How CISA Zero Trust Maturity Model Rules Hit Real OT Walls
9 min read
The Gap Between Zero Trust Slides and Copper Wire
Marcus sat in a room that smelled faintly of ozone and damp concrete, watching a green light on a Siemens S7-300 programmable logic controller blink with the steady rhythm of a healthy machine. He is a plant operations manager for a regional water district, and his job is simple: make sure the high-service pumps keep water moving to eighty-five thousand homes. On his desk lay a freshly printed 28-page document titled Adapting Zero Trust Principles to Operational Technology, co-authored by CISA, the Department of Defense, the Department of Energy, the FBI, and the State Department.
The document is an ambitious blueprint designed to dismantle implicit trust in critical infrastructure networks. It warns that threat actors like Volt Typhoon are already lurking inside utility systems, waiting for the right moment to disrupt physical operations. CISA wants operators to validate every single access request based on identity, context, and risk rather than network location. The primary topic of this guidance—implementing the CISA Zero Trust Maturity Model in legacy operational technology—sounds flawless on a PowerPoint slide presented in a Washington briefing room.
But Marcus was looking at a controller that was installed during the second Clinton administration. It communicates over a serial bus using a protocol that does not recognize the concept of a username or a password. To the controller, any command sent over the wire is a command that must be executed. The sales representatives from enterprise security vendors tell Marcus he needs to deploy identity-defined microsegmentation, but Marcus knows that if a software agent latency spike delays a telemetry packet by even fifty milliseconds, the system will trigger an emergency shutdown.
Why We Cannot Simply Patch a Forty-Year-Old Water Pump
The fundamental friction of securing operational technology (OT) is that IT security prioritizes confidentiality, while OT prioritizes availability. If an enterprise IT laptop gets infected with malware, the security operations center isolates the device, wipes the drive, and restores it from a backup. If a valve controller at a water treatment plant gets isolated during a pressure surge, the resulting water hammer can rupture a main line under a major highway, cutting off water to an entire county.
Most modern enterprise security tools rely on continuous communication with cloud-based identity providers like Okta or Microsoft Entra ID. They require lightweight agents running on the endpoints to monitor memory space and network connections. In the physical world of pumps, turbines, and assembly lines, these assumptions fall apart. The systems running our critical infrastructure are dominated by proprietary real-time operating systems that cannot support third-party agents.
Furthermore, the communication protocols themselves are inherently insecure by design. Protocols like Modbus/TCP or EtherNet/IP were built decades ago for closed, physically isolated networks where everyone was assumed to be friendly. They transmit commands in cleartext without cryptographic signatures. If an attacker gains access to the network segment, they do not need to exploit a complex vulnerability; they can simply send a standard "stop" command to a controller, and the machine will obediently halt.
The Trap of the Single-Pane-of-Glass Sales Pitch
Security vendors frequently promise a unified dashboard that manages both IT and OT assets under a single zero trust policy. This pitch appeals to corporate executives who want a clean, consolidated view of risk, but it ignores the operational reality on the plant floor. Managing industrial control systems through a cloud-managed portal introduces external dependencies that critical infrastructure operators have spent decades trying to avoid.
"An industrial network is not just a collection of slow computers; it is a physical machine where a delayed packet has the same consequence as a broken gear."
How the Global Regulatory Convergence Forces Our Hand
While plant managers grapple with the physical limitations of their hardware, a wave of global regulatory pressure is removing the option of doing nothing. Regulators across different jurisdictions have independently arrived at the same conclusion: the traditional perimeter-based security model is dead. They are codifying zero trust principles into law, forcing organizations to navigate a complex web of compliance requirements.
In Europe, the NIS2 Directive is expanding cybersecurity requirements to a wider range of essential and important entities, demanding strict access controls and supply chain security. In the financial sector, the Digital Operational Resilience Act (DORA) mandates rigorous testing of third-party risks and operational continuity. In Saudi Arabia, the SAMA Cybersecurity Framework imposes tight controls on financial institutions. In the United States, the federal push is driven by Executive Order 14028, which directly underpins the CISA Zero Trust Maturity Model.
| Regulatory Framework | Primary Jurisdiction | Core Zero Trust Expectation | Enforcement Focus |
|---|---|---|---|
| CISA Zero Trust Maturity Model | United States | Dismantling implicit trust across five pillars: Identity, Device, Network, Application, and Data. | Federal agencies and critical infrastructure operators. |
| NIS2 Directive | European Union | Mandatory risk management, incident reporting, and strict access control for essential services. | National supervisory authorities with significant administrative fines. |
| DORA | European Union | Continuous monitoring of third-party ICT providers and real-time threat intelligence sharing. | Financial regulators with the power to halt non-compliant operations. |
| SAMA Framework | Saudi Arabia | Multi-factor authentication, granular network segmentation, and restricted administrative privileges. | Saudi Central Bank auditing and compliance reviews. |
The Real-World Anatomy of a Zero Trust OT Retrofit
Transitioning a legacy industrial environment toward zero trust is not a single upgrade event. It is a slow, methodical process of wrapping modern security controls around inherently insecure systems without interrupting the physical processes they control. A representative municipal utility attempting this migration typically follows a phased approach to minimize operational risk.
