IC Technology & Cyber — 2026-10-07
CISA Urged to Issue First Binding Directive for Federal Operational Technology After Summer Water Utility Attacks
BLUFCISA is very unlikely to issue a standalone OT Binding Operational Directive by late January 2027, leaving the coalition's push as an industry lobbying signal rather than an imminent policy shift.
The Operational Technology Cybersecurity Coalition, which represents OT security firms and critical infrastructure operators, urged CISA to issue a Binding Operational Directive setting baseline security requirements for operational technology across federal civilian agencies 12. Nextgov/FCW reported the call followed suspected Iran-linked intrusions affecting more than 30 Minnesota water utilities, and the FBI said it is aware of incidents at water entities in at least seven states 1. In its paper, published Tuesday, the coalition recommended that the directive name an accountable OT security officer at each agency, draw on existing federal guidelines, and set minimum practices 2. The coalition does not assert such a directive would have prevented the summer attacks, and CISA did not respond to requests for comment 12.
AnalysisCISA is
very unlikely to issue a Binding Operational Directive specifically addressing operational technology security by January 31, 2027. We have high confidence in this judgment because the coalition's paper is a lobbying position, CISA has made no commitment, and no draft or timeline has surfaced. CISA has also folded OT requirements into earlier directives, which weakens its incentive to write a standalone one. Both outlets draw on the coalition's own account, so their agreement reflects one origin, not independent confirmation. The coalition concedes a directive would not have stopped the water attacks and would not reach the utilities hit, so its value is as a private-sector signal. CISA may be more receptive than its silence suggests, since the coalition says agency officials increasingly see the need, and further water-sector intrusions could accelerate action. If no directive comes, agencies keep the current OMB requirements, which GAO found most have not implemented, and lobbying shifts to Congress.
2 sources
- Cyber industry coalition urges federal action after suspected Iran-linked water hacks - Nextgov/FCW
- How experts think CISA should tell agencies to protect OT - CyberScoop
View in full brief →