[{"data":1,"prerenderedAt":341},["ShallowReactive",2],{"blog-ot-zero-trust-starts-with-visibility":3},{"id":4,"title":5,"author":6,"body":7,"categories":320,"category":321,"date":322,"description":323,"extension":324,"featured":325,"fields":320,"image":326,"meta":327,"modified":320,"navigation":325,"path":328,"seo":329,"slug":330,"stem":331,"tags":332,"__hash__":340},"blog\u002Fblog\u002Fot-zero-trust-starts-with-visibility.md","OT Zero Trust Starts With Visibility: What CISA's New Advisory Means for Critical Infrastructure","FirstWave Team",{"type":8,"value":9,"toc":304},"minimark",[10,22,25,40,43,46,51,60,63,77,80,84,87,90,93,96,100,103,108,111,115,118,122,125,129,132,145,149,152,220,223,227,230,240,249,258,267,276,285,288,292,295,298],[11,12,13,14,21],"p",{},"On 29 April 2026, ",[15,16,20],"a",{"href":17,"rel":18},"https:\u002F\u002Fwww.cisa.gov\u002Fresources-tools\u002Fresources\u002Fadapting-zero-trust-principles-operational-technology",[19],"nofollow","CISA published \"Adapting Zero Trust Principles to Operational Technology\""," - a 28-page guide co-authored with the Department of Defense, Department of Energy, FBI, and Department of State.",[11,23,24],{},"The headline message to operators of power, water, transportation, manufacturing, and building automation systems is direct: dismantle implicit trust inside the Operational Technology (OT) estate. Treat lateral movement, vendor remote access, and management-plane connectivity as untrusted by default. Apply zero-trust principles even where the constraints of legacy hardware, uptime obligations and proprietary protocols make standard methods of doing so impractical.",[11,26,27,28,33,34,39],{},"This wasn't the first federal signal of the month. ",[15,29,32],{"href":30,"rel":31},"https:\u002F\u002Ffederalnewsnetwork.com\u002Fcybersecurity\u002F2026\u002F04\u002Fnist-cyber-center-to-launch-ot-visibility-project\u002F",[19],"NIST's National Cybersecurity Center of Excellence launched a parallel OT visibility project"," in April. ",[15,35,38],{"href":36,"rel":37},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fcybersecurity-advisories\u002Faa26-097a",[19],"CISA's 7 April joint advisory on Iranian-affiliated targeting of US energy, water, healthcare, and manufacturing"," called out \"limited visibility into legacy or hybrid environments\" as a recurring weakness.",[11,41,42],{},"Three federal-level signals in thirty days, from three different cohorts of agencies - but the same operational point was made for each one.",[11,44,45],{},"You cannot zero-trust what you cannot see.",[47,48,50],"h2",{"id":49},"why-asset-visibility-is-the-first-requirement-of-ot-zero-trust","Why Asset Visibility Is the First Requirement of OT Zero Trust",[11,52,53,54,59],{},"CISA's zero-trust guide is built around the NIST Cybersecurity Framework 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) and aligned to ",[15,55,58],{"href":56,"rel":57},"https:\u002F\u002Fwww.cisa.gov\u002Fcross-sector-cybersecurity-performance-goals\u002Fcross-sector-cybersecurity-performance-goals",[19],"CISA's Cross-Sector Cybersecurity Performance Goals 2.0."," Zero trust starts with \"Identify\" -  and \"Identify\" starts with assets.",[11,61,62],{},"Federal guidance and industry data point to the same gap. NIST's OT visibility project was launched because real-time insight into OT networks remains the exception rather than the norm, and both federal guidance and industry data point to this gap.",[11,64,65,70,71,76],{},[15,66,69],{"href":67,"rel":68},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F01\u002Fsurvey-of-100-energy-systems-reveals.html",[19],"Industry surveys across more than a hundred energy systems in 2025 and 2026"," found most operators couldn't confirm what was on their networks. ",[15,72,75],{"href":73,"rel":74},"https:\u002F\u002Fwww.forescout.com\u002Fblog\u002Fics-cybersecurity-in-2026-vulnerabilities-and-the-path-forward\u002F",[19],"Forescout's 2026 OT\u002FICS vulnerability reporting"," also found that up to 82% of OT\u002FICS advisories are high or critical severity, placing risk in the equipment operators struggle to identify and monitor.",[11,78,79],{},"The advisory does not present visibility as a maturity goal, but as the precondition for every control that follows - segmentation, identity, secure communication, vulnerability management, and monitoring. None of those controls work on assets you don't know exist.",[47,81,83],{"id":82},"why-ot-visibility-is-hard","Why OT Visibility Is Hard",[11,85,86],{},"The problem is architecture, not process.",[11,88,89],{},"OT devices - SCADA controllers, PLCs, RTUs, historians - were never designed to be