Enterprise Security
Explaining OT Zero Trust to the Board: A CISO's 90-Day Communication and Action Plan
Since the Colonial Pipeline ransomware attack in 2021, zero-trust architecture in operational technology (OT) environments has become a regulatory and compliance focus. However, implementing zero trust in OT faces unique challenges such as aging equipment and business continuity requirements. Based on industry practices, this article provides CISOs with a 90-day action plan to clearly communicate to the board the practical value, risk priorities, and executable steps of zero trust in OT.
Background: OT Zero Trust Is No Longer Optional
Following the Colonial Pipeline ransomware incident in 2021, the U.S. Transportation Security Administration (TSA) issued multiple security directives requiring pipeline operators to implement network segmentation and zero trust architecture. At the same time, standards such as NERC CIP-013 have raised similar requirements in supply chain security. However, when facing regulatory scrutiny, many companies often verbally claim to have "achieved zero trust" but in reality lack substantive deployment—especially at the critical boundary where OT and the Internet of Things (IoT) converge.
The CISA guide "Adapting Zero Trust Principles to Operational Technology" (IC3/2026/260429) points out that zero trust requires differentiated implementation in OT environments. Although NIST SP 800-07 "Zero Trust Architecture" applies to all networks, its design intent is more oriented toward IT environments. OT systems require 7x24 operation, include many legacy devices, and are highly sensitive to latency and availability, making it difficult to directly apply principles such as "explicit verification, least privilege, assume compromise."
The Problem: What Does the Board Really Care About?
When the board or audit department asks, "Have we achieved zero trust?" the CISO faces a dilemma: either give a vague affirmative answer or list a large amount of technical detail that confuses decision-makers. The truly effective way to communicate is to redefine zero trust as a series of verifiable security control principles rather than an abstract architecture.
For example, you can explain to the board: "Every user and system must prove their identity and justify their access needs—this is the core of zero trust, and we are deploying corresponding authentication, authorization, and logging audit capabilities at key entry points." At the same time, the focus should be on the intersection of IT and OT: jump boxes, historian connections, remote access paths, and cross-domain identity storage. These are precisely the control points that regulatory bodies (such as TSA and NERC) repeatedly emphasize.
Technology and Risk Analysis
Attack Surface and Exploit Chain Attacks in OT environments often penetrate along the IT/OT boundary: attackers first compromise the IT network through phishing emails, then use VPNs or vendor remote access channels to move laterally into the OT network. Once inside, legacy devices lack patches, segmentation is weak, and monitoring is absent, allowing attackers to easily disrupt production processes.
Affected Assets These include compressor stations, control rooms, programmable logic controllers (PLCs), historian servers, remote terminal units (RTUs), etc. The common characteristic of these assets is that they must operate stably and cannot be frequently rebooted or patched.### Risk Levels - Operational Risk: Service interruptions causing revenue loss and infrastructure damage. - Compliance Risk: Violations of TSA directives or NERC standards may result in fines and operational restrictions. - Financial Risk: Ransomware payments, recovery costs, and increased insurance premiums. - Reputational Risk: Attacks on critical infrastructure severely undermine public trust.
Enterprise Impact Analysis
For enterprises with OT environments (e.g., energy, manufacturing, water utilities), the direct consequence of lacking zero trust is a surge in costs for security incident response. Taking pipeline operators as an example, a six-day shutdown could cause hundreds of millions of dollars in losses and trigger congressional hearings. Furthermore, third-party vendor remote access is a common weak link—CISA has repeatedly warned that many attacks originate from unsecured vendor RDP connections.
From a compliance perspective, TSA Directive 2021-02C requires operators to submit annual security plans and update them after significant changes. NERC CIP-013 mandates that vendor management be incorporated into supply chain risk considerations. Enterprises unable to demonstrate zero trust progress may face regulatory escalation or revocation of operating licenses.
Industry Trend Observations
- The discussion of zero trust in OT has shifted from "whether it is feasible" to "how to implement it." The industry is reaching a consensus:
- Start at IT/OT convergence points: Jump servers, remote access, and cross-domain identity systems are the highest-priority control points.
- Tighten vendor remote access: Enforce multi-factor authentication (MFA), proxy access, and session auditing.
- Simplify maturity measurement: Adopt a "Govern-Protect-Detect-Respond" framework, focusing on high-risk asset coverage.
This is not an isolated incident but a microcosm of the global security upgrade for critical infrastructure. The United States, the European Union (NIS2), and Australia are all strengthening OT security regulation. Zero trust is evolving from an IT concept into a compliance necessity for OT.
Defense and Response Recommendations: 90-Day Action Plan
Days 1-30: Inventory Assets and Identities at the IT/OT Boundary - Collaborate with OT engineers to identify high-impact assets (operational, security, and compliance dimensions). - Map all users and channels that can reach the OT network (internal privileged users, vendor VPNs, cloud interfaces). - Classify identities and connections by risk, impact, and exposure. - Output: A clear view of "critical OT assets, entry points, and associated identities."
Days 31-60: Contain Vendor Remote Access for Quick Wins - Mandate proxy-based solutions and enable MFA for all remote OT sessions. - Close vendor RDP connections that are no longer in use. - Implement independent monitoring and logging for third-party activities. - Establish vendor access control policies in line with TSA and NERC CIP-013 requirements.### Days 61-90: Build a Simple Maturity Scorecard and Narrative - Coordinate with security and OT teams to determine metrics suitable for the organization (e.g., "Proportion of high-impact OT assets with segmentation strategies implemented", "Proportion of high-risk remote access paths with MFA and proxy enabled"). - Categorize metrics under the three themes: "Governance", "Protection", and "Detection & Response". - Define "Current State" and "Next Quarter Target" for each theme. - Output: A progress card that can be presented to the board, clearly indicating the current level of zero-trust adoption, improvements completed within three months, and remaining gaps.
SecurityPost Insight
The implementation of zero trust in OT does not require a one-time overhaul of the existing architecture. As the author of this article emphasizes, a quarterly updated 90-day plan is far more persuasive than a commitment to "fully achieve zero trust."
The core challenge for CISOs is how to translate security language into business language. By focusing on IT/OT boundaries, identity mapping, and supplier controls, and leveraging regulatory requirements as drivers, CISOs can gradually enhance security resilience without disrupting operations. In the future, as AI-driven threat detection and automated responses mature, OT zero trust will become more intelligent, but the foundation will always be clear identity and access control. Enterprises should start now, replacing vague visions with measurable actions.
Evidence route · securitypost
securitypost frames this note through Security Post publishes defensive cybersecurity intelligence for enterprise security leaders, covering thre.... Threat Briefing / Enterprise Security / AI & Cybersecurity explains the local editorial angle: Source links should be opened before the summary is reused. dates, names and status changes still need checking.