Zero Trust for OT: How critical infrastructure can defend against embedded nation‑state threats and rising cyber‑physical risks.

Mission Spotlight

Critical Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond mere compliance to defeat threats already lurking within OT systems.

By Pia Capra, David Forbes, Brandon Grimes, and Kyle Miller
Velocity Magazine | V5. Summer 2026

abstract background image of city infrastructure

Speed Read ↗︎

  • The convergence of IT and operational technology (OT) has eliminated once-protective air gaps, allowing nation-state adversaries to embed themselves inside critical infrastructure long before disruption is detected.
  • AI-enabled techniques are accelerating disruptive campaigns—forced shutdowns, loss of visibility, ransomware—narrowing the space between disruption and destruction.
  • Given the extensive challenges of implementing zero trust across critical infrastructure, organizations should view policy deadlines as starting points for sustained resilience, not finish lines for compliance.
This is a web summary.

Download the article for the complete zero trust toolkit mapped to DoW's 105 OT activities, policy framework analysis, and global commercial guidanceor download the full edition of Velocity Magazine for more insights for innovators.

Speed Read ↗︎

The convergence of IT and operational technology (OT) has eliminated once-protective air gaps, allowing nation-state adversaries to embed themselves inside critical infrastructure long before disruption is detected. AI-enabled techniques are accelerating disruptive campaigns—forced shutdowns, loss of visibility, ransomware—narrowing the space between disruption and destruction. Given the extensive challenges of implementing zero trust across critical infrastructure, organizations should view policy deadlines as starting points for sustained resilience, not finish lines for compliance.

This is a web summary.

Download the article for the complete zero trust toolkit mapped to DoW's 105 OT activities, policy framework analysis, and global commercial guidanceor download the full edition of Velocity Magazine for more insights for innovators.

Our adversaries are already inside.

For some U.S. critical infrastructure networks, nation-state actors have pre-positioned themselves—quietly mapping systems, identifying critical assets, and waiting for the right moment to act. The question is no longer whether zero trust belongs in operational technology environments. It's how fast organizations can get there.

escalating threat

Rise in Attacks on Critical Infrastructure

70%
of cyberattacks in 2024 involved critical infrastructure

146%
increase in cyber-driven physical disruptions year-over-year

150%
increase in Chinese cyber espionage targeting industrial sectors

For decades, OT security relied on isolation—air gaps that kept industrial control systems physically separate from networked environments. But air gaps eventually proved to be ineffective. In 2010, Stuxnet crossed the air gap at Iran’s Natanz enrichment facility via a compromised USB drive, causing physical destruction while feeding operators false sensor data. This incident demonstrated that adversaries could reach isolated systems without network connections.

At the same time, the business and mission benefits of IT/OT convergence—real-time operational visibility, predictive maintenance, remote monitoring, and the efficiency gains of industrial Internet of Things (IoT) integration—were becoming more compelling. What has replaced the air gap is a busy connectivity zone that adversaries enter and don’t leave, extending dwell time often for months or years before detection, with consequences that extend beyond the enterprise into critical infrastructure, defense systems, and national security.

What is Zero Trust for OT?

Zero trust grants no implicit trust to assets or user accounts—even inside the network. In operational technology (OT) environments, where failure can mean contaminated water, grid blackouts, or impaired warfighting readiness, the stakes of getting this right are fundamentally higher than in enterprise IT.

New Vulnerabilities, Higher Consequences

In a global networked environment where devices outnumber people two to one, new vulnerabilities are emerging. Everyday physical systems—HVAC, traffic lights, medical devices, emergency management systems—are now integrated with IT networks, expanding the attack surface.

Recent cyberattacks against OT share key traits: they exploit the convergence of IT and OT, use legitimate credentials and native tools that defeat conventional detection, gain initial access through internet-facing devices with known vulnerabilities or default credentials, and establish dwell times from months to years.

real-world examples

Volt Typhoon

China – Active since 2021

Pre-positioned inside U.S. OT infrastructure. In 2023, maintained a 9-month intrusion at a Massachusetts utility, exfiltrating data on OT procedures and grid layout—building knowledge for future exploitation.

