Expert Opinions

Federal Policy Has Moved to OT. Invisinet Is Already There.

Written by:
Bobby Wescott
Bobby Wescott
Published on:
July 28, 2026
Federal Policy Has Moved to OT. Invisinet Is Already There.

I spend my week on calls with the people who run plants, utilities, and defense programs, plus the security and procurement teams who buy on their behalf. For the last couple of years, those conversations all circled the same gap. Everyone agreed that operational technology needed better protection. Nobody in Washington had written down what "better" actually meant for a control system that has been running since before most of us had smartphones.

That gap closed this year. Three federal signals landed almost on top of each other, and together they tell every buyer in this market what the next few budget cycles look like. I want to walk through each one in plain terms, because the technical detail matters less than what it means for your organization and your timeline.

The Pentagon rewrote the rulebook for control systems

In July 2025, the Department of Defense issued a directive extending its Zero Trust mandate to operational technology. A joint federal guide followed in April 2026, and it does something the earlier Zero Trust framework never attempted: it admits that IT and OT are not the same problem.

That distinction matters because most Zero Trust products on the market were built for laptops and cloud applications, then relabeled for the plant floor. The new guidance does not work that way. It expects policy to be enforced right at the asset, not from a console somewhere in the cloud. It expects the network to go down or get cut off, and it expects safety and uptime to win over connectivity when that happens. It expects you cannot run an active scan against a programmable logic controller without risking a shutdown.

None of that was news to us. Invisinet grew out of tactical defense networks, where a control plane you can lose is a control plane you cannot depend on. Our architecture enforces identity locally at every gateway, so when a connection drops, the environment keeps running to policy instead of falling open or falling over. We did not build that to check a box. It is the reason the company exists.

Someone is already inside, and they are not there to steal your data

The second signal came from a joint advisory issued by CISA, the NSA, and the FBI, alongside partners at Energy, EPA, and TSA and allied intelligence services. Their assessment: state-sponsored actors linked to the PRC have been sitting inside U.S. critical infrastructure, in some cases for more than five years, across communications, energy, transportation, and water utilities.

This is not a smash-and-grab. There is no malware to catch, because the intrusion does not use any. The actors log in with valid, stolen credentials and run the same administrative tools your own team uses, so nothing looks out of place. They got in through unpatched edge devices, the same appliances that sit at the edge of most industrial networks today, and moved from there. They are not after your data. They are positioning themselves to disrupt operations if a crisis calls for it.

For a buyer, that changes the question you should be asking your vendors. It is no longer "can we detect an intrusion." It is "can an intruder reach our operational systems at all, even with valid credentials in hand." Our answer is that we do not let the connection start in the first place. Every session has to prove identity before it exists, and a stolen password does not produce that proof. A scan looking for a foothold gets nothing back. You cannot move toward a target you cannot see.

AI is the business case forcing the air gap open

Here is the one I hear about most from commercial customers, and it has nothing to do with a federal mandate. Every plant I talk to wants predictive maintenance, quality vision, or AI-driven process optimization, and every one of those projects needs the same thing: data flowing out to a model, and decisions flowing back in to adjust setpoints. The boundary that used to separate the plant floor from everything else, the one that used to be the whole security plan, is becoming a two-way street whether anyone planned for it or not.

The numbers explain why regulators are moving fast. Ransomware attacks against industrial organizations rose 64% in 2025, hitting roughly 3,300 organizations, and manufacturing has been the most targeted sector for five years running. Washington has answered with a run of new guidance: joint principles for AI in OT in December 2025, a White House cyber strategy naming the grid, water systems, and hospitals as protected terrain in March 2026, the zero trust OT guidance in April, and CISA's direction in May telling operators to plan on running isolated for weeks at a time if they have to. Federal guidance in this space has a track record of becoming sector regulation, and eventually insurance underwriting criteria. Buyers who move now are ahead of both.

Where we come in

None of this requires ripping out equipment that has been running fine for twenty years. Invisinet lays an identity layer across the network you already have. Authorized AI pipelines and analytics traffic move normally. Everything else sees nothing, on the same wire.

A few things I would point to specifically. There is no hardware refresh required, because the identity layer rides on the protocols already in place, including some old enough to vote. There is no new dependency on the cloud, because enforcement happens locally, so the plant does not stop running policy just because the WAN or a vendor's console goes down. The blast radius stays contained, because trust-based segmentation keeps a ransomware event on the IT side from reaching the floor, which is the loss pattern insurers price hardest. And every session is tied to an identity at the asset level, which is increasingly the evidence regulators and underwriters ask to see.

Three mandates, one architecture

What strikes me about this year is that three groups arrived at the same conclusion from three different starting points. Defense planners want enforcement at the asset and operation that survives disconnection. Threat intelligence analysts want stolen credentials to stop working and assets that cannot be found by a scan. Enterprise security teams chasing AI want the data path open without widening the target. Most federal reference architectures still describe a centralized policy engine as the default. We built for a distributed one from day one, because that is what a tactical network demanded of us long before OT compliance caught up to the same idea.

If you are mapping your own environment against any of these three mandates and want to talk through where the gaps are, reach out. We usually start by laying your network against the guidance and finding the three highest-risk paths first. That conversation tends to be more useful than a product demo, and it is where most of our best relationships start.

Bobby Wescott is the Chief Revenue Officer of Invisinet Technologies. Invisinet's First Packet Authentication technology is patented and FIPS 140-3 validated (Certificate #5273, Active May 2026). It is currently deployed in U.S. government and critical infrastructure environments. For more information, visit invisinet.com.

Table of contents
sign up for newsletter
Receive updates on Invisinet’s solutions and security insights.