NIST has published a draft update to its operational-technology security guidance, while CISA and the FBI have issued a fact sheet on risks associated with third-party ICS integrators, SecurityWeek reports. Together, the publications place attention on the security responsibilities that arise when industrial environments depend on external service providers and integrators.

OT operators should review the draft guidance and the agencies’ recommendations against their own architecture, vendor-access model, and incident-response plans. Third-party access should be inventoried, constrained to the minimum necessary scope, monitored, and reviewed regularly. Contracts and operating procedures should set clear requirements for remote access, logging, notification, and change control.

Defenders should also validate segmentation between enterprise and operational networks, preserve tested offline recovery processes, and rehearse how an integrator-related incident would be detected and contained. Guidance is not a substitute for local engineering judgment, but it can help organizations structure a risk review around real operational dependencies.

Source: SecurityWeek.

By Allan