Salt Typhoon

China – 2024

Compromised at least nine major U.S. telecommunications providers, enabling real-time interception of senior government officials' communications. Same emphasis on stealth, persistence, and strategic positioning.

Sandworm

Russia (GRU) – Ongoing

Behind the 2015–2016 Ukrainian power grid attacks. By December 2025, deployed DynoWiper malware against Polish heat-and-power plants during peak winter demand. Defenders contained it—but the intent was clear.

CyberAv3ngers

Iran (IRGC Affiliated) – Escalating

Exploited default credentials on PLCs at a Pennsylvania water facility. CISA has warned the group continues to exploit internet-accessible OT devices. Activity has reportedly escalated with the onset of open hostilities.

The near-term threat—now accessible to a broad range of adversaries—is disruption: loss of visibility, operational shutdown, and extended recovery. The Colonial Pipeline attack illustrates how: ransomware hit billing systems, not OT, yet operators shut the pipeline down voluntarily because they could no longer safely monitor product flow. The longer-term, higher-consequence threat is physical destruction, currently concentrated in nation-states but expanding as AI lowers barriers.

What Federal Leaders Are Up Against

As the federal government focuses on translating zero trust principles into OT-native implementations that preserve operational uptime, agencies will need different tools, timelines, and risk calculations compared with zero trust for IT, particularly when the goal is detecting and neutralizing access that may already exist. 

According to our exclusive survey of over 100 federal IT and cyber leaders, they're currently facing multiple barriers to zero trust OT implementation. These barriers reflect real structural challenges: OT devices in federal and commercial environments often carry lifecycles of 15 to 30+ years, engineered for reliability—not security. Many can't run authentication software, accept patches without operational risk, or participate in identity-based access control. And 98% of organizations experiencing cyberattacks report that IT incidents also affected OT environments, reflecting collapsed domain boundaries.

survey of federal it and cyber leaders

Biggest Barriers to OT Zero Trust Implementation

56%
Legacy OT systems that can’t support modern security controls

44%
Fragmented governance across IT, OT, and external operators

37%
Shortage of staff with both OT and cybersecurity expertise

The Policy Direction

DoW's Zero Trust for Operational Technology Activities and Outcomes guidance, issued November 2025, defines 105 zero trust activities across seven pillars—users, devices, applications and workloads, data, networks and environments, automation and orchestration, and visibility and analytics. Compliance against all 105 is neither required nor expected in most cases; the guidance empowers asset owners to tailor requirements to their systems. An updated DoW Zero Trust Strategy is expected soon, with additional guidance for weapons systems and defense critical infrastructure.

President Trump's Cyber Strategy for America reinforces the same imperative, elevating protection of critical infrastructure and the defense industrial base as strategic priorities. The direction is clear. The execution challenge is what separates compliance from resilience.

getting started

The Road to Resilience

Practical steps to close the gap between zero trust intent and measurable, mission-aligned resilience.

icon of a gear

step one

Assess & Roadmap

Establish a defensible starting point by assessing OT cybersecurity maturity, identifying gaps, and hunting for threats already inside the environment. Build a prioritized roadmap that sequences investment and guides the transformation.

icon of a document and binary code

step two

Design & Engineer

Translate assessment findings into architecture—define target-state environments, select OT-appropriate tools, and embed secure-by-design principles into systems rather than retrofitting after deployment.

icon of a brick wall

step three

Implement & Remediate

Execute the designed architecture: deploy segmentation, harden networks and devices, and progressively reduce attack surface without disrupting operational uptime.

icon of a caution symbol and bomb

step four

Detect & Respond

Move from passive defense to active resilience: stand up threat reduction programs, deploy managed detection & response capabilities, and establish OT-specific incident response protocols.

