RSS Amplifier

The Cabreza Independent · Jan 27, 2026

146 Advice Organizations: Which Ones Matter?

0
Sign in to vote or save

Jason Rivera · The Cabreza Independent

I recently tried to catalog the organizations that produce advisory ICS/OT security guidance, standards, regulations and frameworks.

No vendor marketing, just the entities whose outputs theoretically inform how asset owners should think about and manage OT security.

  • US federal agencies

  • International standards bodies

  • ISACs across different sectors

  • European Union agencies and national authorities

  • Asia-Pacific cyber centers

  • Research institutions. Industry consortiums

  • Sector-specific regulators

  • Historical organizations whose guidance still floats around in legacy documentation

The count landed at 146. And that’s probably incomplete.

CISA issues advisories. NIST publishes special publications. DOE’s CESER runs maturity models. TSA issues security directives for pipelines and rail.

USCG just finalized cybersecurity rules for maritime that take effect July 2025. FERC approves NERC standards for the electric grid.

IEC develops the 62443 series. ISA maintains them and runs ISASecure certifications. IEEE publishes technical standards.

Protocol-specific groups like OPC Foundation, ODVA, and Modbus.org each maintain their own security specifications.

E-ISAC for electricity. WaterISAC for water and wastewater. ONE-ISAC (formerly ONG-ISAC) for oil, gas, and renewables. MTS-ISAC for maritime. Manufacturing ISAC launched in 2022.

And that’s just the US-based ones; there are European, Japanese, and Asia-Pacific equivalents.

ENISA publishes guidelines and threat reports. The NIS2 Directive just went into effect October 2024, covering 18 sectors.

Then each member state has its own national authority: BSI in Germany, ANSSI in France, NCSC in the UK.

Japan alone has multiple bodies: METI issues OT security guidelines, ICSCoE runs training programs, JPCERT/CC handles incident response.

Australia has ACSC and CISC. Singapore’s CSA published its OT Addendum.

INL developed the CCE methodology. Sandia runs red team assessments. SANS provides training and certifications.

IAEA for nuclear, IMO for maritime, ICAO for aviation.

Each with their own cybersecurity guidance, often overlapping with national requirements.

I haven’t even mentioned the 21 historical entities whose legacy outputs still appear in documentation, like ICS-CERT advisories that predate CISA.

Share

For an industry OT security professional, if not for regional and sector differentiations, the practical challenge would be completely absurd. For professional service and agency teams, the challenge is absurd.

A chemical manufacturer in Texas with facilities in Germany faces a different regulatory landscape than a water utility in New Jersey. The Texas plant cares about EPA guidance and ISA/IEC 62443. The German facility needs NIS2 and BSI guidance.

Then layer in the standards themselves.

IEC 62443 is treated as the foundational framework for industrial cybersecurity. But it’s a series of documents across four groups, each addressing different aspects of the security lifecycle. An organization “implementing 62443” might be dealing with 4-1, 3-3, or 2-1. Each has different applicability.

Now consider overlap.

NIST Cybersecurity Framework maps to IEC 62443, but they’re not identical. NIS2 requirements may differ from TSA security directives, even when applied to the same facility. Multiple ISACs may cover the same organization depending on sector boundaries.

An OT security manager at a mid-sized manufacturer probably tracks CISA advisories, subscribes to their sector ISAC. They’ve heard of IEC 62443 and might own a couple of documents. They know of NIST and that it exists.

Beyond that? It depends on what auditors ask for.

They are not systematically reviewing BSI guidance, ANSSI publications, ENISA threat reports, and METI frameworks. They’re not attending NATO CCDCOE exercises or reading INL’s latest CCE research. They probably haven’t looked at the IMO’s cyber risk management guidelines unless they operate ships.

It’s just triage.

When you have actual OT systems to secure and compliance audits to prepare for, consuming the full output of even just a few standard, regulatory, advisory or framework organizations can be a lot to wrangle.

So practitioners basically develop heuristics. They follow a handful of trusted sources. They rely on consultants to surface relevant guidance. They respond to regulatory requirements as they emerge rather than proactively tracking development.

Most organizations operate on a subset of available information, without clear visibility into what they’re missing.

Information ages. Some quicker than others.

CFATS, the Chemical Facility Anti-Terrorism Standards, required cybersecurity controls for high-risk chemical facilities. Its authority expired July 28, 2023. Conventional wisdom says organizations that built programs around CFATS have a gap.

ICS-CERT was absorbed into CISA in 2018, but legacy documentation still references it.

NIST SP 800-82 Revision 3 was published September 2023, updating 2015 material. Organizations on Revision 2 are working with outdated guidance. And now Revision 4 is underway.

Regulations change.

NIS2 superseded the original NIS Directive with substantial scope expansion. TSA security directives have been revised multiple times.

Even organizational structures shift: CPNI became NPSA in 2023, ONG-ISAC became ONE-ISAC in 2024.

Staying current is a continuous activity, not a one-time investment.

The information landscape is what it is because ICS/OT security genuinely involves multiple sectors, multiple jurisdictions, and multiple technical domains.

So acknowledging the problem has value.

When we talk about OT security challenges, we focus on technical complexity, legacy systems, workforce shortages.

We less often discuss the cognitive load of staying informed in a domain with so many active information sources.

This can be a real barrier to program effectiveness.

Not because the information isn’t out there, but because finding the signal that actually matters for any specific organization, in the moment when it matters, is genuinely difficult.

The organizations producing this guidance aren’t going to consolidate. The volume will increase, not decrease.

And the 52.6% of the ICS/OT workforce with less than five years of experience is expected to navigate this while still learning the field.

All these organizations want your attention. Nobody has bandwidth for all of them.

Read the original on cabreza.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.