Skip to content
Bellator Cyber Guard
News6 min readStandard

NIST Revises OT Security Guide, CISA Flags ICS Risk

NIST's draft Revision 4 of its OT security guide is open for comment through November 30, 2026, as CISA and the FBI issue guidance on ICS integrator risk.

By Bellator Cyber Guard Security Team
NIST Revises OT Security Guide, CISA Flags ICS Risk - nist security standards revision 2026 update 2026

NIST Opens Comment Period on Revised OT Security Guide

The National Institute of Standards and Technology (NIST), the federal agency that develops cybersecurity standards and guidelines for U.S. industry and government, has released a draft Revision 4 of its operational technology (OT) security guide for public comment, according to SecurityWeek. Operational technology refers to the hardware and software that monitors and controls physical processes, such as programmable logic controllers on a factory floor, building automation systems in a hospital, or pump controls at a water utility. Comments on the draft are open through November 30, 2026.

This guide, known in its current published form as NIST Special Publication 800-82, is the primary federal reference document that organizations use to secure industrial control systems (ICS) and other OT environments separately from standard IT networks. The prior major update, Revision 3, was finalized in 2023, so a new draft revision signals that NIST believes the threat landscape and available defensive practices have shifted enough to warrant another round of updates. The specific technical changes proposed in Revision 4 were not detailed in the available reporting, so organizations that rely on this guide should review the draft directly once it is published on the NIST website rather than assume any particular change.

Separately, the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued guidance aimed at ICS system integrators, the third-party firms that design, install, and maintain industrial control systems for asset owners in sectors like manufacturing, energy, and water treatment. The exact contents of that advisory were not detailed in the source material Bellator Cyber Guard reviewed for this analysis, so we are not characterizing its specific findings or recommendations here. What is clear is that federal agencies are treating the integrator layer, not just the end-user asset owner, as a distinct point of cybersecurity accountability in industrial environments.

Key Takeaway

NIST's draft Revision 4 of its OT security guide accepts public comment through November 30, 2026. Organizations that operate industrial control systems, building automation, or connected medical equipment should plan to review the draft once available and consider submitting feedback, since this document shapes audit expectations and vendor security requirements across critical infrastructure sectors.

Why ICS Integrators Are Getting Federal Attention

A joint advisory from CISA and the FBI focused on system integrators fits a pattern regulators have flagged repeatedly: attackers increasingly target the vendors and contractors who have privileged remote access into multiple client environments, because compromising one integrator can open a path into many downstream facilities at once. This is the same logic behind supply chain risk management guidance in other sectors, applied here to the specialized firms that program, configure, and support industrial equipment. Asset owners in manufacturing, utilities, healthcare facilities with building management systems, and food and beverage production should treat their integrator relationships as a security control point, not just a procurement relationship.

For readers who do not operate industrial equipment directly, this still matters. Many small and midsize businesses, including medical practices and professional service firms, rely on third-party vendors for HVAC controls, physical access systems, and connected building equipment that increasingly run on the same networking infrastructure as business IT systems. If an integrator or vendor has standing remote access to your environment for maintenance, that access deserves the same scrutiny as any other privileged account.

What Readers Should Do Now

Organizations with any OT or ICS footprint, from a hospital's building automation system to a manufacturer's production line controllers, should take a few concrete steps while this guidance is being finalized. First, inventory every vendor and integrator with remote access to control systems and confirm that access is logged, time-limited, and revocable on demand rather than standing indefinitely. Second, segment OT networks from general business IT networks so that a compromise on one side does not automatically expose the other; this is a core principle already embedded in NIST SP 800-82 and reinforced across CISA's industrial control systems advisories. Third, assign someone on your team, even if that is an outside IT provider, to monitor the NIST public comment page for the finalized Revision 4 and flag any changes that affect your compliance obligations or insurance requirements, since cyber insurers increasingly reference NIST frameworks when underwriting critical infrastructure and healthcare facility policies.

What This Means For Your Business

Healthcare practices with connected medical devices or building automation, small manufacturers, water and utility operators, and any organization that contracts with an ICS integrator should not wait for the final Revision 4 text to act. Reviewing vendor remote-access agreements, confirming network segmentation between OT and IT, and documenting who has access to industrial control systems are steps that hold value regardless of what NIST finalizes. Bellator Cyber Guard will continue tracking this draft as it moves toward publication and will flag material changes that affect compliance expectations for readers operating in regulated or infrastructure-adjacent industries.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

People also look for

Keep exploring Incident response & NIST

Build a response process that helps people detect, contain, recover, and improve when something goes wrong.

Learn first. Decide when you are ready.

Keep learning, or apply this to your situation

Continue with a related guide, compare your options, or ask a specialist to help turn the advice into a practical next step.