Risk management

NIST updates its Guide to Operational Technology Security with a focus on broader enterprise risk management

September 23, 2026
12 min read

Key Insights:

  • NIST has issued a public draft of its fourth revision of SP 800-82 which provides guidance for securing Operational Technology (OT)
  • The latest draft provides an overview of OT and typical system topologies for various sectors
  • The draft identifies common threats and vulnerabilities faced by organisations relying on OT and recommended security safeguards
  • New sectors include Building Automation and Control Systems (BACS), Water and Wastewater Systems (WWS), food and agriculture, freight rail, maritime vessels, and Industrial Internet of Things (IIoT)
  • The guidance is restructured around the NIST Cybersecurity Framework (CSF) 2.0 and how OT risk management aligns with broader enterprise risk management
  • Reviewers can dive into more than 300 pages and submit feedback and comments by 30 November 2026

NIST has issued its latest (fourth edition) of NIST SP 800-82 and has signalled it is moving away from a purely technical ICS/OT cyber security model and towards an enterprise risk and resilience model with a stronger mapping to CSF 2.0 and the six primary Functions.

A shift to business risk management

The draft puts greater emphasis on:

  1. Alignment with the NIST Cybersecurity Framework (CSF) 2.0 as the organising model
  2. Organisational governance and enterprise risk management for OT environments and the role they play in enabling critical industries
  3. Consequence-driven risk management with a focus on prioritising what could happen to safety, operations, people, the environment and critical services, rather than simply counting technology vulnerabilities
  4. Zero Trust principles, particularly around management functions and access as shown in various architectures and topolgies
  5. The increasing convergence of OT, IT, cloud and IIoT and the resulting risk impacts that could introduce
  6. Expanding NIST's guidance beyond core ICS areas for sectors including water/wastewater, buildings, food and agriculture, freight rail and maritime.

Consequences matter

Rather than treating OT security as a function owned by the engineering and/or cybersecurity teams, this latest draft connects OT risks to top level organisational objectives, business functions and broader enterprise risk management.

OT risk assessment needs to consider what happens if an asset or process is compromised, rather than simply whether the asset has a vulnerability.

For example, a vulnerable engineering workstation controlling a low-consequence process may warrant different treatment from an equally vulnerable system controlling a high-consequence chemical, energy or water process.

In OT, availability, integrity and safety can be more important than confidentiality, and taking a system offline to patch it may itself create operational or safety risk.

An updated risk approach should consider 'What is the consequence if this system is compromised or unavailable?' rather than simply 'How vulnerable is this system?'

Apply Zero Trust where you can

Zero Trust has been the buzzword of the last decade or more and the principles and security architecture have become increasingly well embedded into many mature organisations.

In OT, network segmentation, trusted zones and implicit trust inside the OT network itself has been the standard. Especially in an environment where security controls must not interfere with safety and availability.

The latest guidance takes a stronger view on the application of ZTA and advises apply Zero Trust principles where they can be implemented without compromising OT safety and reliability.

Applying the guidance

It takes time to review changes to a substantial and important publication for high reliability industries.

A simple summary focuses on business processes, visibility, consequences and impacts, access and controls and detecting and recovering safely. A resulting OT security programme ultimately is condensed into six questions:

  1. What do we have?
  2. What does it control?
  3. What happens if it fails?
  4. Who can access it?
  5. Can we detect compromise?
  6. Can we recover safely?

For those assessing their compliance against this new draft, performing a gap assessment and crosswalk against CSF 2.0 would be good initial actions during the review window.

CSF 2.0 adds Govern activities - including ownership, accountability, risk appetite, supply chain considerations and integration with enterprise risk management - and is the big addition in r4 that matters most. Moving on from a control centric view of OT to a world of managing the potential consequences should be the plan for 2027.

Next steps

At 321 pages, it's a beast of a read for those looking to assess the draft and respond to the revisions before the deadline of 30 November 2026.

The document contains extensive information on OT cyber security, numerous architectures for sectors including rail and maritime operations, application of risk management practices and substantial appendices on threats, activities and how these relate to an OT overlay with tailored controls.

Those looking to submit feedback can do so via the comment template at SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security.

Similar posts

Identify. Secure. Assure.

Ready to simplify cybersecurity compliance for critical infrastructure?
Book a demo