ALAMO ACE — The Air Force will soon begin applying zero trust cybersecurity principles to the industrial control systems that run its bases and infrastructure, but a senior Air Force official warned that those operational technology (OT) environments can’t simply inherit the same requirements that the Pentagon has introduced for information technology (IT) systems like laptops and networks. Such IT requirements include a minimum of 91 target-level goals that must be achieved across the entirety of the Defense Department by the end of fiscal 2027.
Speaking at the Alamo ACE conference here in San Antonio, Department of the Air Force Chief Information Security Officer Aaron Bishop said the Pentagon’s 2027 zero trust mandate for information technology is only the first step in securing its assets from cyber attack. A tailored framework specifically for OT is now in the works — one that recognizes that airport runway landing lights and elevators may behave differently from email servers but are still cyber attack vectors.
“You cannot apply 100 percent identically what you did with your laptop to a PLC,” Bishop said, referring to programmable logic controllers that sit at the heart of many OT environments. “They don’t operate the same way. They don’t interface the same way. They don’t connect the same way. You can’t just say those 92 arbitrary activities for computer systems for [are] going to apply to OT.”
By contrast, he said, OT and weapons systems are on a slower glidepath, with zero trust compliance targets expected to push out to the end of the decade. However, the DoD CIO office is developing an OT “fan chart,” which may be released by year-end. A fan chart is a visual roadmap for zero trust activities, laid out like a fan of wedges showing what capabilities must be implemented and in what time frame.
OT As A Mission-critical Attack Surface
Bishop framed the OT push in stark operational terms. The Air Force increasingly recognizes that an adversary doesn’t have to hack a network to disrupt sorties and mission planning. In many cases, knocking out utilities or support systems on a base can have the same effect, as can disrupting power supplies outside the base that cuts off power to the base.
“[OT systems are] typically not connected, so you can’t see them every day, you don’t know what’s happening with them,” said Bishop. “They’re typically proprietary. You also have the lifecycle problem where the system has been there for 10 years. You expect to get 20 more years out of it for your capital cost, but now it’s outdated from an IT perspective or an OT perspective and we need to update it.”
That combination — long lifecycles, vendor-specific hardware and software, and limited visibility — creates a challenge for applying any security framework, much less zero trust’s granular, identity- and data-centric model.
Designing Resilience In From The Start
For Bishop, the end state is not checked compliance, but an infrastructure that continues to function even under active attack. That doesn’t mean employing redundancy or recovery processes. Though those are also vital, the point of zero trust is for the system to never go down in the first place or be taken over by an adversary even when fending off cyber attacks.
That’s a challenge with so many different variations of supervisory control and data acquisition systems in the OT world. Typical secure-by-design engineering principles that normally build resilience for the IT side now need to be transposed into the OT world. The upcoming OT fan chart is intended to give the services a more realistic target for future zero trust compliance.
Bishop cautioned that the work will take time and iteration. He also emphasized that leaving OT outside the zero trust effort is not an option in a world where adversaries are willing to go after any connected system that can affect operations.
“Zero trust is never done,” he said. “You can always find new ways to protect yourself within yourself.”