For manufacturers, cybersecurity is no longer limited to laptops, email, servers, and office networks.

Production increasingly depends on connected technology.

Operational systems may rely on networks, servers, authentication, remote access, cloud platforms, virtualization, data, and other IT services to keep processes running.

That means a cybersecurity problem does not necessarily have to begin on the plant floor to affect the plant floor.

The National Institute of Standards and Technology reinforced that connection on September 21, 2026, when it released the initial public draft of NIST Special Publication 800-82 Revision 4, Guide to Operational Technology Security.

NIST defines operational technology, or OT, as programmable systems and devices that interact with the physical environment or manage devices that do. That can include industrial control systems, building automation systems, physical access controls, environmental monitoring systems, and other technologies tied to physical processes.

The new draft updates NIST's guidance for securing these environments while accounting for the performance, reliability, and safety requirements that make OT different from traditional IT.

For manufacturing leaders, the important takeaway is not simply that there is a new NIST document to read.

It is that operational technology risk increasingly has to be understood as part of the organization's broader business and cybersecurity risk.

What Is OT Security in Manufacturing?

Operational technology security is the protection of the systems, devices, networks, and supporting technology used to monitor or control physical manufacturing processes.

That is different from traditional information technology security, although the two environments increasingly depend on one another.

Traditional IT may include:

  • Email
  • Microsoft 365
  • Business applications
  • File servers
  • Identity systems
  • Employee endpoints
  • Cloud services
  • Business networks

OT may include systems and devices involved in:

  • Production processes
  • Industrial control
  • Machine monitoring
  • Building controls
  • Environmental systems
  • Physical access
  • Industrial automation

The important issue for manufacturers is not deciding whether a particular system belongs neatly in the IT box or the OT box.

The more useful question is:

What does production depend on, and what happens if one of those dependencies becomes unavailable?

That is an operational-risk question.

Why Did NIST Update Its OT Security Guidance?

NIST's September 2026 draft of SP 800-82 Revision 4 expands and reorganizes its OT security guidance.

Among the documented changes, NIST says the revision:

  • Aligns the guidance more closely with the NIST Cybersecurity Framework 2.0
  • Expands discussion of OT risk management as part of broader enterprise risk management
  • Adds guidance around asset management
  • Expands network monitoring and detection guidance
  • Adds security architecture guidance
  • Addresses areas such as Industrial Internet of Things and cloud convergence
  • Expands the range of OT environments discussed

The draft is open for public comment through November 30, 2026.

This is important context: Revision 4 is currently a draft, not finalized guidance.

Manufacturers should not treat it as a new regulation or mandatory requirement simply because NIST published it.

Instead, it provides a current view of how NIST is approaching OT cybersecurity and risk management.

Review NIST SP 800-82 Revision 4

OT Risk Is Business Risk

One of the most useful changes in the new NIST draft is its stronger connection between OT cybersecurity and broader enterprise risk management.

That makes sense for manufacturing.

An operational technology problem does not stay neatly inside the cybersecurity department when it affects:

  • Production
  • Availability
  • Shipping
  • Quality
  • Facility operations
  • Employee access
  • Customer commitments
  • Recovery priorities

This is why executives, operations leaders, plant leadership, and IT teams need a shared understanding of technology risk.

The conversation should not simply be:

"Is the network secure?"

It should also include:

"What business processes depend on this technology?"

"What would happen if it became unavailable?"

"What systems would have to be restored first?"

"Who is responsible for making those decisions?"

That moves cybersecurity from a technical conversation to a business-risk conversation.

Your Plant Floor May Depend on Systems That Are Not on the Plant Floor

One of the easiest mistakes to make in manufacturing cybersecurity is focusing only on industrial devices when thinking about production risk.

Production may depend on systems outside the immediate OT environment.

Depending on the manufacturer, those dependencies could include:

  • Identity and authentication
  • Network services
  • Servers
  • Virtual infrastructure
  • Cloud services
  • Remote access
  • Business applications
  • File systems
  • Backup infrastructure
  • Vendor connectivity
  • Internet connectivity

The exact dependencies will be different for every organization.

That is why manufacturers should map them rather than assume where operational risk begins and ends.

A piece of production equipment may be functioning normally while a supporting technology problem still prevents employees from using the process as intended.

The question is not simply:

"Is the machine working?"

It is:

"Can the entire process the machine depends on continue operating?"

Start With Visibility Into the Environment

Manufacturers cannot manage technology risk effectively without understanding what is present.

NIST's Revision 4 draft expands its guidance around asset management, reinforcing the role that visibility plays in OT security.

For manufacturers, an asset-management discussion should go beyond creating a list of devices.

Leadership and IT should understand:

  • What critical systems exist
  • What business or production process each system supports
  • Who owns or manages it
  • How systems communicate
  • Which systems depend on one another
  • Which vendors have access
  • Which systems can be accessed remotely
  • What happens if a critical system becomes unavailable

That last question is particularly important.

An inventory tells you what you have.

