← Back to advisories & guidance
September 29, 2025
FBI
Alert
Co-sealed by: ASD/ACSC, BSI, CCCS, CISA, FBI, NCSC-NL, NCSC-NZ, NCSC-UK
Summary
It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management. Principle 1: Define processes for establishing and maintaining the definitive record Principle 2: Establish an OT information security management programme Principle 3: Identify and categorise assets to support informed risk-based decisions Principle 4: Identify and document connectivity within your OT system Principle 5: Understand and document third-party risks to your OT system This guidance has been developed with contributions from partnering agencies and is part of a series of publications aiming to draw attention to the importance of cyber security in Operational Technology. It is produced by the UK National Cyber Security Centre (NCSC) in partnership with the Security Agency (CISA), the US Federal Bureau of Investigation (FBI), Germany’s Federal Office for Information Security (BSI), Netherlands National Cyber Security Centre (NCSCNL), and New Zealand’s National Cyber Security Centre (NCSC-NZ).
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
No KEV-catalogued vendors are named in this publication.