On April 29, 2026, CISA, the Department of War, DOE, FBI, and State released Adapting Zero Trust Principles to Operational Technology. It’s a timely, 28-page roadmap for critical infrastructure owners who can no longer rely on air-gaps, “closed networks,” or perimeter defenses alone. Operational Technology (OT) cyber defenses can no longer treat the endpoint as a black box. This post explores this further, how to mitigate the risks, and why AppGuard does this exceptionally well.
The guidance is excellent on paper. It diagnoses the unique OT constraints — legacy systems with 10- to 30-year lifecycles, non-negotiable uptime and safety requirements, limited patching windows, proprietary protocols, sparse logging, and the explosion of IT-OT convergence that turns every engineering workstation, HMI, and SCADA server into a high-value target. It organizes recommendations around the NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover) and stresses micro-segmentation, identity/access controls, supply-chain rigor, and careful detection that won’t interfere with real-time processes.
But here’s the honest gap the guidance surfaces (and that every OT practitioner feels daily): most zero-trust frameworks still treat the endpoint as a black box. They secure the door to the plant floor but leave the processes, files, folders, and applications inside those Windows-based HMIs and engineering stations wide open. That’s where the majority of real-world OT breaches begin and where the “lion’s share of the attack surface” actually lives.
AppGuard was built for this!
The OT Reality the Guidance Acknowledges — and AppGuard Solves
OT environments are not IT environments with different branding. A successful attack on a manufacturing line, water treatment plant, or hospital medical device network doesn’t just leak data — it can halt production for days, endanger lives, or trigger physical consequences. The new CISA guide repeatedly warns about:
- Legacy insecure systems that can’t be easily scanned or patched.
- Living-off-the-land (LOTL) techniques and fileless attacks that bypass signature-based tools.
- The impossibility of “detect-and-respond” at machine speed when every alert investigation risks operational disruption.
- The fact that even strong network segmentation and MFA can be bypassed once an attacker reaches an endpoint (session hijacking, credential theft from browsers/OS, process injection, BYOVD, etc.).
Traditional detection layers (AV, EDR, XDR) struggle here. They require constant signature/behavior updates, generate alert fatigue that OT teams (often small and non-specialized) can’t staff 24/7, and risk false positives that force unnecessary shutdowns. Other application-control or containment tools demand 10–100× more policy rules and constant manual tuning — a non-starter when change management already moves at glacial speed to protect safety and uptime.
AppGuard flips the model. Instead of trying to recognize every possible malicious file or behavior (an impossible task against polymorphic, zero-day, and AI-enhanced attacks), it applies zero-trust principles at the computing-process level inside every endpoint.
Three simple, powerful controls do the heavy lifting:
- Launch control — Blocks execution from risky locations or of dangerous OS utilities (PowerShell, certutil, etc.) unless explicitly allowed.
- Containment — Prevents even legitimate-looking but compromised or unpatched applications from harming the host or other processes.
- Isolation — Protects critical files, registry keys, and data from unauthorized access or modification.
Because these controls are technique-based, not signature-based, AppGuard stops ransomware, credential stealers, process-injection attacks, and zero-days without ever needing to “know” the malware. Patented auto-adaptive technology means policies rarely (if ever) need updating — even when applications patch or new processes appear. It runs lightweight (roughly 1/5 the footprint of Windows Defender), works fully offline, and has zero user-visible friction in production environments.
Real-World Proof in OT and Critical Environments
JFE Steel Corporation (one of the world’s largest steelmakers, ¥2.77 trillion revenue) is driving digital transformation across its production sites — classic OT environments full of industrial control systems. Under their “DX with Security” principle, they chose AppGuard specifically because it delivers rigorous protection for the terminals controlling industrial systems while operating reliably in offline conditions and remaining lightweight enough not to impact operations. No constant policy churn. No testing cycles that delay deployment. Just continuous, deterministic blocking of malicious techniques.
Hospitals and healthcare systems (another high-stakes OT/IoT domain with connected medical devices, building management, and clinical workstations) have seen the same results. AppGuard has been recognized by the Japan Hospital Association as optimal for cyber protection and is powering zero-trust initiatives that layer real endpoint controls on top of network segmentation and asset management platforms.
