Back to blogs

Blog | JUL 27, 2026

CISA's AA26-097A Advisory Proves Secure by Demand Is No Longer Optional

Cyber Security

In brief: CISA's July advisory documents attacks its own Secure by Demand guidance anticipated eighteen months ago: tampered controller logic, falsified operator displays, commands accepted without verification. Most OT estates, and most OT products, still cannot answer the guidance's core questions. A phased remedy, sign and log first, is deployable today across existing infrastructure, without replacing devices.

On 22 July 2026, CISA and its partner agencies updated a joint advisory (AA26-097A) on an active campaign against US critical infrastructure. According to the advisory, Iranian-affiliated actors have been compromising internet-connected OT devices since at least April, attempting to load malicious project files onto PLCs and manipulate the data shown on HMI and SCADA displays. Affected organisations, across water and wastewater, energy and government facilities, reported operational disruption and financial loss. The update expands the scope to PLCs from multiple major manufacturers and adds new guidance on one specific problem: detecting malicious changes to the reusable code modules inside PLC programs.

Consider what that tells us. The assets running critical infrastructure cannot prove what their own logic and configuration looked like before the intrusion, whether the data on their operators' screens is authentic, or whether the changes they executed were ever authorised. There is no chain of proof, so CISA is left publishing forensic guidance for finding tampering after the fact. The real gap is not better detection tooling; it is tamper-evident proof of every change to data, logic and commands, created at source, before anything goes wrong.

The guidance that saw this coming

Here is the uncomfortable part: the questions that would have exposed this gap have been on the table for eighteen months.

In January 2025, CISA and eleven international partners, including the UK's NCSC, Germany's BSI and the European Commission's DG CONNECT, published the joint guide Secure by Demand, defining twelve security elements OT buyers should demand of the products they purchase. In April 2025, CISA condensed it into a two-page fact sheet built to be carried into procurement meetings. Among its questions:

  • Does the product have tamper prevention or detection? (Configuration Management)

  • Does the product have a way to verify its data integrity? (Protection of Data)

  • Does the product have a method to establish trust for commands to and from critical components? (Secure Controls)

These questions have not yet made their way into most procurement processes, and most estates cannot yet answer them. That is not negligence; it is the normal lag between guidance and practice in an industry where equipment outlives its designers. But the July advisory is what that lag looks like when someone exploits it: logic changes to controllers that nothing flagged, display data operators had no way to verify, commands and project files that devices accepted from whatever the network delivered.

The guidance was not wrong or premature. It was early. This month proved it was also urgent.

The gap: trust was assumed, never proven

This is not a criticism of operators. The installed base running today's energy grids, water systems, ports and plants was engineered decades ago for safety and availability, in an era when the network was assumed to be trusted. It will keep running for decades more.

CISA's guidance Barriers to Secure OT Communication (February 2026), built from interviews with asset owners across the energy, water, transport, chemical and food sectors, confirmed the underlying condition: legacy industrial protocols still lack basic authentication and integrity checks, and secure protocol versions, available for more than twenty years, remain largely unadopted because of cost, complexity and the burden of managing PKI in operational environments.

In plain terms: on most OT networks today, a message claiming to come from a sensor, a controller or an engineering workstation cannot be proven to have come from it, and cannot be proven to have arrived unmodified. The July advisory documents what happens when someone exploits that.

The consequence: this belongs in procurement now

For operators, the advisory changes the calculus in three ways. Incident response is exposed as the weak point: without verifiable records, forensics cannot distinguish a malicious logic change from an engineering error, which is precisely the problem the advisory's new detection guidance is trying to patch after the fact. Boards and regulators will ask whether the Secure by Demand elements are reflected in procurement and estate planning, and after an advisory like this one, "we had not got to it yet" becomes a harder answer to give. And every AI and analytics initiative built on the estate inherits the gap: a model trained on data nobody can verify produces decisions nobody can defend, to a regulator, an insurer or a court.

For manufacturers, the signal is just as clear. The twelve elements have not yet hardened into standard tender language, which is exactly the opportunity: they will, and advisories like this one accelerate it. Products that can answer these questions natively when they arrive will differentiate; products that defer them to the customer's security stack will find the ground shifting beneath them.

The proof: the path CISA recommends is deployable today

To be clear about what would and would not have helped: the campaign's initial access came through internet-exposed devices, and CISA's first mitigation, restricting internet access to PLCs, stands on its own. No data layer substitutes for it.

But the damage described in the advisory, unnoticed logic changes and falsified operational displays, is a failure of proof, not just of perimeter. And CISA has already described the remedy path. Its February 2026 guidance recommends phasing in secure communications: begin by signing all OT communications and logging the results, then progressively tighten controls as confidence grows.

That phased path, integrity and authenticity first, is the model Tributech has been building on since long before the guidance was written.

Our patented data notarization cryptographically signs data at source, creating tamper-evident proof that can be verified at any point in the data lifecycle, without trusting intermediate systems and without re-engineering the devices that produce it. Had the falsified display data in the advisory's scenario passed through a notarized pipeline, the mismatch between signed source values and displayed values would have been detectable, with cryptographic evidence rather than guesswork. Our patented Secure Remote Commands apply the same assurance in the other direction: commands for configuration changes and setpoint changes are signed at origin, checked against policy at the edge and verified by the asset before execution, with cryptographic confirmation returned to the issuer, so an unauthorised change is not a silent event but a policy violation with a record.

Both operate as a middleware layer across the existing estate, integrating over OPC-UA, MQTT, Modbus, ADS and REST, so there is no rip and replace. And both complement the OT network monitoring platforms operators already run: those platforms secure and observe the network, while Tributech's protection travels with the data and the commands themselves.

Adopting Secure by Demand does not require waiting for the installed base to be replaced. It can start now, across brownfield infrastructure, on CISA's own recommended adoption path.

The obligation: the questions are becoming law

The Secure by Demand guide explicitly anchors its elements to the EU Cyber Resilience Act and NIS2. From September 2026, the CRA's Article 14 reporting obligations begin to apply to manufacturers of products with digital elements placed on the EU market, and NIS2 requires essential entities to ensure the products deployed on their networks are secure. Even where the guidance has not yet reached procurement practice, the regulation is arriving on a fixed timetable, and advisories like AA26-097A are the evidence file regulators will point to.

What to do next

If you operate OT infrastructure: start with CISA's own mitigations in AA26-097A. Then use our companion answer sheet, which maps each of CISA's Secure by Demand procurement questions to the mechanism that answers it across a mixed-vendor installed base, to bring the elements into your next procurement cycle and estate review, and talk to us about what a phased rollout, signing and logging first, would look like. Adopting the guidance ahead of your peers is currently a differentiator; soon it will be the baseline. Download the Answer Sheet: here

If you manufacture OT products: these questions are coming to your buyers' tenders, the advisory makes that trajectory unmistakable, and the CRA turns parts of it into law from September. Our OEM design-in brief shows how embedding data notarization and secure remote commands, from a Docker-based attach at gateway level to firmware-level design-in, lets your product answer natively when they arrive, protected by dual patents. Download the OEM Design-In Brief here.

The question list has been public for eighteen months. This month showed why acting on it can no longer wait.

Thomas Plank
CEO, Tributech

Blog | JUL 27, 2026

Contact us

You want to unleash the full potential of your data? Contact us for a first discussion about your data strategy.