ISA, OTCC partner to advance OT cybersecurity ISA, OTCC partner to advance OT cybersecurity

ISA, OTCC partner to advance OT cybersecurity

The International Society of Automation (ISA) and the Operational Technology Cybersecurity Coalition (OTCC) have announced their intention to collaborate to help strengthen OT cybersecurity across critical infrastructure.

The two organisations have signed a Memorandum of Understanding (MOU) to work together on initiatives that raise awareness of OT cybersecurity risks and solutions, explore strategic issues of shared interest and facilitate technical engagement between members of each organisation.

The goal is to encourage better implementation and recognition of foundational cybersecurity standards like ISA/IEC 62443, the globally recognised consensus-based series of OT cybersecurity standards developed by ISA.

“Protecting critical infrastructure requires sustained collaboration, practical guidance and a shared commitment to standards-based cybersecurity,” said Claire Fallon, CEO of ISA. “This partnership creates an important framework for ISA and OTCC to help advance key OT cybersecurity practices.”

“ISA and OTCC come at OT cybersecurity from different angles – ISA through the standards that define good practice, OTCC through the companies putting them to work,” said Tatyana Bolton, Executive Director of OTCC. “Bringing those perspectives together is how standards move from paper into practice, and we look forward to working with ISA to make that happen.”

OTCC recently published a position paper advocating for a single, horizontal standard for OT cybersecurity rather than a patchwork of sector-specific mandates. The paper recommends that ISA/IEC 62443 be recognized as the global OT security standard. It names ISA/IEC 62443 as an established framework uniquely situated to harmonise around, as this standard has been specifically tailored to meet the requirements of OT.

With one interoperable OT cybersecurity standard such as ISA/IEC 62443, the OTCC paper argues, the burden of adhering to duplicative standards can be reduced, helping to ensure critical infrastructure and industrial operations stay resilient everywhere.