- Passive Asset Discovery: The security team cannot use active scanning tools like Nessus or Qualys, because an unexpected ping sweep can crash an older PLC. Instead, they deploy passive network monitoring tools from specialized vendors like Claroty, Nozomi Networks, or Dragos. By tapping network switch ports (SPAN/RSPAN), these tools analyze copy traffic to build an inventory of every connected device, its firmware version, and its baseline communication patterns.
- Boundary Cleanup and MFA Enforcement: Before attempting to segment the internal OT network, the team secures the boundary between the corporate network (Purdue Model Level 4) and the industrial operations zone (Level 3). They eliminate all direct connections, routing all remote engineering access through a secure jump host. This jump host requires multi-factor authentication managed by enterprise identity systems, ensuring that a compromised corporate laptop cannot directly access the control network.
- Protocol-Aware Industrial Firewalls: The team installs industrial-grade firewalls from vendors like Fortinet or Palo Alto Networks at key points within the plant network. These firewalls do not just filter traffic by IP address and port; they perform deep packet inspection of industrial protocols. If an engineering workstation attempts to write a new configuration to a PLC outside of a scheduled maintenance window, the firewall blocks the specific write command while allowing normal read telemetry to pass through.
Where Physical Isolation and Legacy Air-Gaps Actually Still Work
The prevailing industry consensus is that the physical air-gap is a myth. While it is true that modern business demands have connected most industrial networks to corporate systems for billing, reporting, and remote maintenance, there are scenarios where attempting to overlay a complex software-defined zero trust architecture is counterproductive. In high-consequence, low-complexity environments, physical isolation remains the most resilient defense.
Consider a remote pump station that only needs to communicate its tank levels back to a central facility twice a day. If you install a complex software-defined perimeter client on that remote node, you introduce a massive software stack that requires constant updates, patch management, and cryptographic certificate renewals. If the local cellular connection drops or the external identity provider experiences an outage, the local control system may lock out legitimate operators who need to make emergency adjustments.
In these isolated environments, a hard physical lock on the enclosure, disabled USB ports, and a dedicated, non-routable serial connection are far more reliable than a suite of modern security software. The operational overhead of maintaining a complex security agent on a remote, low-bandwidth node often creates a larger vulnerability than the one it was designed to fix. Security leaders must recognize when the complexity of the security tool exceeds the risk of the asset itself.
The Broken Pipes in the Utility Data Layer
When organizations attempt to measure their progress against the CISA Zero Trust Maturity Model, they quickly find that the bottlenecks are not financial; they are structural. The older the facility, the more difficult it is to collect the clean telemetry required to make real-time, risk-based access decisions. The data layer of a legacy utility is often a fragmented mess of isolated databases, undocumented serial links, and custom software written by engineers who retired a decade ago.
Illustrative figures for explanation — representative, not measured.
The chart above illustrates the reality on the ground. Over forty percent of the friction in migrating to a zero trust posture stems from legacy hardware constraints—devices that physically cannot support modern encryption or authentication protocols. Another twenty-eight percent is driven by protocol incompatibility, where the industrial protocols running the plant cannot be parsed by standard security tools without causing latency issues.
A security strategy that relies on continuous cloud connectivity is a luxury that physical infrastructure simply cannot afford.
To make meaningful progress, security teams must stop trying to force-fit IT identity models onto OT devices. Instead of trying to give a water pump an identity, they must focus on securing the path to that pump. This means implementing strict access controls at the network layer, using protocol-aware gateways to translate legacy commands, and relying on continuous monitoring to detect anomalies in physical behavior rather than relying solely on cryptographic verification.
Frequently Asked Questions
What happens to our safety instrumented systems (SIS) when a zero trust access broker experiences a regional network outage?
Safety instrumented systems (SIS) must always be physically and logically isolated from the rest of the control network. They should never depend on external zero trust access brokers, identity providers, or cloud-managed firewalls to perform their safety functions. If an external network outage occurs, the SIS must continue to operate locally, using hardwired logic to bring the process to a safe state regardless of the status of the security software layer.
How do we handle transient assets, like a third-party turbine technician's unmanaged laptop, without violating our zero trust posture?
Transient assets are a major vector for malware introduction. Under a zero trust framework, these devices should never be allowed to connect directly to the OT network. Instead, the technician must connect their device to an isolated staging network where it can be scanned for malware and verified. Any configuration changes or PLC code updates must be uploaded to a secure intermediate file share (a DMZ jump host) and inspected before being transferred to the production environment by a resident engineer using a managed, trusted workstation.
The Industrial Reality Check: Achieving zero trust in operational technology is a game of compromise, requiring security teams to wrap modern controls around legacy systems rather than replacing them. True resilience lies in understanding the physical consequences of network decisions, ensuring that security measures never compromise the safety or availability of the physical process. If a security control can cause a plant shutdown during a network outage, it is a vulnerability, not a defense.
When was the last time your security team tested what happens to your physical operations when your enterprise identity provider goes offline for four hours?
Related from this blog
- How CISA Zero Trust Maturity Model Shifts Agency Budgets
- ZTNA vs VPN Reality in 2026 Production Environments