Takeaways for Leaders

Establish comprehensive asset visibility.
You can't segment, monitor, or protect what you can't see—and OT environments are routinely under-inventoried.

Implement network segmentation.
Create defensible barriers between IT and OT environments to limit blast radius and constrain lateral movement.

Identify operational crown jewels. 
Risk-based investment decisions require knowing which systems, if compromised, would cause mission or business failure.

Position security as an operational enabler. 
The strongest programs secure funding through business leadership, not IT budgets. 

Treat policy deadlines as starting points. 
Compliance milestones mark the beginning of sustained resilience—not the end of the journey.

Read the Full Article

The article PDF includes the complete zero trust technical toolkit (asset inventory, identity and access management, microsegmentation, behavioral monitoring, data protection, and automation) mapped to DoW's OT Activities and Outcomes, the full policy framework landscape, CISA/NCSC-UK global guidance, and complete survey methodology.

New edition | v5. summer 2026

Explore the New Velocity

cover story

Reimagining Cyber for a Faster Fight

Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days. 

graphic representing AI agent

tech spotlight

How Can You Trust Agentic AI? Start with Engineering

Why trust must be designed, governed, and validated—not assumed.

image of city infrastructure

mission spotlight

Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond compliance to defeat new threats.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It: Zero-Knowledge Proofs

Trusting more (but revealing less) with zero-knowledge proofs for government.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It

Trusting more (but revealing less) with zero-knowledge proofs for government.

New edition | v5. summer 2026

Explore the New Velocity

cover story

Reimagining Cyber for a Faster Fight

Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days. 

graphic representing AI agent

tech spotlight

How Can You Trust Agentic AI? Start with Engineering

Why trust must be designed, governed, and validated—not assumed.

image of city infrastructure

mission spotlight

Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond compliance to defeat new threats.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It: Zero-Knowledge Proofs

Trusting more (but revealing less) with zero-knowledge proofs for government.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It

Trusting more (but revealing less) with zero-knowledge proofs for government.

New edition | v5. summer 2026

Explore the New Velocity

cover story

Reimagining Cyber for a Faster Fight

Securing enterprises against AI threats requires disrupting operating models, enriching detection, and strengthening resilience—because attacks now unfold in minutes, not days. 

graphic representing AI agent

tech spotlight

How Can You Trust Agentic AI? Start with Engineering

Why trust must be designed, governed, and validated—not assumed.

image of city infrastructure

mission spotlight

Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond compliance to defeat new threats.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It: Zero-Knowledge Proofs

Trusting more (but revealing less) with zero-knowledge proofs for government.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It

Trusting more (but revealing less) with zero-knowledge proofs for government.

New edition | v5. summer 2026

Explore the New Velocity

graphic of technology intersecting with Washington DC

cover story

Reimagining Cyber for a Faster Fight

Learn how CISOs are rebuilding to keep pace with AI-powered attacks.

graphic representing AI agent

tech spotlight

How Can You Trust Agentic AI? Start with Engineering

Why trust must be designed, governed, and validated—not assumed.

image of city infrastructure

mission spotlight

Infrastructure Under Attack: The Zero Trust Imperative

Cybersecurity must go beyond compliance to defeat new threats.

graphic of technology intersecting with Washington DC

in conversation

Infrastructure to Impact with Raghu Raghuram

An interview with Raghu Raghuram, managing partner at a16z.

abstract image of math

emerging trends

The Math that Makes Technology Trustworthy

Formal methods and automated reasoning are reshaping software and AI security.

graphic representing resilient technology

lessons from the edge

Resilience Tops Perfection: Desiging for Failure Wins

Resilience doesn't come from preventing failure, it comes from surviving it well.

image of digital fingerprint

tech watch

Don't Take My Word For It: Zero-Knowledge Proofs

Trusting more (but revealing less) with zero-knowledge proofs for government.