(TLP:CLEAR) NSA Releases Zero Trust Guidance for Hardening OT Environments, Cites Water Sector Threats
Created: Thursday, October 8, 2026 - 15:06
Categories: Cybersecurity, Federal & State Resources, OT-ICS Security
Summary: NSA has published a Cybersecurity Information Sheet (CSI), “Hardening Department of War (DoW) Critical Operational Technology (OT) Environments with Zero Trust (ZT) Principles,” which translates zero trust into practical, high-impact steps for legacy OT. Zero trust assumes a breach is possible or already present and continuously verifies users, devices, workflows, and communications rather than trusting anything inside a network perimeter. The CSI is written primarily for national security, DOW, and defense industrial base system owners, but its approach applies to any operator running aging control systems, including water and wastewater utilities.
The guidance centers on a problem familiar to the water sector: many OT devices cannot support modern authentication, encryption, or security agents and cannot be patched without disrupting operations. Rather than requiring a hardware overhaul, NSA recommends wrapping legacy assets in external controls, what it calls compensating controls, to achieve zero trust outcomes. The CSI distills the broader DOW zero trust framework down to 26 high-impact activities and organizes them into ten mitigation steps: securing remote access, protecting OT data, inventorying OT assets, enhancing visibility, using OT cyber threat intelligence, hardening smart controllers, strengthening networks through segmentation and monitoring, securing engineering workstations and human-machine interfaces, hardening Active Directory and domain controllers, and verifying controls safely.
NSA also warns that adversaries are beginning to use advanced AI, which the CSI refers to as “super intelligence,” to automate reconnaissance, accelerate exploit development, and run campaigns at greater speed and scale. The agency frames continuous verification and strong visibility as increasingly necessary as those capabilities spread.
Analyst Note: The threats NSA cites to justify this guidance are water-sector threats. The CSI references the joint advisory on Iranian-affiliated actors exploiting programmable logic controllers (PLCs) in the water and wastewater sector through internet-exposed devices and default credentials, and it points to a recent 2026 compromise of a Minnesota water system that prompted widespread password resets and raised concerns that configuration files were taken. It also describes Volt Typhoon’s pattern of compromising IT networks first, then pivoting into OT and pre-positioning for later disruption. These are the exact access paths, exposed remote connections, default passwords, and flat networks that let an intruder reach control systems, that the mitigation steps are built to close.
For utilities, the value here is sequencing. The CSI treats an accurate asset inventory and OT visibility as the foundation everything else rests on, since access and segmentation decisions depend on knowing what is actually on the network and how it communicates. It then prioritizes removing direct internet connections to OT, tightly controlling remote and vendor access with phishing-resistant multi-factor-authentication (MFA) and time-bound approvals, and segmenting networks to limit lateral movement. For verification, NSA stresses passive techniques (configuration audits, log analysis, and SPAN/TAP monitoring) over active scanning, which can disrupt sensitive Level 0 and Level 1 devices. That caution matches the operational reality at most utilities, where uptime and process safety constrain what defenders can test.
Members can use the CSI as a planning document rather than a compliance checklist. A practical starting point is to confirm an accurate OT asset inventory, map which assets communicate outside the OT environment, and verify that no control system component is directly reachable from the internet.
Additional Reading:
- Adapting Zero Trust Principles to Operational Technology (CISA)
- Iranian-Affiliated Cyber Actors Exploit PLCs Across US Critical Infrastructure (AA26-097A)
- Primary Mitigations to Reduce Cyber Threats to Operational Technology (CISA)
- NSA Zero Trust Implementation Guidelines
Related WaterISAC PIRs: 6-12
