NIST recently released the Initial Public Draft of SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security.
I went through the new revision mainly with one question in mind:
What has actually changed from Rev. 3, and what should OT practitioners pay attention to?
This is not a completely new OT security model.
It is more of an evolution.
Rev. 4 brings SP 800-82 closer to NIST Cybersecurity Framework 2.0, strengthens governance and enterprise risk management, expands practical guidance around asset visibility and monitoring, and gives more attention to modern OT architectures and Zero Trust principles.
NIST also continues to emphasize something very important for anyone working in OT:
security controls and security testing must respect operational requirements, reliability, and safety.
The biggest change: CSF 2.0 and GOVERN
One of the clearest changes is the alignment with NIST CSF 2.0.
The familiar functions are now:
Govern → Identify → Protect → Detect → Respond → Recover
For OT, I think the addition and stronger emphasis on Govern is important.
Cybersecurity in industrial environments cannot remain only a technical discussion between engineers and security teams.
It has to connect with:
- business objectives
- operational risk
- responsibilities and accountability
- supply chain
- investment decisions
- enterprise risk management
This is an important direction.
A firewall, IDS, EDR platform, or segmentation project is not the objective by itself.
The real question is:
What operational risk are we trying to reduce?
Rev. 4 makes this connection much clearer.
OT continues to expand beyond traditional ICS
Rev. 3 already made an important change by moving from an ICS-centered view toward the broader term Operational Technology.
Rev. 4 continues in that direction.
NIST now explicitly discusses environments including industrial control systems, building automation and control systems, water and wastewater, transportation, maritime systems, Industrial Internet of Things, and cloud-connected OT environments.
This matters because OT security is no longer only about PLCs inside a refinery or manufacturing plant.
Cyber-physical systems are everywhere.
And the boundary between traditional IT, OT, IIoT, and cloud services continues to become less clear.
More emphasis on knowing what you actually have
Another useful improvement is the expanded guidance around asset management, network monitoring, and detection.
This sounds basic, but it remains one of the biggest practical problems in OT security.
Before asking:
How do we protect the environment?
we still need to answer:
What exactly is in the environment?
Rev. 4 provides more guidance around asset visibility and monitoring and recognizes the different approaches that may be required in operational environments.
It also expands guidance around network monitoring and detection.
For defenders, this reinforces the importance of understanding normal communications, asset relationships, network architecture, and what is happening between different parts of the OT environment.
Zero Trust comes further into OT
Rev. 4 also provides more guidance on applying Zero Trust principles to OT.
This should not be interpreted as taking an enterprise Zero Trust architecture and simply dropping it into a plant.
Many OT devices cannot support the same identity, authentication, endpoint, or policy technologies we expect in modern IT environments.
Instead, the principles become more interesting:
limit access, reduce unnecessary trust, control privileged access, segment systems, authenticate where possible, and continuously monitor communications.
The technology used to achieve this may be different in OT.
The principle is still useful.
NIST specifically identifies security architecture guidance around protecting management functions and applying Zero Trust principles as one of the important additions to Rev. 4.
What does Rev. 4 say about penetration testing?
This part caught my attention because I have been spending more time recently on OT penetration testing.
Rev. 4 does not introduce a new OT penetration testing methodology.
But it reinforces an important distinction between traditional IT penetration testing and testing industrial environments.
NIST says penetration testing can be used as part of vulnerability assessment, provided that the testing does not adversely impact the production environment.
That qualification is critical.
OT systems can have timing constraints, limited resources, legacy equipment, and direct interaction with physical processes.
A technique that is routine in IT may have very different consequences inside OT.
NIST therefore recommends caution when performing penetration testing on operational systems.
Where possible, testing may be performed using:
replicated, virtualized, or simulated systems.
Testing of production systems may sometimes need to be coordinated with planned outages or other operational windows.
NIST also highlights another important point:
effective OT penetration testing requires OT-specific knowledge and skills.
That is something I think deserves much more attention as interest in OT penetration testing grows.
Knowing Kali Linux, Metasploit, Nmap, or industrial protocol tools is not enough.
The tester needs to understand the environment being tested and the possible operational consequences of the test.
This reminded me of Duggan’s 2005 paper
This section of Rev. 4 immediately reminded me of an article I recently wrote about the 2005 Sandia report “Penetration Testing of Industrial Control Systems” by David Duggan and his colleagues.
The paper was published more than 20 years ago.
Interestingly, much of the terminology we use today was not yet established in the same way.
The industry was not having today’s discussions around “OT security,” “Zero Trust for OT,” or modern cyber-physical security programs.
But the core testing problem was already very clear.
Duggan and his colleagues were already discussing the fact that penetration testing industrial control systems is different because the tester must consider the consequences to the process itself.
That makes Rev. 4 an interesting follow-up.
The technology has changed.
The architectures have changed.
The frameworks have matured.
The terminology has changed.
But the basic principle remains:
You cannot test an industrial environment exactly like a normal IT network.
Twenty years later, NIST is still emphasizing the same operational reality, but now within a much broader OT cybersecurity framework.
For me, there is an important lesson here for penetration testers entering OT.
The goal is not to prove how aggressive your tools can be.
The goal is to understand security weaknesses without allowing the security test itself to become an operational incident.
My main takeaway
If I had to summarize the evolution:
Rev. 2: Secure ICS.
Rev. 3: Think broader — secure OT.
Rev. 4: Connect OT cybersecurity more closely with governance, enterprise risk, visibility, modern architecture, monitoring, and CSF 2.0.
And for penetration testers, the message remains consistent with what researchers were already saying two decades ago:
understand the process before you test the technology.
That may sound obvious.
In OT, it is fundamental.
One final point: Rev. 4 is currently an Initial Public Draft, published on September 21, 2026. NIST is accepting public comments until November 30, 2026, so the final version may still change.
Want to go deeper into OT security and penetration testing?
If you are new to OT security and want a practical introduction, you can start with my OT security fundamentals and penetration testing course, where I introduce the OT environment and basic hands-on testing using LabShock:
https://alhasawi.gumroad.com/l/OT-P2P
I am also developing a more detailed Practical OT/ICS Penetration Testing course covering OT architecture, scoping and rules of engagement, industrial protocols, enumeration, vulnerability assessment, and safe penetration testing techniques.
If you are interested in joining the next cohort, you can register here:
https://forms.gle/EyjHPzMwaKLqxBok8
References
NIST, SP 800-82 Rev. 4 — Guide to Operational Technology (OT) Security, Initial Public Draft, September 2026.
David P. Duggan, Michael Berg, John Dillinger, and Jason Stamp, Penetration Testing of Industrial Control Systems, Sandia National Laboratories, 2005.
