Nation-State Threat Critical Infrastructure CISA Guidance · April 29, 2026
Zero Trust for OT
Volt Typhoon is prepositioning inside U.S. critical infrastructure OT networks — using stolen IT credentials and legitimate tools. CISA, DoD, FBI, DOE, and DOS issued joint guidance. Here's what to do.
At a Glance
Threat Actor
Volt Typhoon (PRC)
Issuing Agencies
CISA · DoD · FBI · DOE · DOS
Attack Type
IT credential theft → OT lateral movement
Technique
Living off the Land (LOTL)
Sectors at Risk
Energy, water, manufacturing, transport, comms
Goal
Physical damage capability — not ransomware
Core ZT Failure
Shared AD between IT and OT
OT Constraint
Legacy devices: can't patch, scan, or run agents
This Is Not Hypothetical CISA has confirmed Volt Typhoon has been inside U.S. critical infrastructure networks. They are not disrupting systems today — they are waiting. The access already exists. The guidance exists to close the door before it is used.
5 Actions Right Now
  • 1
    Deploy TAPs at every IT/OT boundary Passive network visibility first — active scanning can crash legacy OT devices. You cannot protect what you cannot see.
  • 2
    Enforce MFA on all OT remote access Every jump host, every session, every user including vendors. A single stolen password should not reach OT.
  • 3
    Separate OT accounts from enterprise AD Shared Active Directory is the Volt Typhoon lateral movement path. OT systems must not be reachable with corporate credentials.
  • 4
    Audit and scope-limit all vendor remote access Compile every third-party account with OT access. Limit scope, require session logging, time-limit all access.
  • 5
    Table-top your OT incident response plan Pre-authorize soft segmentation procedures before you need them. Do not design OT containment during an active incident.
Volt Typhoon — The Attack Chain
  • Step 1: Compromise the corporate IT environment (phishing, exposed VPN, public-facing apps)
  • Step 2: Steal Active Directory credentials — the key to adjacent OT systems
  • Step 3: Move laterally into OT using legitimate tools already installed — no malware, no signatures
  • Step 4: Establish persistent access, map operational systems, and wait
Zero Trust Controls by Pillar
ZT Pillar Immediate Action Strategic Fix Framework / Top 10
Identity
Top 10 #1, #4, #9, #10
Separate OT Active Directory from enterprise AD. Enforce MFA on all jump hosts. Audit break-glass account scope and expiry. Deploy Zero Standing Privilege for OT: per-session, scoped access only. No standing administrative credentials. Time-limited break-glass accounts with automatic alerts on use. NIST SP 800-207 §3.3 · CISA ZTMM Identity
Devices
Top 10 #2
Deploy network TAPs at IT/OT boundaries for passive asset discovery. Do not use active scanning — it can crash legacy PLCs and RTUs. Build incremental OT asset inventory from passive traffic data. Add ZT requirements (logging, SBOM, ICAM) to all new OT procurement specifications. NIST SP 800-207 Tenet 6 · CISA ZTMM Devices
Networks
Top 10 #5, #7
Treat the IT/OT boundary as a hard enforcement point. Log all cross-boundary traffic. Restrict enterprise accounts from OT systems immediately. Deploy data diodes for unidirectional OT-to-IT data flows. Harden jump hosts as single authorized remote access entry — MFA, session recording, minimum-scope access. Pre-plan soft segmentation procedures for incident containment. NIST SP 800-207 Tenet 2 · CISA ZTMM Networks
Apps & Workloads
Top 10 #3, #6
Audit OT engineering workstations for unnecessary software. Enable application allowlisting on HMIs where feasible (WDAC for Windows-based systems). Wrap legacy OT protocols (Modbus, DNP3, EtherNet/IP) in TLS-enabled gateways at zone boundaries. Apply SSVC framework to prioritize OT patches by actual exploitation risk vs. downtime cost. NIST SP 800-207 Tenet 1 · CIS Controls v8 #2, #4
Data
Top 10 #8
Concentrate logging at IT/OT junction points and jump hosts — where visibility is feasible and value is highest. Deploy CISA's open-source Malcolm SIEM for industrial protocol parsing. Build OT-specific backups: engineering logic, ladder diagrams, I/O lists, configuration, startup values. Validate via checksum before needed. Know your OT recovery time objective from a known-good state. NIST SP 800-207 Tenet 7 · CISA ZTMM Visibility
Recommended 90-Day Path
Timeframe Priority Actions
Days 1–7 Deploy TAPs at IT/OT boundaries · Enforce MFA on jump hosts · Audit vendor remote access · Export 90 days of IT/OT boundary logs
Days 8–30 Passive asset discovery · Separate or restrict OT AD accounts · Table-top OT IR plan with soft segmentation · Enable full vendor session logging
Days 31–90 Deploy Malcolm SIEM for industrial protocol visibility · Implement SSVC-based OT patch prioritization · Add ZT and SBOM requirements to OT procurement specs · Validate OT-specific backups

Get the Full Advisory

The complete OZTP advisory includes all five ZT pillars with NIST and CISA framework citations, the full OZTP Top 10 mapping for OT environments, and access to Agent Zeta — our free AI Zero Trust advisor.

oztp.org/advisories Free  ·  No account required