The NIST Cybersecurity Framework Applied to OT
Updated: a few seconds ago
The NIST Cybersecurity Framework is one of the most widely used ways to organize a security program, and many boards and executives already know its vocabulary. The challenge for operational technology teams is that the framework is deliberately general. This article translates each of its functions into concrete actions for plants, pipelines, utilities and other industrial environments.
What CSF 2.0 is

The US National Institute of Standards and Technology released version 2.0 of the Cybersecurity Framework (CSF) in February 2024. It is voluntary, free and intended for organizations of any size and sector, not just critical infrastructure. Version 2.0 added a new function, Govern, and broadened its guidance on supply chain risk.
The framework is organized around six functions:
Govern (new in 2.0)
Identify
Protect
Detect
Respond
Recover
The CSF tells you what outcomes to achieve, not exactly how to achieve them. For OT, the "how" usually comes from IEC 62443 and NIST SP 800-82, which pair well with the CSF.
Govern and Identify: know what you are protecting and who owns it
Govern
Govern covers strategy, roles, policy, oversight and supply chain risk. In OT, that means:
Name an accountable owner for OT cybersecurity, and make clear how responsibility is split between operations, IT and the automation team.
Set risk tolerance in operational terms, such as acceptable downtime, safety and environmental consequences, not just data loss.
Write OT-specific policies for remote access, removable media, change management and vendor access, rather than stretching IT policies that do not fit.
Manage supplier risk by building security expectations into purchasing and service contracts for integrators and equipment vendors.
Report to leadership regularly on OT risk, using measures executives can act on.
Identify
Identify is about understanding your assets, risks and dependencies.
Build and maintain an OT asset inventory, including controllers, HMIs, network devices, firmware versions and communication paths. Passive monitoring is the safest way to start.
Map critical processes and the systems they depend on, including power, communications and third-party services.
Assess risk by consequence, focusing on what could happen to the physical process.
Track vulnerabilities relevant to your actual equipment, and judge them in the context of your network exposure rather than headline scores alone.
Protect: reduce the chance of a bad day
Protect covers access, training, data security, platform security and resilience of the technology itself.
Segment the network into zones with controlled conduits, and keep a clear boundary between corporate IT and control systems.
Lock down remote access with multifactor authentication, a single managed entry point, session approval and recording.
Manage accounts carefully: remove shared and default credentials where possible, and review vendor accounts on a schedule.
Harden systems by disabling unused services and ports, and apply patches through a tested, planned process that respects operational windows.
Control removable media with scanning stations and clear rules.
Train people for their roles, including operators, controls staff and contractors, with content that reflects real OT scenarios.
Back up configurations, controller logic and system images, and store copies offline.
Detect: notice when something is wrong
Detection in OT is often the weakest function, because many control networks have no monitoring at all.
Deploy passive network monitoring that understands industrial protocols, so you can see unexpected connections, new devices and unusual commands such as controller programming changes.
Establish a baseline of normal traffic, which in OT is usually stable and predictable, making anomalies easier to spot.
Collect logs from firewalls, remote access systems, Windows hosts and, where supported, controllers.
Decide who watches the alerts, whether that is an internal team or a provider, and make sure they understand operational context.
Respond and Recover: limit harm and get running again
Respond
Write an OT incident response plan that defines roles across operations, IT, safety, leadership and outside support.
Agree in advance when to isolate, including who has authority to disconnect OT from IT and how to keep the process safe while doing so.
Practice with tabletop exercises built on realistic scenarios, such as ransomware on the corporate network spreading towards OT, or a compromised vendor connection.
Know your reporting obligations to regulators and authorities, and keep contact details current.
Recover
Plan recovery around the process, not just the servers: which systems must be restored first to resume safe operation.
Test restores of controller logic, HMI projects and historian data, not just the backups themselves.
Keep manual operating procedures current so the plant can run, or shut down safely, while systems are restored.
Capture lessons learned and feed them back into Govern and Protect.
Profiles: from where you are to where you need to be
The CSF uses profiles to make the framework practical. A current profile describes the outcomes you achieve today. A target profile describes the outcomes you need, based on your risk, obligations and business goals. The gap between the two becomes your roadmap.
For OT, it often makes sense to build a separate profile for each major facility or system type, because a gas processing plant and a corporate data centre have very different risks. The CSF also describes four implementation levels, ranging from partial and informal practices to adaptive, continuously improving ones. They can help leadership describe how mature and consistent their risk management is, but they are a description, not a certification.
How QBits Networks can help
We help organizations build current and target CSF profiles for their OT environments, using a passive-first OT security assessment to ground the current state in what is actually on the network. Where detection and response are the gap, our OT incident response readiness work turns plans into practised capability. Tell us what you need through our contact page and we'll scope it with you.