You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 1800-41 (Initial Public Draft) Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: May 21, 2026 Comments Due: July 8, 2026 (public comment period is CLOSED) Email Questions to: [email protected] Author(s) Michael Powell (NIST) , Michael Pease (NIST) , Keith Stouffer (NIST) , Toby Maysey (MITRE) , Chris Peloquin (MITRE) , Bob Stea (MITRE) , Kangmin Zheng (MITRE) , Geoff Sweet (AWS) , Brian Butler (Cisco) , Josh Carlson (Dragos) , Chris Manrique (Dragos) , Chris Bihary (Garland Technology) , Jason Drewniak (Garland Technology) , Nathan Boeger (Inductive Automation) , Brad Fischer (Inductive Automation) , Kim Gajewski (Google Cloud) , Sri Goutisetti (Google Cloud) , Chris Sistrunk (Google Cloud) , Stephen Petruzzo (GreenTec-USA) , Billy John Stewart (GreenTec-USA) , Ahmik Hindman (Rockwell Automation) , John Crawford (Siemens AG) , Allen Cantrell (Siemens AG) , Dallas Levine (Siemens AG) , Ray Erlinger (TDi Technologies) , Bill Johnson (TDi Technologies) , Pam Johnson (TDi Technologies) , Clyde Poole (TDi Technologies) , Chris Jensen (Tenable) , Joshua Moll (Tenable) Announcement The NIST National Cybersecurity Center of Excellence (NCCoE) has released this initial public draft NIST Cybersecurity Practice Guide, which provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience. The comment period for this publication is open through July 8, 2026. Background As Operational Technology (OT) systems like ICS become increasingly interconnected with IT networks, they are increasingly being targeted by cyber threats, putting factory operations, safety, and property at risk. Organizations operating these systems, such as those in the manufacturing sector, need to have plans and capabilities in place to respond to cyber incidents and restore operations to improve overall resilience. The NCCoE worked with 11 industry collaborators to develop reference architectures, describe response and recovery scenarios, and demonstrate relevant approaches and capabilities. This draft publication provides actionable guidelines on responding to and recovering from cyber attacks in manufacturing environments. Discover how to: Understand the risks and potential impact of cyber incidents on your operations Develop a comprehensive response and recovery plan Implement best practices to minimize downtime and restore operations quickly Comment Now! We encourage you to review the publication and share your feedback by July 8, 2026. If you’re interested in staying up-to-date on this project, you can join the NCCoE Manufacturing Community of Interest by signing up on our project page . Abstract Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing number of cyber incidents, posing a real threat to safety and production, and impacting the economic performance of manufacturing organizations. Though defense-in-depth security architecture helps mitigate cyber risks, it cannot eliminate all cyber risks; therefore, manufacturing organizations should also have a plan to recover and restore operations should a cyber incident impact operations. This practice guide showcases various cyber attack scenarios developed with industry collaborators to produce a methodology that enables the adoption and implementation of response and recovery measures in manufacturing environments to strengthen operational resilience. Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing... See full abstract Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing number of cyber incidents, posing a real threat to safety and production, and impacting the economic performance of manufacturing organizations. Though defense-in-depth security architecture helps mitigate cyber risks, it cannot eliminate all cyber risks; therefore, manufacturing organizations should also have a plan to recover and restore operations should a cyber incident impact operations. This practice guide showcases various cyber attack scenarios developed with industry collaborators to produce a methodology that enables the adoption and implementation of response and recovery measures in manufacturing environments to strengthen operational resilience. Hide full abstract Keywords cybersecurity ; incident investigation ; incident response ; industrial control systems ; manufacturing ; operational technology ; recovery ; response ; restoration Control Families None selected Documentation Publication: Download URL Supplemental Material: Submit comments Project homepage Related NIST Publications: Project Description Document History: 05/21/26: SP 1800-41 (Draft) Topics Security and Privacy incident response Applications operational technology Sectors manufacturing HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov