Bottom line: Effective OT security requires designing networks that are more resilient and isolated than conventional IT networks.
What's happening: The UK's National Cyber Security Centre (NCSC) has published guidance on connecting OT systems to the internet, while the US Securities and Exchange Commission (SEC) has issued new rules for OT security. Meanwhile, the ISO/IEC 27001 standard for information security management has been updated to include guidelines for OT security.
What to do: Security leaders should prioritize the implementation of Biba and SEC-OT mitigations, as well as the use of modern "islanding" techniques to further enhance OT network security.