The Need to Protect Critical Infrastructure with Cybersecurity for IoT and OT

With the growing threat of cyberattacks on critical U.S. infrastructure, is the government prepared?

A December 1, 2022, report released by the U.S. Government Accountability Office (GAO) called for immediate action on cybersecurity for IoT and OT-connected devices to provide better security for critical infrastructure vulnerable to today’s sophisticated cyber threats.

The report indicates 16 critical infrastructure areas reliant on internet-connected devices and systems, providing essential services from electricity to health care. All sectors fall under the GAO report’s high-risk category.

A primary concern for the GAO is that more action is needed to provide the level of cybersecurity required to secure these critical U.S. departments. The GAO has provided more than 90 cybersecurity recommendations since 2010, with more than 50 unimplemented as of June 2022.

Mike Sheward, Head of Security for Particle, believes the U.S. government needs to get serious about cybersecurity for IoT and OT.

Mike’s Thoughts

“On the government accountability officers report on IOT and OT security. So, there are a couple of things that jump out to me. The first is that there are no shortage of different agencies within the federal government making recommendations about cybersecurity for these kinds of devices and having lots of different recommendations from lots of different places about lots of different types of devices is a very good way to kind of get into a state of analysis paralysis and not apply anything cause you’re worried about which standard you should be applying.

So, I would like to see more of a focus on the ecosystem that those devices are connected to. Maybe kind of sorting them out by classification so we can focus on securing that platform or that environment more than each device on a device-by-device basis. That would be probably more effective. The second thing is that a lot of the previous recommendations made in the report have not been implemented yet. That’s because, in my opinion, the government is probably still in the discovery stage for a lot of this stuff. The larger the organization, the harder it is to apply any kind of cybersecurity program.

Just because you don’t know what’s out there, you lose track of it. You can’t protect what you don’t know about. It’s hard to think of many organizations that are bigger than the federal government. So, I imagine that they are, working on doing the discovery, and so I need to focus on speeding that up so that you could probably do a lot of kind of disabling of things that no longer need to be in the environment, and then focusing on the things that are left for the new security standards.

Follow us on social media for the latest updates in B2B!

Image

Latest

data center
The Next Data Center Bottleneck Isn’t Power or Cooling, It’s People
February 8, 2026

With the rapid rise of AI workloads, data centers are being built with higher power density, stricter reliability expectations, and cooling technologies that are evolving faster than most teams can adapt. As a result, these facilities aren’t just getting bigger—they’re becoming harder to operate, harder to staff, and far less forgiving when something goes…

Read More
Precision With Purpose: The Geospatial Advantage in Telecom Network Planning
February 7, 2026

Telecom networks are no longer planned or evaluated in isolation. As 5G, private LTE, fixed wireless, and mission-critical communications expand, operators are expected to deliver stronger coverage, higher reliability, and demonstrable performance—often while managing complex technologies and constrained resources. Regulators, customers, and public agencies are increasingly focused on outcomes that can be measured and validated,…

Read More
Leadership
Leading Change from Within: The Power of Transformational Leadership
February 7, 2026

Leadership is being tested in real time. As organizations navigate AI adoption, remote work, and constant structural change, many leaders are discovering that strategy alone isn’t enough. People are asking deeper questions about purpose, trust, and what it really means to show up for teams when uncertainty is the norm. In a world where burnout…

Read More
technology
Clarity Under Pressure: Technology, Trust, and the Future of Public Safety
February 7, 2026

When something goes wrong in a community—a major storm, a large-scale accident, a violent incident—there’s often a narrow window where clarity matters most. Leaders must make fast decisions, responders need to trust the information in front of them, and the systems supporting those choices have to work as intended. Public safety agencies now rely…

Read More