Mission Spotlight
Cybersecurity must go beyond mere compliance to defeat threats already lurking within OT systems.
By Pia Capra, David Forbes, Brandon Grimes, and Kyle Miller
Velocity Magazine | V5. Summer 2026
Download the article for the complete zero trust toolkit mapped to DoW's 105 OT activities, policy framework analysis, and global commercial guidance, or download the full edition of Velocity Magazine for more insights for innovators.
The convergence of IT and operational technology (OT) has eliminated once-protective air gaps, allowing nation-state adversaries to embed themselves inside critical infrastructure long before disruption is detected. AI-enabled techniques are accelerating disruptive campaigns—forced shutdowns, loss of visibility, ransomware—narrowing the space between disruption and destruction. Given the extensive challenges of implementing zero trust across critical infrastructure, organizations should view policy deadlines as starting points for sustained resilience, not finish lines for compliance.
Download the article for the complete zero trust toolkit mapped to DoW's 105 OT activities, policy framework analysis, and global commercial guidance, or download the full edition of Velocity Magazine for more insights for innovators.
For some U.S. critical infrastructure networks, nation-state actors have pre-positioned themselves—quietly mapping systems, identifying critical assets, and waiting for the right moment to act. The question is no longer whether zero trust belongs in operational technology environments. It's how fast organizations can get there.
escalating threat
Rise in Attacks on Critical Infrastructure
70%
of cyberattacks in 2024 involved critical infrastructure
146%
increase in cyber-driven physical disruptions year-over-year
150%
increase in Chinese cyber espionage targeting industrial sectors
For decades, OT security relied on isolation—air gaps that kept industrial control systems physically separate from networked environments. But air gaps eventually proved to be ineffective. In 2010, Stuxnet crossed the air gap at Iran’s Natanz enrichment facility via a compromised USB drive, causing physical destruction while feeding operators false sensor data. This incident demonstrated that adversaries could reach isolated systems without network connections.
At the same time, the business and mission benefits of IT/OT convergence—real-time operational visibility, predictive maintenance, remote monitoring, and the efficiency gains of industrial Internet of Things (IoT) integration—were becoming more compelling. What has replaced the air gap is a busy connectivity zone that adversaries enter and don’t leave, extending dwell time often for months or years before detection, with consequences that extend beyond the enterprise into critical infrastructure, defense systems, and national security.
Zero trust grants no implicit trust to assets or user accounts—even inside the network. In operational technology (OT) environments, where failure can mean contaminated water, grid blackouts, or impaired warfighting readiness, the stakes of getting this right are fundamentally higher than in enterprise IT.
In a global networked environment where devices outnumber people two to one, new vulnerabilities are emerging. Everyday physical systems—HVAC, traffic lights, medical devices, emergency management systems—are now integrated with IT networks, expanding the attack surface.
Recent cyberattacks against OT share key traits: they exploit the convergence of IT and OT, use legitimate credentials and native tools that defeat conventional detection, gain initial access through internet-facing devices with known vulnerabilities or default credentials, and establish dwell times from months to years.
real-world examples
China – Active since 2021
Pre-positioned inside U.S. OT infrastructure. In 2023, maintained a 9-month intrusion at a Massachusetts utility, exfiltrating data on OT procedures and grid layout—building knowledge for future exploitation.
China – 2024
Compromised at least nine major U.S. telecommunications providers, enabling real-time interception of senior government officials' communications. Same emphasis on stealth, persistence, and strategic positioning.
Russia (GRU) – Ongoing
Behind the 2015–2016 Ukrainian power grid attacks. By December 2025, deployed DynoWiper malware against Polish heat-and-power plants during peak winter demand. Defenders contained it—but the intent was clear.
Iran (IRGC Affiliated) – Escalating
Exploited default credentials on PLCs at a Pennsylvania water facility. CISA has warned the group continues to exploit internet-accessible OT devices. Activity has reportedly escalated with the onset of open hostilities.
The near-term threat—now accessible to a broad range of adversaries—is disruption: loss of visibility, operational shutdown, and extended recovery. The Colonial Pipeline attack illustrates how: ransomware hit billing systems, not OT, yet operators shut the pipeline down voluntarily because they could no longer safely monitor product flow. The longer-term, higher-consequence threat is physical destruction, currently concentrated in nation-states but expanding as AI lowers barriers.
As the federal government focuses on translating zero trust principles into OT-native implementations that preserve operational uptime, agencies will need different tools, timelines, and risk calculations compared with zero trust for IT, particularly when the goal is detecting and neutralizing access that may already exist.
According to our exclusive survey of over 100 federal IT and cyber leaders, they're currently facing multiple barriers to zero trust OT implementation. These barriers reflect real structural challenges: OT devices in federal and commercial environments often carry lifecycles of 15 to 30+ years, engineered for reliability—not security. Many can't run authentication software, accept patches without operational risk, or participate in identity-based access control. And 98% of organizations experiencing cyberattacks report that IT incidents also affected OT environments, reflecting collapsed domain boundaries.
survey of federal it and cyber leaders
Biggest Barriers to OT Zero Trust Implementation
56%
Legacy OT systems that can’t support modern security controls
44%
Fragmented governance across IT, OT, and external operators
37%
Shortage of staff with both OT and cybersecurity expertise
DoW's Zero Trust for Operational Technology Activities and Outcomes guidance, issued November 2025, defines 105 zero trust activities across seven pillars—users, devices, applications and workloads, data, networks and environments, automation and orchestration, and visibility and analytics. Compliance against all 105 is neither required nor expected in most cases; the guidance empowers asset owners to tailor requirements to their systems. An updated DoW Zero Trust Strategy is expected soon, with additional guidance for weapons systems and defense critical infrastructure.
