May 20, 2025
May 20, 2025
Dale Peterson's article, "What's Next for DHS / CISA in OT Security?" published on May 14, 2025, critically examines the U.S. Department of Homeland Security (DHS) and the Cybersecurity and Infrastructure Security Agency's (CISA) approach to Operational Technology (OT) security. Drawing from interviews with past DHS OT security leaders, Peterson highlights a consistent pattern: a focus on information sharing and public-private partnerships, but a lack of measurable outcomes or metrics to assess the effectiveness of these initiatives.
Peterson notes that while previous leaders like Marty Edwards and Chris Krebs emphasized organizational changes and awareness campaigns, tangible improvements in OT cybersecurity posture remained elusive. Under Jen Easterly's tenure, CISA achieved significant visibility and raised awareness about OT security, especially among small and medium-sized enterprises. However, Peterson argues that this period was marked by high activity but limited measurable results in reducing OT cyber risks.
Looking ahead, Peterson expresses cautious optimism about Sean Plankey's appointment, given his background in both the private sector and government energy cybersecurity programs. He advocates for a shift from broad messaging to more substantive engagement with the OT security community, recruitment of professionals with OT experience into CISA, and the establishment of clear metrics to evaluate the success of security initiatives. Peterson emphasizes the need for DHS and CISA to move beyond awareness campaigns and focus on actionable strategies that demonstrably enhance OT cybersecurity.
Source: https://dale-peterson.com/2025/05/14/whats-next-for-dhs-cisa-in-ot-security/