- New NSA guidance covers OT systems in national security and defense settings
- It applies a zero trust model that continuously verifies users, devices and communications
- NSA cites adversary use of AI tools as a growing risk
The National Security Agency is urging owners of operational technology systems in national security and defense settings to apply zero trust principles in a new Cybersecurity Information Sheetthe agency said Thursday.
What Does NSA’s Zero Trust Guidance for Operational Technology Recommend?
The sheet is primarily intended for owners of national security systems, Department of War networks and defense industrial base networks, along with the operators responsible for protecting the systems. NSA said the guidance also applies to technical leaders and experts, as well as information technology and OT managers and administrators.
Zero trust assumes that adversaries have breached a network or may already be inside it, and it continuously verifies users, devices, workflows and communications under a “never trust, always verify” principle. Applying the approach to OT is meant to strengthen protection against unauthorized access, lateral movement and adversary persistence.
Adopting the principles is intended to support defense in depth for legacy OT capabilities across critical infrastructure while keeping organizations in line with federal guidance.
How Is AI Affecting OT Security?
Organizations are increasingly integrating artificial intelligence into OT to improve efficiency, resilience and mission effectiveness, which introduces new risks, attack surfaces and opportunities for disruption, NSA said.
Adversaries are using AI to automate reconnaissance, speed exploit development and run cyber campaigns at greater speed and scale, according to the guidance. Adversarial attacks now extend beyond espionage and reconnaissance to efforts aimed at disrupting or destroying critical infrastructure. Affected sectors may include government facilities, public health, agriculture, water and energy.
What Other Federal Efforts Address Zero Trust and OT Security?
In April, the Cybersecurity and Infrastructure Security Agency released guidance with the departments of War, Energy, State and the FBI on applying zero trust principles to OT. The document highlights supply chain risk management and identity and access controls, among other priorities.
In December 2025, U.S. and allied cybersecurity agencies, including the FBI and NSA’s Artificial Intelligence Security Center, issued joint guidance for critical infrastructure operators that use AI in OT. The document warns that the tools create new pathways for adversary threats.
A Sept. 29 executive order signed by President Donald Trump tells executive branch agencies to say super intelligence in place of artificial intelligence in official communications. The order treats the new term as covering the same technologies that federal law defines as AI. The December 2025 guidance predates the order.
Source: www.executivegov.com




