Skip to content
CISA Urged to Implement OT Cybersecurity Directive Following Water Utility Attacks

CISA Urged to Implement OT Cybersecurity Directive Following Water Utility Attacks

First seen 6 Oct 2026, 17:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 19:02 UTC
  • •CISA is urged to issue a Binding Operational Directive for OT cybersecurity.
  • •Most federal agencies have not met OMB's requirements for networked device inventories.
  • •The coalition emphasizes the need for clear governance and accountability for OT security.

A coalition of cyber firms and critical infrastructure operators has recommended that the Cybersecurity and Infrastructure Security Agency (CISA) issue a Binding Operational Directive (BOD) to enhance cybersecurity for operational technology (OT) systems in federal agencies. This follows attacks on water utilities earlier in the summer of 2026, which highlighted vulnerabilities in OT systems. The coalition's recommendations include establishing clear governance and accountability for OT security, incorporating OT into existing cybersecurity guidance, and aligning requirements with CISA's performance goals. The Government Accountability Office (GAO) reported that most federal agencies have not complied with Office of Management and Budget (OMB) requirements for managing networked devices, with only seven out of 22 agencies fully addressing these requirements as of September 2026. The lack of a cohesive approach to OT cybersecurity poses significant risks to federal infrastructure, which relies on OT in over 8,000 facilities managed by the General Services Administration (GSA).

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-01
Attacks on water utilities reported
Cyberattacks targeted water utilities, exposing vulnerabilities in operational technology systems.
Cyberscoop
2026-09-30
GAO report on agency compliance released
GAO reported that only seven out of 22 agencies fully complied with OMB's networked device requirements.
files.gao.gov
2026-10-06
Coalition recommends CISA directive
The Operational Technology Cybersecurity Coalition called for a BOD to improve OT cybersecurity practices across federal agencies.
Cyberscoop

More articles in this cluster (3)

Common questions

What is the current status of OT cybersecurity in federal agencies?
Most federal agencies have not fully complied with OMB's requirements for managing networked devices.
What are the recommendations for CISA?
The coalition recommends issuing a Binding Operational Directive to establish minimum cybersecurity practices for OT.
How many agencies have complied with OMB requirements?
As of September 2026, only seven out of 22 agencies have fully addressed all of OMB's requirements.