NSA urges zero trust controls for operational technology systems

NSA urges zero trust controls for operational technology systems

NSA released new guidance for applying zero trust controls to operational technology used in critical infrastructure.

Format News Brief
Read Time 3 min
Category Cyber Security
Updated Oct 09, 2026

The National Security Agency has released new guidance for applying zero trust principles to operational technology, the industrial systems used in power, water, transportation, agriculture, public health and government facilities. The October 8 advisory is aimed first at National Security Systems, Department of War environments and the Defense Industrial Base, but NSA says the same guidance is also relevant for technical leaders and OT administrators outside those groups.

The practical shift is simple to state and harder to execute. Instead of treating a plant network, device segment or trusted user account as safe by default, the guidance asks operators to assume compromise is possible and keep verifying users, devices, workflows and communications. NSA says that approach can reduce unauthorized access, lateral movement and long term persistence inside environments where old equipment, uptime requirements and specialized vendor access often make ordinary IT security models difficult to copy.

Why OT teams should care

Operational technology has a different risk profile from office IT. A failed business application can disrupt work. A failed industrial process can affect electricity, water treatment, transportation or health services. NSA explicitly warns that attacks against these systems can aim to deny, degrade, disrupt, deceive or destroy critical infrastructure, not just steal information.

The agency also connects the guidance to the rise of what it calls super intelligence in OT. Its concern is not only that defenders may add more automation to industrial environments. NSA says adversaries are also using advanced AI capabilities to speed reconnaissance, exploit development and cyber campaigns. That makes identity checks, segmentation, least privilege access, device validation and continuous monitoring more important because the attacker may move faster than a manual response process.

The CyberOGZ read

For operators, the useful decision rule is to start with the paths that would matter most during an incident. Remote maintenance access, engineering workstations, historian servers and links between corporate IT and plant networks deserve earlier attention than broad policy rewrites. Zero trust in OT will rarely mean replacing everything at once. It will usually mean tightening access around the systems that can change physical processes, then proving those controls do not break safety or availability.

The guidance is also a reminder for vendors building AI features into industrial products. Cybersecurity claims will need to cover the surrounding control boundary, not only the model or dashboard. Buyers should ask how a product verifies operators and devices, how it limits movement after a compromised account, and what logs remain available when a site is under stress.

Sources

Cover photo by Shameer Vayalakkad Hydrose on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...