Date Published: May 21, 2026
Comments Due:
Email Questions to:
Author(s)
Michael Powell (NIST), Michael Pease (NIST), Keith Stouffer (NIST), Toby Maysey (MITRE), Chris Peloquin (MITRE), Bob Stea (MITRE), Kangmin Zheng (MITRE), Geoff Sweet (AWS), Brian Butler (Cisco), Josh Carlson (Dragos), Chris Manrique (Dragos), Chris Bihary (Garland Technology), Jason Drewniak (Garland Technology), Nathan Boeger (Inductive Automation), Brad Fischer (Inductive Automation), Kim Gajewski (Google Cloud), Sri Goutisetti (Google Cloud), Chris Sistrunk (Google Cloud), Stephen Petruzzo (GreenTec-USA), Billy John Stewart (GreenTec-USA), Ahmik Hindman (Rockwell Automation), John Crawford (Siemens AG), Allen Cantrell (Siemens AG), Dallas Levine (Siemens AG), Ray Erlinger (TDi Technologies), Bill Johnson (TDi Technologies), Pam Johnson (TDi Technologies), Clyde Poole (TDi Technologies), Chris Jensen (Tenable), Joshua Moll (Tenable)
Announcement
The NIST National Cybersecurity Center of Excellence (NCCoE) has released this initial public draft NIST Cybersecurity Practice Guide, which provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience. The comment period for this publication is open through July 8, 2026.
Background
As Operational Technology (OT) systems like ICS become increasingly interconnected with IT networks, they are increasingly being targeted by cyber threats, putting factory operations, safety, and property at risk. Organizations operating these systems, such as those in the manufacturing sector, need to have plans and capabilities in place to respond to cyber incidents and restore operations to improve overall resilience.
The NCCoE worked with 11 industry collaborators to develop reference architectures, describe response and recovery scenarios, and demonstrate relevant approaches and capabilities.
This draft publication provides actionable guidelines on responding to and recovering from cyber attacks in manufacturing environments. Discover how to:
- Understand the risks and potential impact of cyber incidents on your operations
- Develop a comprehensive response and recovery plan
- Implement best practices to minimize downtime and restore operations quickly
Comment Now!
We encourage you to review the publication and share your feedback by July 8, 2026. If you’re interested in staying up-to-date on this project, you can join the NCCoE Manufacturing Community of Interest by signing up on our project page.
Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing number of cyber incidents, posing a real threat to safety and production, and impacting the economic performance of manufacturing organizations. Though defense-in-depth security architecture helps mitigate cyber risks, it cannot eliminate all cyber risks; therefore, manufacturing organizations should also have a plan to recover and restore operations should a cyber incident impact operations. This practice guide showcases various cyber attack scenarios developed with industry collaborators to produce a methodology that enables the adoption and implementation of response and recovery measures in manufacturing environments to strengthen operational resilience.
Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing...
See full abstract
Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing number of cyber incidents, posing a real threat to safety and production, and impacting the economic performance of manufacturing organizations. Though defense-in-depth security architecture helps mitigate cyber risks, it cannot eliminate all cyber risks; therefore, manufacturing organizations should also have a plan to recover and restore operations should a cyber incident impact operations. This practice guide showcases various cyber attack scenarios developed with industry collaborators to produce a methodology that enables the adoption and implementation of response and recovery measures in manufacturing environments to strengthen operational resilience.
Hide full abstract
Keywords
cybersecurity; incident investigation; incident response; industrial control systems; manufacturing; operational technology; recovery; response; restoration
Control Families
None selected