Zero Trust in OT: A Pragmatic 90-Day Action Plan

Aligning zero trust architecture with operational technology environments through a strategic, actionable 90-day plan.

ThreatVectr Newsdesk· 2 min read
Zero Trust in OT: A Pragmatic 90-Day Action Plan
Share

Since the Colonial Pipeline ransomware incident, zero trust has become the industry's new refrain. But in practice, applying zero trust to operational technology (OT) can feel misaligned. The NIST Zero Trust Architecture model (SP 800-207) is crafted with IT networks in mind, not the 24/7 operations of compressor stations and control rooms. CISA offers guidance for adapting zero trust to OT, but the challenge remains to satisfy both OT teams and leadership.

One thing the post-mortem will say: regulatory compliance drives action. TSA Directive 2021-02C mandates pipeline operators to affirm network segmentation and zero-trust architectures. NERC CIP-013, focused on supply chain security, echoes similar priorities. Yet, in practical terms, everyone knows the answer to "Are you zero trust?" is often a reluctant "yes."

Reframing zero trust for OT depends on problem-solving in real conversations. Instead of overwhelming teams with abstract architectures, emphasize the principle: "Every user and system must prove they are who they are and why they need access." Focus where IT and OT meet, like jump hosts and shared identity stores. Tie actions to existing regulatory requirements, shifting the dialogue from "why change?" to "how to do it right."

A 90-Day Plan for OT

Days 1–30: Map Assets and Identities

The first month is about visibility. Ask: "Who can currently reach OT?" Work with OT engineers and network staff to identify assets that, if compromised, threaten operations, safety, or compliance. Map users and connections into OT, including internal staff, remote vendor support, VPNs, and cloud platforms. Categorize identities based on risk and exposure.

By day 30, present leadership with a clear overview of critical OT assets, internal and external entry points, and associated identities.

Days 31–60: Contain Vendor Remote Access

Focus on quick, non-disruptive wins. Vendor remote access is often the vulnerability—CISA warns about it consistently. Implement MFA for remote OT sessions. Close old, unused vendor RDP connections. Suggest audited brokered remote access solutions as replacements for unsecured methods.

Days 61–90: Build a Maturity Scorecard

Month three is for tracking progress. With improved visibility of IT/OT boundaries and secured access paths, consult with security leaders to devise metrics that fit your organization's context. "Govern, protect, and detect & respond" are common themes. Measure OT asset segmentation and high-risk remote access pathways.

Operational takeaway: Align zero trust with OT by grounding it in practical steps and regulatory ties.

© 2026 Threat Vectr