Where an attack produces a physical consequence. Plant, grid, pipeline, water and manufacturing, where a failure moves something, heats something, or stops something.

What we track

NIS2 in operational technology

EU. How reporting and risk management duties reach plant operational technology for in-scope manufacturers.

NERC CIP

US electricity. Enforceable standards including internal network security monitoring under CIP-015.

TSA security directives

US pipelines and rail. Architecture, segmentation and testing requirements, and the renewal cycle behind them.

CISA guidance for OT and ICS

US and international. Internet exposure reduction and asset visibility expectations.

Singapore critical services

Singapore. Advisories and code of practice provisions for operational technology in critical services.

IEC 62443

International. The standard regulators reach for when they need to say what good looks like.

Who is in scope

Operators of essential services first: energy, water, transport, health and manufacturing at scale. In the EU this arrives through the NIS2 sector lists. In the US it arrives sector by sector, through NERC for electricity, TSA directives for pipelines and rail, and CISA guidance more broadly.

Manufacturers are the group that most often assumes it is outside. NIS2 covers manufacturing sub-sectors in Annex II, which brings plant operational technology inside a cybersecurity regime that was written with IT in mind.

Where the deadlines fall

Enforcement dates, and they are audited. NERC standards become enforceable on a set date and are then audited. TSA directives run on a renewal cycle and tighten at each renewal. NIS2 obligations arrive with your member state’s commencement.

The constraint that matters is the maintenance window. Most OT change happens during a planned shutdown, so a compliance date that falls between shutdowns effectively means the previous shutdown was your deadline.

Where organisations get caught

Reporting clocks now reach the plant floor. An operational technology incident at an in-scope manufacturer can trigger the same notification duties as an IT incident. Plant teams are rarely part of the process that produces the notification. The person who first sees the anomaly is frequently a shift engineer with no route into it.

Component provenance. Restrictions on foreign-made equipment in power and control systems turn a procurement decision into a compliance decision, and the affected assets have twenty year lifecycles. Replacing them is a capital programme with a multi-year budget behind it.

Asset visibility. Almost every regime now expects you to know what is on the network, and OT environments frequently cannot be scanned safely. Passive discovery is the answer, and it needs a budget line.

Questions worth asking now

  • Do we have an asset inventory for OT, and how was it built?
  • Which plants are in scope under which regime, and does the plant manager know?
  • If a shift engineer saw something odd at 2am, what would they do and who would hear about it?
  • What is directly reachable from the internet today, and when did we last check?
  • Which control system components come from restricted suppliers, and what is the replacement plan?
  • When is the next maintenance window, and what compliance work is queued for it?

Related domains

Incident reporting covers the clocks that now reach the plant. Robotics and autonomous systems covers machinery on the same networks. Third-party and supply chain risk covers component provenance.

All sixteen domains and how the Radar works.