discovered. They speak proprietary protocols, live on isolated subnets, and in many cases will fault under active scanning. A significant portion were also likely installed before the people now responsible for securing them had the job, and the documentation often doesn't survive the handover.",[11,91,92],{},"The IT\u002FOT boundary can compound the problem. Jump hosts, vendor remote access pathways, BMS gateways, and historian replication paths all cross this boundary by design - but they're also exactly the implicit-trust surfaces the federal advisory flags. Plus, they're invisible to any monitoring tool that stops at the IT firewall.",[11,94,95],{},"Then there's everything that isn't in any inventory at all. IP cameras, contractor laptops, smart-building sensors, and forgotten test equipment quietly accumulate on operational networks, unrecorded - each a viable pivot point for an attacker who knows where to look.",[47,97,99],{"id":98},"what-continuous-accurate-asset-inventory-actually-means","What \"Continuous, Accurate Asset Inventory\" Actually Means",[11,101,102],{},"These agencies are all consistent on what a successful continuous, accurate asset inventory looks like, even when the language varies.",[104,105,107],"h3",{"id":106},"it-discovers-everything-automatically","It discovers everything, automatically",[11,109,110],{},"A continuous asset inventory fingerprints every device on the network, IT and OT, without relying on operators to manually add new equipment. Hardware identity (manufacturer, model, serial), software identity (OS, firmware, kernel, installed packages), network identity (IP, MAC, subnet, VLAN), and operational context (role, location, ownership) are all captured and kept current.",[104,112,114],{"id":113},"its-ot-safe-by-design","It's OT-safe by design",[11,116,117],{},"Passive discovery, controlled active probing, and protocol-aware fingerprinting for SCADA, ICS, and BMS estates are non-negotiable. Many OT devices, including Programmable Logic Controllers (PLCs), can't tolerate the kind of active scanning standard IT tools use. A discovery tool that crashes a controller during scanning isn't a solution, but a new incident.",[104,119,121],{"id":120},"it-maintains-an-auditable-record-of-change","It maintains an auditable record of change",[11,123,124],{},"The inventory updates as the estate changes and records what changed and when, so the gap between yesterday's known state and today's is always visible and provable.",[104,126,128],{"id":127},"it-anchors-three-operational-layers","It anchors three operational layers",[11,130,131],{},"None of these operational layers can exist without a continuous, accurate asset inventory:",[133,134,135,139,142],"ul",{},[136,137,138],"li",{},"A configuration baseline that flags drift the moment it occurs",[136,140,141],{},"East-west traffic visibility that surfaces unexpected flows between subnets",[136,143,144],{},"Common Vulnerabilities and Exposures (CVE) mapping against the live device list, so your next patch deadline doesn't involve a research project.",[47,146,148],{"id":147},"how-the-federal-zero-trust-requirements-translate-into-operational-practice","How the Federal Zero-Trust Requirements Translate Into Operational Practice",[11,150,151],{},"Each prerequisite the CISA zero-trust guide names corresponds to an operational capability which we've listed below as outcomes, not as products.",[153,154,155,168],"table",{},[156,157,158],"thead",{},[159,160,161,165],"tr",{},[162,163,164],"th",{},"Federal ask",[162,166,167],{},"Operational capability required",[169,170,171,180,188,196,204,212],"tbody",{},[159,172,173,177],{},[174,175,176],"td",{},"Comprehensive asset visibility (IT + OT)",[174,178,179],{},"Continuous, automated discovery and fingerprinting across the unified estate",[159,181,182,185],{},[174,183,184],{},"Configuration baseline and drift detection",[174,186,187],{},"Approved configuration captured per device; deviations flagged in minutes",[159,189,190,193],{},[174,191,192],{},"East-west and IT\u002FOT boundary visibility",[174,194,195],{},"Flow-level traffic analysis between subnets, including vendor remote access pathways",[159,197,198,201],{},[174,199,200],{},"Vulnerability management against live inventory",[174,202,203],{},"Vulnerability exposure mapped against a live device inventory, not last quarter's spreadsheet",[159,205,206,209],{},[174,207,208],{},"Service health under change",[174,210,211],{},"Protocol-level performance and fault data so a security change does not cascade into an outage",[159,213,214,217],{},[174,215,216],{},"Audit-ready evidence of remediation",[174,218,219],{},"Reports that map controls