A dependency map helps tell you what matters when something breaks.

IT and OT Security Need Coordination

IT and OT environments often have different priorities.

An office workstation might tolerate a reboot to complete an update.

A production-related system may have operational, reliability, or safety requirements that make the timing and process more complicated.

NIST specifically notes that OT security needs to account for the performance, reliability, and safety requirements of these environments.

That means manufacturers should avoid simply applying every traditional IT security practice to OT without considering operational consequences.

It also means the opposite approach can create problems:

OT cannot be treated as completely separate from cybersecurity simply because its requirements are different.

Manufacturing organizations need coordination between the teams responsible for IT, operations, engineering, vendors, security, and business continuity.

For organizations that already have an internal IT team but need additional cybersecurity and infrastructure support, AvTek's Co-Managed IT Services are designed to extend internal IT capabilities while allowing the organization's team to retain control over policies and risk decisions. AvTek's documented co-managed capabilities include cybersecurity monitoring, Microsoft 365 protection, identity and access controls, cloud and core infrastructure support, and related IT services.

Remote Access Belongs in the OT Risk Conversation

Manufacturers frequently depend on remote connectivity for legitimate business and technical reasons.

Vendors may need access to support equipment.

Employees may need remote access to business systems.

IT teams may need to troubleshoot infrastructure without being physically present.

Remote connectivity can provide real operational value.

It also means organizations need to understand:

  • Who can connect remotely
  • Which systems they can reach
  • How access is authenticated
  • Whether access remains enabled when it is no longer needed
  • How privileged access is managed
  • How remote activity is monitored

These are areas where traditional cybersecurity practices and operational security intersect.

AvTek's Cybersecurity Services include network security, VPN and remote-access security, multi-factor authentication, privileged access management, role-based access controls, conditional access, monitoring, and security assessments.

Those capabilities can help manufacturers address the IT and access-control side of the broader operational-risk picture without assuming that traditional IT controls alone solve every OT security challenge.

Backups Are Part of OT Security, but a Backup Is Not the Same as Recovery

NIST has also put specific attention on OT backup management this year.

In June 2026, the NIST National Cybersecurity Center of Excellence released Special Publication 1339, OT Backup Quick Start Guide.

NIST says effective OT backup management involves:

  • Integrating backups into change-management processes
  • Creating backups regularly
  • Testing backups
  • Reviewing backups during recovery exercises

That distinction matters.

A manufacturer can have backup files and still have unanswered recovery questions.

For example:

What gets restored first?

Which systems depend on one another?

How do you know the backup is usable?

Who decides when a recovered system is safe to reconnect?

What happens if a supporting IT service is still unavailable?

When was the recovery process last tested?

NIST's guidance reinforces an important idea:

Backup is an activity. Recovery is a capability.

Read NIST's OT Backup Quick Start Guide

Manufacturing Recovery Needs to Account for Dependencies

Disaster recovery planning becomes more useful when it starts with business processes rather than individual servers.

Suppose a manufacturer successfully restores a critical application.

That does not automatically mean the production process that depends on it can resume.

The application may also depend on:

  • Authentication services
  • Network connectivity
  • DNS or other network services
  • Storage
  • Virtual infrastructure
  • Databases
  • Vendor connectivity
  • Cloud services
  • User endpoints
  • Other applications

A recovery plan should therefore answer more than:

"Do we have a backup?"

It should answer:

"What has to be working, and in what order, before this process can operate again?"

AvTek's Data Backup and Disaster Recovery Services include automated backups, backup monitoring and verification, disaster recovery planning, RTO and RPO alignment, business continuity strategies, failover and recovery solutions, and recovery testing.

For manufacturers, those IT recovery capabilities should be considered alongside the organization's operational recovery requirements.

Security Monitoring Matters When IT and OT Become More Connected

The more connected the environment becomes, the more valuable visibility becomes.

NIST's Revision 4 draft expands its discussion of network monitoring and detection within OT security.

Monitoring can help organizations understand unexpected activity, identify security events, and investigate what happened when something goes wrong.

But monitoring should be designed around the environment being protected.

Manufacturers should consider questions such as:

  • Which networks and systems are being monitored?
  • Who reviews alerts?
  • How are significant events escalated?
  • Are IT and operational teams communicating about relevant incidents?
  • Does the organization know what "normal" activity looks like?
  • How would suspicious activity affecting a production dependency be handled?

AvTek's cybersecurity services include managed detection and response, security monitoring and alerting, threat triage and escalation, endpoint detection, incident response support, and network-security controls.

Vendor Access Is Part of Manufacturing Cyber Risk

Manufacturing environments often rely on specialized vendors.

Those relationships can be essential for maintaining equipment and systems.

They can also create technology dependencies that need to be understood.

Manufacturers should know:

  • Which vendors can access company systems
  • What they can access
  • How they authenticate
  • Whether they use shared or individual accounts
  • When access is enabled
  • Whether access is removed when no longer needed
  • What systems rely on vendor-hosted services
  • How a vendor outage would affect operations

The goal is not to eliminate vendor access.

