OT DEFENSEREVIEW

Intelligence for systems that move the physical world.

Coverage desk

Standards

Source-backed reporting and analysis connected to the companies, capabilities, authorities, and operating domains it affects.

ISA/IEC 62443 keeps OT security responsibility role-specific

ISA describes shared responsibility across asset owners, product suppliers, integrators, and service suppliers while assigning different requirements across the 62443 series. A product mapping or certificate cannot transfer the facility's operating, engineering, safety, and risk decisions.

NIST SP 800-82r3 makes OT asset discovery a method-risk decision

NIST treats an accurate OT asset inventory as important to risk management while warning that collection methods can affect the environment being observed. Passive, active, automated, and manual approaches have different evidence gaps and operational consequences, so discovery authority must be bounded before a tool is run.

NIST opens the SP 800-82 Rev. 4 pre-draft process

The January 2026 notice begins a revision of the central U.S. OT security guide while leaving Rev. 3 as the current final publication.

CISA partners publish Secure by Demand guidance for OT buyers

The guide puts secure configuration, identity, logging, vulnerability handling, updates, support, and buyer evidence into product selection rather than leaving them for post-purchase remediation.