Zero Trust for OT: Data-at-Rest Security Lessons from the Air Force’s Shift to Contested Base Operations

Kelvin Quezada
May 5, 2026
7 minute read

The Shift to Contested Environments is Redefining OT Cybersecurity

The Department of War is accelerating its Zero Trust adoption as the threat landscape evolves, and nowhere is this shift more evident than in the U.S. Air Force’s focus on treating military installations as frontline targets in contested environments.

As detailed in recent reporting, military installations are no longer viewed as inherently secure environments, but as contested environments where adversaries can disrupt operations through cyber attacks on infrastructure and operational technology (OT). Additional analysis highlights how this shift is driving expanded Zero Trust implementation across Air Force systems, including operational technology environments.

For defense organizations, this shift has significant implications for how Zero Trust is implemented across OT and industrial control systems. Traditional perimeter-based security models are insufficient in environments where adversaries may already have network access or physical proximity to critical systems.

As emphasized in Department of the Air Force Zero Trust guidance, security must move toward a data-centric model where access is explicitly verified and no implicit trust is granted based on location, network, or system state.

Why Zero Trust for OT Must Include Data-at-Rest Protection

In modern OT environments, mission-critical data is distributed across devices such as PLCs, SCADA systems, edge compute nodes, ruggedized endpoints, and embedded controllers. These systems store operational configurations, telemetry, mission logs, and control data required for continuous mission execution.

According to DoW CIO guidance, Zero Trust principles must apply uniformly across both IT and OT environments to ensure consistent enforcement of identity, device, and data protections. Without protecting data at rest, organizations risk exposing sensitive information even when network defenses and access controls are in place.

The Department of the Air Force reinforces that data is a primary security boundary, requiring protection wherever it resides, not just while it is in transit or under active use. In OT environments, this means Zero Trust must extend to stored data on endpoints operating outside traditional secure infrastructure.

The Critical Gap: What Happens After a Compromise?

Zero Trust assumes that compromise is possible through credential theft, insider activity, or physical access to systems. Once an attacker gains access to a device, traditional controls such as network segmentation and perimeter defenses provide limited protection against data exposure.

This is where data-at-rest protection becomes essential and why the Department of Defense is actively addressing these gaps. Without independently implemented protections for stored data, attackers with physical or logical access can extract sensitive information, modify configurations, or erase logs in offline environments.

Policy guidance such as DoD Directive-Type Memorandum 25-003 reinforces the need for layered defenses that assume compromise and are designed to limit adversary impact across mission systems.

In OT environments, where systems are distributed, intermittently connected, and often physically exposed, this capability is foundational to maintaining operational integrity.

CSfC Data-at-Rest: A Proven Model for Zero Trust OT Security

The NSA’s Commercial Solutions for Classified (CSfC) program provides a validated framework for protecting data at rest in high-risk environments.

The CSfC Data-at-Rest Capability Package defines an architecture requiring two independently implemented protections that secure stored information when a device is powered off or not authenticated.

This model ensures that sensitive data remains protected even if one protection mechanism is compromised. It is widely used across national security systems to safeguard classified information in environments where physical access is a realistic and persistent threat.

For defense organizations, this aligns directly with Zero Trust principles:

Applying CSfC Principles to OT and ICS Environments

Dual-Layer Protection for OT Systems

OT environments often operate in distributed, disconnected, and physically exposed conditions. CSfC-aligned architectures address this by requiring independent protections for data at rest.

In practice, this includes:

This separation ensures that no single control failure exposes mission data and supports resilience in contested environments.

Pre-Boot Authentication for Physical Access Risk (Outer Layer)

Pre-boot authentication is critical for OT systems deployed in remote, unattended, or physically accessible environments. It ensures that possession of a device does not equate to access to its data.

By enforcing authentication before the operating system loads, PBA establishes the outer layer of protection and ensures encrypted storage remains inaccessible without valid credentials, even in loss or capture scenarios.

Software Full Drive Encryption Authentication (Inner Layer)

Software Full Drive Encryption (SWFDE) provides the independent inner protection layer required for CSfC-aligned architectures. Like the outer layer, it enforces authentication prior to granting access to encrypted data within the operating system environment.

This inner authentication step ensures that even if outer-layer protections are bypassed or compromised, access to classified or sensitive mission data still requires successful user verification. SWFDE therefore extends Zero Trust principles deeper into the system by enforcing identity validation at the data layer itself.

Key Risks to OT Data at Rest in Defense Environments

Best Practices for Zero Trust Data at Rest in OT

Why Data-at-Rest Security Is Foundational to Zero Trust OT

Zero Trust for OT must extend to stored data. Identity and network controls are necessary, but they are not sufficient to prevent data exposure once a system is accessed or physically compromised.

Protecting data at rest ensures that sensitive information remains cryptographically protected even under adverse conditions. This aligns with core Zero Trust principles of explicit verification, continuous validation, and elimination of implicit trust based on location or device state.

Advancing Zero Trust with Full-Stack Data-at-Rest Protection

As defense organizations modernize cybersecurity strategies, OT security requires a full-stack approach that integrates:

In contested environments where bases and infrastructure are treated as frontline targets, protecting data at rest is essential to mission resilience and operational continuity.

By extending Zero Trust to include stored data protection, Department of War organizations can build architectures that are more resilient, more complete, and aligned to the realities of modern operational warfare.

 

Kelvin Quezada

Kelvin Quezada is a Product Marketing Manager at Cigent, where he leads strategy, positioning, and go-to-market efforts for the company’s Data-at-Rest protection solutions. With more than a decade of experience across cybersecurity deployments, product marketing, and technical enablement, he translates complex technical concepts into clear, mission-focused value for defense programs.

More from Cigent