The goal is to make it intentional and governed.

This is another area where executive cybersecurity oversight can help connect technology decisions to business risk.

For manufacturers that need additional strategic cybersecurity leadership, AvTek's vCISO Services include cybersecurity risk management, security strategy, remediation planning, policies and documentation, vendor-risk discussions, and executive guidance. AvTek specifically lists construction, manufacturing, and engineering organizations among the industries those services support.

OT Security Is Not Just an IT Department Project

One of the biggest themes manufacturers should take from the updated NIST guidance is governance.

Revision 4 has been reorganized around the NIST Cybersecurity Framework 2.0 and places additional emphasis on the Govern function and alignment between OT risk and broader enterprise risk management.

That makes OT security a leadership issue.

Operations may understand production dependencies.

Engineering may understand equipment.

IT may understand infrastructure and identity.

Security may understand threats and controls.

Leadership understands business priorities.

A useful cybersecurity program needs those perspectives to connect.

Questions for leadership include:

Who owns operational cyber risk?

Who decides which systems are most critical?

Who approves remote vendor access?

Who determines acceptable downtime?

Who decides which risks need remediation first?

Who leads when an incident affects both technology and production?

Those are governance questions, not merely technical ones.

Manufacturers Should Prioritize Risk, Not Chase Every Security Control

The goal of OT security is not to collect as many security tools as possible.

It is to identify meaningful risk and make informed decisions about reducing it.

NIST's updated draft explicitly connects OT risk management with broader enterprise risk management.

A manufacturer can apply that concept by asking:

  1. What business processes are most important?
  2. What technology do those processes depend on?
  3. What could disrupt that technology?
  4. What controls already exist?
  5. Where are the meaningful gaps?
  6. What would the business impact be if the risk became real?
  7. Which remediation efforts should happen first?

That creates a more useful roadmap than treating every vulnerability as equally important.

AvTek's Managed IT Services include proactive monitoring, patch management, cybersecurity, risk assessments, recommendations, strategic IT planning, and support for manufacturing and other small to midsized organizations.

Frequently Asked Questions About OT Security for Manufacturers

What is operational technology in manufacturing?

NIST defines operational technology as programmable systems or devices that interact with the physical environment or manage devices that do.

In manufacturing, that can include industrial control systems and other technology used to monitor or control physical processes.


What is the difference between IT and OT security?

IT security generally focuses on information systems, data, users, and traditional business technology.

OT security focuses on technology that interacts with physical processes.

The environments have different operational requirements, but they can also depend on one another. NIST emphasizes that OT security needs to account for performance, reliability, and safety requirements.


Is NIST SP 800-82 Revision 4 a new manufacturing regulation?

No.

As of October 2026, Revision 4 is an initial public draft of NIST guidance. The public comment period runs through November 30, 2026.

Manufacturers should not describe it as a new regulatory requirement unless another applicable authority specifically requires them to follow it.


Why should manufacturers care about IT/OT dependencies?

Production processes can depend on IT services such as identity, networks, servers, applications, remote connectivity, and other infrastructure.

Understanding those dependencies helps organizations make better security, business-continuity, and recovery decisions.


What does NIST recommend for OT backups?

NIST's 2026 OT Backup Quick Start Guide recommends integrating backups into change management, creating backups regularly, testing them, and reviewing them during recovery exercises.


Is having backups enough for manufacturing recovery?

Backups are an important part of recovery, but organizations also need to understand restoration priorities, system dependencies, recovery procedures, and whether backups work as intended.

NIST specifically recommends testing OT backups and reviewing them during recovery exercises.


Who should be involved in manufacturing cybersecurity?

The appropriate participants depend on the organization, but OT cybersecurity can involve leadership, IT, cybersecurity, operations, engineering, facilities, vendors, and other teams responsible for systems or business processes.

NIST's current OT guidance connects OT cybersecurity to broader enterprise risk management rather than treating it solely as a technical issue.

The Most Important Question Is Not "Is Our OT Secure?"

That question is too broad to be useful.

A better set of questions is:

What does our production environment depend on?

Which of those dependencies create the most business risk?

Who has access to them?

How are they monitored?

What happens when one becomes unavailable?

Can we recover it?

Have we tested that recovery process?

NIST's latest OT guidance reinforces the need to look at operational technology through the lenses of cybersecurity, governance, asset management, monitoring, architecture, and enterprise risk.

Manufacturers do not need to turn every executive into an OT cybersecurity engineer.

But leadership should have a clear understanding of where technology risk can become production risk.

AvTek Solutions helps manufacturing organizations strengthen the IT and cybersecurity foundation those operations depend on through managed IT, co-managed IT, cybersecurity services, backup and disaster recovery, and vCISO guidance.

If you are not sure which IT systems your production environment depends on, how those systems are protected, or how quickly your organization could recover from a disruption, that is the place to start.

Talk with AvTek about your manufacturing technology risk