Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 1800-41 (Initial Public Draft)

Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector

Date Published: May 21, 2026
Comments Due: July 8, 2026 (public comment period is CLOSED)
Email Questions to: [email protected]

Author(s)

Michael Powell (NIST), Michael Pease (NIST), Keith Stouffer (NIST), Toby Maysey (MITRE), Chris Peloquin (MITRE), Bob Stea (MITRE), Kangmin Zheng (MITRE), Geoff Sweet (AWS), Brian Butler (Cisco), Josh Carlson (Dragos), Chris Manrique (Dragos), Chris Bihary (Garland Technology), Jason Drewniak (Garland Technology), Nathan Boeger (Inductive Automation), Brad Fischer (Inductive Automation), Kim Gajewski (Google Cloud), Sri Goutisetti (Google Cloud), Chris Sistrunk (Google Cloud), Stephen Petruzzo (GreenTec-USA), Billy John Stewart (GreenTec-USA), Ahmik Hindman (Rockwell Automation), John Crawford (Siemens AG), Allen Cantrell (Siemens AG), Dallas Levine (Siemens AG), Ray Erlinger (TDi Technologies), Bill Johnson (TDi Technologies), Pam Johnson (TDi Technologies), Clyde Poole (TDi Technologies), Chris Jensen (Tenable), Joshua Moll (Tenable)

Announcement

The NIST National Cybersecurity Center of Excellence (NCCoE) has released this initial public draft NIST Cybersecurity Practice Guide, which provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience. The comment period for this publication is open through July 8, 2026.

Background

As Operational Technology (OT) systems like ICS become increasingly interconnected with IT networks, they are increasingly being targeted by cyber threats, putting factory operations, safety, and property at risk. Organizations operating these systems, such as those in the manufacturing sector, need to have plans and capabilities in place to respond to cyber incidents and restore operations to improve overall resilience.

The NCCoE worked with 11 industry collaborators to develop reference architectures, describe response and recovery scenarios, and demonstrate relevant approaches and capabilities.

This draft publication provides actionable guidelines on responding to and recovering from cyber attacks in manufacturing environments. Discover how to:

  • Understand the risks and potential impact of cyber incidents on your operations
  • Develop a comprehensive response and recovery plan
  • Implement best practices to minimize downtime and restore operations quickly

Comment Now!

We encourage you to review the publication and share your feedback by July 8, 2026. If you’re interested in staying up-to-date on this project, you can join the NCCoE Manufacturing Community of Interest by signing up on our project page.

Abstract

Keywords

cybersecurity; incident investigation; incident response; industrial control systems; manufacturing; operational technology; recovery; response; restoration
Control Families

None selected

Documentation

Publication:
Download URL

Supplemental Material:
Submit comments
Project homepage

Related NIST Publications:
Project Description

Document History:
05/21/26: SP 1800-41 (Draft)

Topics

Security and Privacy

incident response

Applications

operational technology

Sectors

manufacturing