A software maintenance window has a tidy beginning and end on a calendar. A pumping station has water in its pipes. Before a controller can restart, somebody has to decide what happens to the process it controls. The update may be a file; the consequences are mechanical.
NIST’s new initial public draft of SP 800-82 Revision 4, published September 21, places operational technology security within performance, reliability and safety requirements. Comments are open until November 30. Its announced changes include broader sector coverage, alignment with Cybersecurity Framework 2.0, expanded asset-management and monitoring guidance, and architecture guidance concerning management functions and zero trust. This is a draft, not a newly imposed compliance deadline.
The useful question for operators reviewing it is smaller and harder than whether their organization has adopted the right framework: when a vulnerability reaches the plant, can anyone turn the advisory into a safe, accountable maintenance decision? Cyberdelia’s argument is that the patch window should be treated as a physical event with an owner, a recovery plan and an observable end state.
The exception needs an engineering record
Consider an illustrative facility where a maintenance workstation manages several controllers. A vendor releases a fix. The security team wants it installed, while operations wants to avoid disturbing production. Neither preference describes the whole system. The relevant decision depends on the actual software version, the vulnerable component’s use, reachable interfaces, operational dependencies and the availability of a tested recovery route. A spreadsheet row marked deferred cannot carry all that information.
A 2025 research paper by Philip Huff, Nishka Gandu and Pavel Novák examined CISA’s known-exploited-vulnerability entries through July 2025. The authors reported that only 13 percent included vendor workarounds or mitigations as alternatives to patching. That is a finding about the information in their historical dataset. It is not a claim that 87 percent of industrial equipment cannot be protected, nor a measurement of the catalog today.
The distinction matters. Missing guidance is a work assignment, not evidence that a particular workaround succeeds. If a team proposes disabling a service, it needs to establish whether that service is involved in the vulnerable path and whether the plant can operate without it. If it proposes a network restriction, it needs to identify which connections the restriction removes and which remain. A control deserves credit for the attack path it changes, not for sounding reassuring in a meeting.
Recovery must include the process
In the illustrative facility, restoring a workstation image would answer only part of the recovery question. Operators would still need to establish that communications, configuration and expected process behavior had returned. A desktop that boots successfully can coexist with a maintenance workflow that no longer works. Conversely, an apparently ordinary application warning could be important if it conceals loss of visibility into a physical process.
Our proposed acceptance record would therefore distinguish software checks from operational checks. It would name the people who can authorize the change, the observations that establish success, and the conditions that require stopping. Those details must come from the facility’s engineering and safety procedures. They cannot be manufactured by a generic security checklist or borrowed from a different plant simply because the hardware looks similar.
A recovery plan also needs an honest account of dependencies. Can the organization obtain the required installer, license, configuration and credentials when a vendor portal is unavailable? Who can interpret the resulting alarms? Is the spare machine actually prepared for this environment? These are questions to investigate before a maintenance event. They are not instructions to bypass controls or experiment on a running process.
Make temporary protection temporary
The dangerous part of a deferred update is often its administrative afterlife. The exception survives while the justification ages. A vendor connection changes, a replacement workstation appears, or a new service is enabled. The original compensating measure may remain on paper even though the conditions that made it useful have disappeared.
Cyberdelia proposes that each exception carry a review date and explicit change triggers. A new access route, a revised vendor advisory, or a change in operating mode should reopen the decision. The record should identify who owns that review. Without ownership, temporary protection becomes a permanent story that the organization tells itself.
Monitoring belongs in the same record. What activity would indicate that the assumed boundary has been crossed? Where would that evidence appear, and who would act on it? An alert that nobody can interpret during a night shift is an incomplete arrangement. So is a dashboard that quietly stops receiving data without making the loss visible.
Send NIST the inconvenient details
The draft’s public-comment period gives practitioners an opportunity to explain where broad guidance becomes difficult to execute. Useful feedback would identify the system context, the dependency that blocks a proposed safeguard, and the evidence an operator would need to approve it. Removing sensitive facility details does not require removing the engineering problem.
The limit of this analysis is deliberate: no document can determine whether an unspecified controller, workstation or process is safe to update. The proposed record is a way to make that decision inspectable, not a replacement for qualified site-specific judgment. NIST supplies a developing framework; the facility still has to supply the facts.
A patch is complete when the intended security change has been established and the system’s required operation has been verified. For equipment that moves water, power or material, those are connected obligations. The calendar can reserve the window. Only the people responsible for the plant can say what happened inside it.
Related reporting: The Air Gap Ends Where the File Begins.
Sources and reporting limits
NIST SP 800-82 Revision 4, initial public draft; Revision 3, final guidance; Huff, Gandu and Novák, 2025 research preprint. This article reviews the draft’s announcement and the paper’s abstract. It does not claim a line-by-line review of the draft or an independent replication of the study. The facility scenario and proposed maintenance record are Cyberdelia analysis.