President Trump's Cyber Strategy for America reinforces the same imperative, elevating protection of critical infrastructure and the defense industrial base as strategic priorities. The direction is clear. The execution challenge is what separates compliance from resilience.
getting started
Practical steps to close the gap between zero trust intent and measurable, mission-aligned resilience.
step one
Establish a defensible starting point by assessing OT cybersecurity maturity, identifying gaps, and hunting for threats already inside the environment. Build a prioritized roadmap that sequences investment and guides the transformation.
step two
Translate assessment findings into architecture—define target-state environments, select OT-appropriate tools, and embed secure-by-design principles into systems rather than retrofitting after deployment.
step three
Execute the designed architecture: deploy segmentation, harden networks and devices, and progressively reduce attack surface without disrupting operational uptime.
step four
Move from passive defense to active resilience: stand up threat reduction programs, deploy managed detection & response capabilities, and establish OT-specific incident response protocols.
Establish comprehensive asset visibility.
You can't segment, monitor, or protect what you can't see—and OT environments are routinely under-inventoried.
Implement network segmentation.
Create defensible barriers between IT and OT environments to limit blast radius and constrain lateral movement.
Identify operational crown jewels.
Risk-based investment decisions require knowing which systems, if compromised, would cause mission or business failure.
Position security as an operational enabler.
The strongest programs secure funding through business leadership, not IT budgets.
Treat policy deadlines as starting points.
Compliance milestones mark the beginning of sustained resilience—not the end of the journey.
The article PDF includes the complete zero trust technical toolkit (asset inventory, identity and access management, microsegmentation, behavioral monitoring, data protection, and automation) mapped to DoW's OT Activities and Outcomes, the full policy framework landscape, CISA/NCSC-UK global guidance, and complete survey methodology.
New edition | v5. summer 2026
cover story
Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days.
tech spotlight
Why trust must be designed, governed, and validated—not assumed.
mission spotlight
Cybersecurity must go beyond compliance to defeat new threats.
in conversation
An interview with Raghu Raghuram, managing partner at a16z.
emerging trends
Formal methods and automated reasoning are reshaping software and AI security.
lessons from the edge
Resilience doesn't come from preventing failure, it comes from surviving it well.
tech watch
Trusting more (but revealing less) with zero-knowledge proofs for government.
in conversation
An interview with Raghu Raghuram, managing partner at a16z.
emerging trends
Formal methods and automated reasoning are reshaping software and AI security.
lessons from the edge
Resilience doesn't come from preventing failure, it comes from surviving it well.
tech watch
Trusting more (but revealing less) with zero-knowledge proofs for government.
New edition | v5. summer 2026
cover story
Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days.
tech spotlight
Why trust must be designed, governed, and validated—not assumed.
mission spotlight
Cybersecurity must go beyond compliance to defeat new threats.
in conversation
An interview with Raghu Raghuram, managing partner at a16z.
emerging trends
Formal methods and automated reasoning are reshaping software and AI security.
lessons from the edge
Resilience doesn't come from preventing failure, it comes from surviving it well.
tech watch
Trusting more (but revealing less) with zero-knowledge proofs for government.
in conversation
An interview with Raghu Raghuram, managing partner at a16z.
emerging trends
Formal methods and automated reasoning are reshaping software and AI security.
lessons from the edge
Resilience doesn't come from preventing failure, it comes from surviving it well.
tech watch
Trusting more (but revealing less) with zero-knowledge proofs for government.
New edition | v5. summer 2026
cover story
Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days.
tech spotlight
Why trust must be designed, governed, and validated—not assumed.
mission spotlight
Cybersecurity must go beyond compliance to defeat new threats.
in conversation
An interview with Raghu Raghuram, managing partner at a16z.
emerging trends
Formal methods and automated reasoning are reshaping software and AI security.
lessons from the edge
Resilience doesn't come from preventing failure, it comes from surviving it well.
tech watch
Trusting more (but revealing less) with zero-knowledge proofs for government.
in conversation
An interview with Raghu Raghuram, managing partner at a16z.
emerging trends
Formal methods and automated reasoning are reshaping software and AI security.
lessons from the edge
Resilience doesn't come from preventing failure, it comes from surviving it well.
tech watch
Trusting more (but revealing less) with zero-knowledge proofs for government.
New edition | v5. summer 2026
cover story
Learn how CISOs are rebuilding to keep pace with AI-powered attacks.
tech spotlight
Why trust must be designed, governed, and validated—not assumed.
mission spotlight
Cybersecurity must go beyond compliance to defeat new threats.
in conversation
An interview with Raghu Raghuram, managing partner at a16z.
emerging trends
Formal methods and automated reasoning are reshaping software and AI security.
lessons from the edge
Resilience doesn't come from preventing failure, it comes from surviving it well.
tech watch
Trusting more (but revealing less) with zero-knowledge proofs for government.