Zero trust operational technology sounds like a contradiction. The machines that run pumps, turbines, production lines and other physical processes were built to stay available, often for years at a time. Now the U.S. National Security Agency is telling operators to design those environments around a harsher assumption: compromise may already have happened.
In guidance released on October 8, the NSA recommends applying zero-trust principles to operational technology, or OT, across sensitive and critical environments. Instead of trusting a device or user because it sits inside a protected network, the model continuously verifies identities, devices, workflows and communications. The agency says the goal is to reduce unauthorized access, lateral movement and adversarial persistence. NSA guidance
Zero trust operational technology meets machines that cannot simply reboot
The difficult part is not the slogan. It is the machinery. OT systems control physical processes where availability and safety can matter more than rapidly replacing hardware or forcing constant software changes. The NSA’s document is aimed primarily at national-security and defense environments, but it says the principles also apply more broadly to technical leaders and IT/OT managers.
Other agencies have been moving in the same direction. In April, CISA and U.S. government partners published guidance that emphasizes asset visibility, supply-chain risk, identity and access controls, segmentation and secure communications for OT. CISA guidance NIST’s September draft update to its OT security guide likewise adds zero-trust architecture while explicitly preserving OT requirements such as reliability, performance and safety. NIST SP 800-82 Rev. 4 draft
The risk is digital. The consequences are physical.
That distinction is why the guidance matters. A compromised office account can expose data; a compromised control environment can affect equipment and services people depend on. The NSA names sectors including energy, water, agriculture, public health and government facilities when describing the potential consequences of attacks on OT.
The UK’s National Cyber Security Centre made a similar point in resilience guidance published this month: connections between IT and OT should be tightly controlled, unnecessary dependencies reduced and systems designed so that one compromise cannot spread freely. NCSC resilience guidance
This is not evidence that every factory or water system is already breached, and the NSA is not prescribing a single universal retrofit. The bigger shift is architectural: the old perimeter can no longer be the main reason a machine is trusted. For infrastructure built around physical continuity, that means cybersecurity is moving deeper into the logic of how the machinery itself is allowed to operate.








