Zero Trust in OT: A Pragmatic 90-Day Action Plan
Applying zero trust to operational technology environments without breaking operations or losing the room.

Key points
- Colonial Pipeline's 2021 shutdown exposed how unprepared OT networks are for zero trust enforcement
- TSA Directive 2021-02C requires pipeline operators to attest to network segmentation and zero trust architectures
- NERC CIP-013 adds supply chain security obligations that overlap with zero trust controls
- Vendor remote access is the highest-impact, lowest-disruption place to start
- A 90-day asset-mapping and access-hardening cycle fits OT audit timelines better than a full architecture overhaul
Why zero trust breaks down in OT
NIST SP 800-207 was written for IT networks, not compressor stations running 24/7 on equipment older than the security tools meant to protect it. CISA has guidance that narrows the gap, but the honest version of the conversation is this: when an auditor asks "are you zero trust?", the answer is always yes, everyone in the room knows it isn't, and nothing changes until something breaks. That's the loop colonial Pipeline broke open in 2021.
Regulatory pressure is what actually moves OT organisations. TSA Directive 2021-02C requires pipeline operators to attest to network segmentation and zero trust architectures. NERC CIP-013 covers supply chain risk management for utilities connecting suppliers to critical systems. Both frameworks give security teams a lever that isn't "trust us, this is best practice."
Our May 2026 coverage of OT monitoring gaps found fewer than 10 percent of OT networks have meaningful monitoring in place, which makes the asset-mapping phase below harder than it looks on a slide.
Should you worry about the framing?
Yes, because the framing determines whether OT engineers cooperate or stonewall you. Drop the architecture diagrams. Say instead: every user and system must prove who they are and why they need access. That's what NIST and CISA actually emphasise, translated into language that doesn't make a control-room engineer's eyes glaze over. Focus on where IT and OT already meet: jump hosts, historian connections, shared identity stores. That's where least-privilege and detailed logging get you real wins without touching the predictable-behavior requirements that keep turbines running.
The 90-day plan
Days 1 to 30: map assets and identities. Ask who and what can currently reach OT, intentionally or by accident. Work with OT engineers and network staff to identify assets that threaten operations or compliance if compromised. Map every connection into OT: internal staff with elevated privileges, remote vendor support, VPNs. Categorise by risk and exposure, not job title. By day 30 you want leadership holding a clear picture of critical assets, entry points and the identities attached to both.
Days 31 to 60: contain vendor remote access. This is the quick-win phase. Replace unsecured remote access methods with audited brokered solutions. Enforce MFA on every remote OT session. Close unused vendor RDP connections. CISA has flagged third-party remote access consistently; TSA pipeline directives require monitoring and controls around it. You're not reinventing anything, you're retiring methods that were already past their shelf life.
Days 61 to 90: build a maturity scorecard. Translate the work into repeatable metrics: OT asset segmentation coverage, high-risk remote access pathways closed, MFA enforcement rate. Tie each number to a TSA or NERC CIP requirement so the next audit conversation starts from evidence, not attestation.