to frameworks and show change history end to end",[11,221,222],{},"The ask is integrated, and the answer has to be, too.",[47,224,226],{"id":225},"how-to-close-the-ot-visibility-gap","How to Close the OT Visibility Gap",[11,228,229],{},"Closing the OT visibility gap requires capabilities that work across the full estate, not just point solutions that address one layer in isolation. The following tools form an integrated stack - each addressing a distinct prerequisite from the federal guidance, and each feeding into the others.",[11,231,232,239],{},[233,234,235],"strong",{},[15,236,238],{"href":237},"\u002Fproducts\u002Fopen-audit\u002F","Open-AudIT"," delivers continuous asset discovery across IT and OT - the prerequisite the federal guidance names first. It fingerprints every device down to OS, kernel version, installed software, and configuration state, updating automatically as the network changes.",[11,241,242,248],{},[233,243,244],{},[15,245,247],{"href":246},"\u002Fproducts\u002Fnmis\u002F","NMIS"," captures protocol-level health and fault data across IT and OT systems. When a security change is pushed, NMIS confirms the network still works. When a device starts misbehaving, NMIS finds it first.",[11,250,251,257],{},[233,252,253],{},[15,254,256],{"href":255},"\u002Fproducts\u002Fopconfig\u002F","opConfig"," maintains the approved configuration baseline for IT-side hosts that touch OT - jump hosts, historians, engineering workstations, and OT firewalls. Drift surfaces in minutes, not at the next quarterly audit.",[11,259,260,266],{},[233,261,262],{},[15,263,265],{"href":264},"\u002Fproducts\u002Fopflow\u002F","opFlow"," surfaces east-west traffic patterns between IT and OT subnets. Unexpected flows from a vendor jump host into an OT historian appear in flow data long before they trigger a security alert.",[11,268,269,275],{},[233,270,271],{},[15,272,274],{"href":273},"\u002Fproducts\u002Fcybercision\u002F","CyberCision"," maps vulnerability exposure against the live IT\u002FOT inventory, turning the next patch deadline into a prioritised remediation list rather than a research project.",[11,277,278,284],{},[233,279,280],{},[15,281,283],{"href":282},"\u002Fproducts\u002Fopcharts\u002F","opCharts"," gives leadership a single view across IT, OT, and the boundary between them - shifting the board conversation from \"are we compliant?\" to \"what changed, and what did we do about it?\"",[11,286,287],{},"Together, these tools address every operational capability the federal guidance requires without requiring operators to stitch together point solutions from multiple vendors.",[47,289,291],{"id":290},"what-critical-infrastructure-operators-should-do-now","What Critical Infrastructure Operators Should Do Now",[11,293,294],{},"Three federal signals in thirty days all point to the same gap. Visibility isn't a maturity goal, but the baseline the guidance assumes you already have.",[11,296,297],{},"The CISA advisory doesn't include a remediation deadline, but operators who can demonstrate what's on their network, how it's configured, who's communicating with it, and where the vulnerabilities are - across IT and OT, continuously, with evidence - are well positioned for the compliance and regulatory pressure that follows. Those who can't are perpetually catching up, while the parts of their network they can't see remain the most exposed.",[11,299,300],{},[15,301,303],{"href":302},"\u002Fcontact\u002F","Talk to a FirstWave expert about closing your OT visibility gap.",{"title":305,"searchDepth":306,"depth":306,"links":307},"",2,[308,309,310,317,318,319],{"id":49,"depth":306,"text":50},{"id":82,"depth":306,"text":83},{"id":98,"depth":306,"text":99,"children":311},[312,314,315,316],{"id":106,"depth":313,"text":107},3,{"id":113,"depth":313,"text":114},{"id":120,"depth":313,"text":121},{"id":127,"depth":313,"text":128},{"id":147,"depth":306,"text":148},{"id":225,"depth":306,"text":226},{"id":290,"depth":306,"text":291},null,"Cybersecurity","2026-07-15","CISA's OT zero-trust advisory names asset inventory as the first prerequisite for every control that follows. Here's what that means in practice - and how to close the gap.","md",true,"\u002Fimages\u002Fblog\u002Fot-zero-trust-starts-with-visibility.webp",{},"\u002Fblog\u002Fot-zero-trust-starts-with-visibility",{"title":5,"description":323},"ot-zero-trust-starts-with-visibility","blog\u002Fot-zero-trust-starts-with-visibility",[333,334,335,336,337,338,339,238,247,256,265,274],"zero trust","operational technology","OT security","CISA","asset inventory","critical infrastructure","network visibility","a9ubTR6xAVfcb0M585w8wDXi2oHrR8N101c9Ndptkr4",1784608704191]