Large-scale enterprise deployments (All Nippon Airways protecting 25,000+ endpoints) show the broader pattern: dramatic reduction in SOC hours (66% in one case), elimination of malware-caused remediations, and the ability to run “business as usual” even when detection layers are blind or overwhelmed. The same logic scales directly to OT — fewer alerts, fewer investigations, fewer forced outages, and the confidence to pursue IT-OT convergence without fear.
How AppGuard Directly Addresses the CISA Guidance’s Priorities
- Protect function — AppGuard is micro-segmentation inside the endpoint. It shrinks the attack surface at the process, file, and folder level — exactly where the guidance notes the bulk of malicious activity occurs after initial access.
- Detect & Respond — By stopping attacks in real time via controls, it dramatically reduces the volume and urgency of alerts that OT teams must investigate. Behavioral detection can focus on the narrow remaining gray areas instead of the entire endpoint.
- Legacy & uptime constraints — No heavy agents that break warranties or require constant updates. Works on older Windows versions common in OT. Auto-adapts without policy pushes that trigger change-management reviews.
- Safety & availability — Deterministic, pre-execution controls mean no “maybe this is bad” moments that force conservative shutdowns. Proven in environments where downtime costs millions per hour.
- IT-OT convergence & supply chain — Reduces the blast radius when a compromised IT laptop or vendor laptop reaches an OT-adjacent endpoint. Complements (does not replace) network ZT, jump hosts, and unidirectional gateways.
In short, the CISA guide gives you the what and the why for zero trust in OT. AppGuard delivers the how at the layer where most breaches actually succeed — the endpoint itself.
Why Not Just Use “Any” Application Control or HIPS?
Because most alternatives create more problems than they solve in OT. They require exhaustive whitelisting, break on every application update, generate excessive false positives, or demand constant expert tuning that OT teams don’t have. AppGuard was designed from day one to avoid those pitfalls: 10–100× fewer rules, implicit lane enforcement that auto-adjusts, and a philosophy of “deny what shouldn’t happen” rather than “guess what’s malicious.”
It doesn’t fight with older OSes the way some tools do. It doesn’t require 24/7 SOC staffing to interpret alerts. And it coexists beautifully with whatever detection or network controls you already have — making them more effective by shrinking what they have to watch.
The Bottom Line for OT Leaders Reading This
The new CISA guidance is a wake-up call that perimeter and identity-focused zero trust is necessary but not sufficient. The endpoint — especially the Windows-based engineering and HMI layer that sits between the corporate network and the PLCs — remains the gaping hole.
AppGuard closes that hole with a controls-based, zero-trust architecture that is:
- Proven in manufacturing (JFE Steel), healthcare OT, aviation, and critical infrastructure.
- Practical for legacy, air-gapped or intermittently connected, safety-critical environments.
- Cost-effective — dramatically lower operational overhead than detection-heavy stacks and far less friction than traditional application control.
- Future-proof — stops tomorrow’s polymorphic and AI-enhanced attacks the same way it stops today’s, because it doesn’t rely on recognizing them.
If you’re an OT owner, CISO, or plant manager wrestling with how to implement the new guidance without breaking production or hiring an army of analysts, start with the endpoints that actually run your processes. That’s where AppGuard turns zero-trust principles into operational reality.
Next Steps We Recommend:
- Download and read the full CISA guidance (linked in comments or search “Adapting Zero Trust Principles to Operational Technology” on cisa.gov).
- Map your OT endpoints — the HMIs, engineering workstations, and servers that touch control systems. These are the highest-leverage places to apply controls first.
- Pilot AppGuard on a non-critical OT-adjacent segment. Measure blocked techniques, alert reduction, and (most importantly) zero operational disruption.
- Reach out to the AppGuard team (www.appguard.us) — we’ve helped organizations exactly like yours move from “we know we have a gap” to “our endpoints are now fortified strongholds.”
The era of hoping detection will be enough, or that network segmentation alone will save us, is over. The organizations that will thrive in the converged IT-OT world are the ones that apply zero trust all the way down to the computing process — inside every endpoint that matters.
AppGuard has been quietly doing exactly that for years. Now the official guidance is catching up.
Let’s make OT security deterministic, not aspirational.
AppGuard stops malware that AV, EDR, and XDR miss — by design, not by detection. Zero trust, completed inside the endpoint.