant Program and extend the Cybersecurity Information Sharing Act of 2015, both set to expire in September. A BOD would bind only federal agencies, not the municipal water utilities actually being targeted, but the coalition argues it would set a floor the private sector could follow.

The request, delivered Friday by OTCC Executive Director Tatyana Bolton (a former CISA cyber policy official) represents a notable inflection. Industry is no longer asking the government to lead by convening working groups or publishing advisories. It's asking the government to bind itself.

"No clearer call to action has existed in the operational technology space," Bolton told Nextgov/FCW. The coalition's core ask is straightforward: a Binding Operational Directive under CISA's authority that mandates federal civilian agencies inventory and secure OT assets, the PLCs, HMIs, SCADA interfaces, and building-management controllers that run physical infrastructure on federal properties.

What a BOD would and wouldn't do

The jurisdictional gap is the first thing to understand about this request. BODs apply to federal civilian agencies, not state and local governments. The water utilities hit in Minnesota (30-plus systems across that state alone, with the FBI confirming incidents in at least seven states) are outside a BOD's reach entirely. The coalition knows this. Its argument is that federal adoption would establish procurement and architecture standards that cascade, and that the alternative (another advisory, another voluntary framework) has been tried.

CISA updated its April advisory on July 22 to expand coverage beyond Rockwell Automation PLCs to include Schneider Electric, Siemens, and other manufacturers. On Thursday, the agency warned WaterISAC members to remove exposed industrial-control equipment from the internet. Both moves are non-binding.

The September cliff

The coalition tied its BOD request to two legislative deadlines. The State and Local Cybersecurity Grant Program and CISA 2015 both sunset at the end of September. OTCC's language on the grant program was blunt: "By not extending this grant program, Congress is leaving small towns to protect themselves from nation-state actors like Iran." The information-sharing law underpins the threat-intelligence pipeline that lets CISA identify campaigns like the current PLC exploitation activity and warn potential victims. Letting it lapse while Iran-linked actors are actively locking operators out of water-treatment controls would be, in the coalition's framing, a self-inflicted wound.

What the BOD can't solve

The attacks that triggered this request exploited internet-exposed PLCs, a problem CISA has been flagging since at least December 2023, when the IRGC-affiliated advisory warned of the same tactic against water and wastewater systems. Getting federal agencies to inventory OT assets behind secure gateways would be progress, but it doesn't close the exposure gap for the 50,000-plus community water systems across the U.S., most of which are small, municipally owned, and dependent on grant funding that expires in two months.

The coalition also urged confirmation of Andrew McClure to lead DOE's Office of Cybersecurity, Energy Security, and Emergency Response. That nomination sits alongside the grant and CISA 2015 extensions as a clock-running item.

CISA has not responded to the coalition's request for comment.


Published ·Updated ·Deep Fathom