Zero Trust in OT: A Pragmatic 90-Day Action Plan
Aligning zero trust architecture with operational technology environments through a strategic, actionable 90-day plan.

Since the Colonial Pipeline ransomware incident, zero trust has become the industry's new refrain. But in practice, applying zero trust to operational technology (OT) can feel misaligned. The NIST Zero Trust Architecture model (SP 800-207) is crafted with IT networks in mind, not the 24/7 operations of compressor stations and control rooms. CISA offers guidance for adapting zero trust to OT, but the challenge remains to satisfy both OT teams and leadership.
One thing the post-mortem will say: regulatory compliance drives action. TSA Directive 2021-02C mandates pipeline operators to affirm network segmentation and zero-trust architectures. NERC CIP-013, focused on supply chain security, echoes similar priorities. Yet, in practical terms, everyone knows the answer to "Are you zero trust?" is often a reluctant "yes."
Reframing zero trust for OT depends on problem-solving in real conversations. Instead of overwhelming teams with abstract architectures, emphasize the principle: "Every user and system must prove they are who they are and why they need access." Focus where IT and OT meet, like jump hosts and shared identity stores. Tie actions to existing regulatory requirements, shifting the dialogue from "why change?" to "how to do it right."
A 90-Day Plan for OT
Days 1–30: Map Assets and Identities
The first month is about visibility. Ask: "Who can currently reach OT?" Work with OT engineers and network staff to identify assets that, if compromised, threaten operations, safety, or compliance. Map users and connections into OT, including internal staff, remote vendor support, VPNs, and cloud platforms. Categorize identities based on risk and exposure.
By day 30, present leadership with a clear overview of critical OT assets, internal and external entry points, and associated identities.
Days 31–60: Contain Vendor Remote Access
Focus on quick, non-disruptive wins. Vendor remote access is often the vulnerability—CISA warns about it consistently. Implement MFA for remote OT sessions. Close old, unused vendor RDP connections. Suggest audited brokered remote access solutions as replacements for unsecured methods.
Days 61–90: Build a Maturity Scorecard
Month three is for tracking progress. With improved visibility of IT/OT boundaries and secured access paths, consult with security leaders to devise metrics that fit your organization's context. "Govern, protect, and detect & respond" are common themes. Measure OT asset segmentation and high-risk remote access pathways.
Operational takeaway: Align zero trust with OT by grounding it in practical steps and regulatory ties.



