Federal agencies must remove end-of-support edge devices, but the same lifecycle risks are quietly growing across industrial and OT networks.

CISA directive insights
- CISA’s Binding Operational Directive 26-02 makes clear that unsupported edge devices are no longer a routine IT maintenance issue, but a legally recognized, high-risk cybersecurity exposure actively exploited by threat actors.
- Industrial and OT operators face the same lifecycle problem as federal agencies, since long-lived edge infrastructure often remains in service well past vendor support and can become an entry point into physical operations.
- Because replacing legacy edge devices isn’t always feasible, organizations must prioritize compensating controls like segmentation, monitoring and resilience strategies to reduce exploitability and operational risk.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a new Binding Operational Directive requiring federal civilian agencies to inventory, remove and replace unsupported edge devices. This highlights a growing cybersecurity risk that extends well beyond government networks and into industrial operations.
The directive, Binding Operational Directive (BOD) 26-02, titled Mitigating Risk From End-of-Support Edge Devices, targets internet-facing infrastructure such as firewalls, routers, VPN gateways, load balancers and similar edge devices that no longer receive vendor security updates. CISA cited growing evidence that threat actors are actively exploiting unsupported edge devices as initial access points.
Importantly, CISA’s directive is a Binding Operational Directive, which under U.S. law is a compulsory cybersecurity mandate for federal civilian agencies. In BOD 26-02, CISA defines end of support (EOS) devices as hardware, firmware or software that no longer receive timely vendor-supported updates, including security patches and bug fixes. The directive also casts a wide net over what constitutes an edge device, explicitly including network equipment located at the boundary of agency networks, such as firewalls, routers, switches, wireless access points, network security appliances and Internet of Things (IoT) edge devices.
CISA’s stated risk rationale is that unsupported edge devices are attractive targets for advanced threat actors because they are exposed at the network perimeter, no longer receive security updates and can be exploited to pivot into internal environments. These vulnerabilities, CISA says, represent a “substantial and constant” threat to federal information systems.
While BOD 26-02 applies specifically to Federal Civilian Executive Branch (FCEB) agencies, it sends a clear signal to critical infrastructure operators and industrial organizations facing similar lifecycle challenges.
“CISA’s directive underscores a growing reality in operational technology: Unsupported edge devices are not just an IT lifecycle issue — they represent a direct risk to physical operations,” said Joe Saunders, CEO of RunSafe Security. “If breached, an attacker would then have access to OT environments, which often depend on legacy systems that were never designed with modern security in mind, yet they continue to control critical processes across infrastructure and industry.”
What does the new CISA directive require?
Under the directive, agencies must establish visibility into unsupported edge infrastructure and take action to mitigate risk. CISA is requiring agencies to inventory and report end-of-support edge devices and ensure they are removed and replaced within defined deadlines.
The directive also calls for improved lifecycle management so that end-of-support systems do not remain in production environments indefinitely. Although timelines vary depending on device status, unsupported edge systems represent a high-risk exposure and should not remain connected to agency networks.
Why unsupported edge devices are a growing target
Edge devices have increasingly become a preferred target for attackers because they sit at the boundary between internal networks and the internet. Many provide remote access capabilities and often have broad privileges once compromised.
Unlike traditional endpoints, these devices may not have strong monitoring, security tooling or patching discipline. Once a vulnerability is exploited, attackers can gain a foothold that bypasses perimeter defenses and enables lateral movement into internal environments.
“When those devices reach end-of-support, organizations are left running technology that is unmanaged, unmonitored and frequently unpatched, creating ideal entry points for attackers,” Saunders said.
CISA’s directive reflects a broader shift in adversary tactics. Rather than focusing exclusively on user devices or servers, threat actors are increasingly targeting network appliances to gain entry, establish persistence and move deeper into networks.
OT and industrial networks face the same lifecycle problem
While federal agencies may have a mandate to replace unsupported edge infrastructure, industrial organizations often face a more complicated reality. OT environments are built for stability and long lifecycles, and many plants operate systems for 10 to 20 years. In many cases, devices remain in use well beyond their intended support window because replacement may require downtime, recertification, redesign or significant capital investment. Also, they continue to get the job done. The result is a persistent exposure window, especially as industrial networks become more connected.
“As OT networks become more interconnected, the attack surface expands, increasing the likelihood that a compromised device could disrupt essential services or cause real-world harm,” Saunders said.
In manufacturing, energy, water, transportation and other critical sectors, edge devices often serve as gateways between enterprise IT and plant-floor systems. If compromised, they can become a bridge into environments controlling physical processes. This elevates the risk from a traditional IT concern into an operational one.
Replacement isn’t always feasible but risk must still be managed
The directive emphasizes removal and replacement, but industrial operators often cannot replace legacy edge infrastructure quickly. For OT security leaders, the challenge is implementing compensating controls that reduce exploitability while modernization plans move forward.
These may include network segmentation, access control restrictions, continuous monitoring, secure configuration baselines and other hardening measures designed to limit an attacker’s ability to pivot deeper into OT environments.
“Security leaders must assume these legacy systems will persist and prioritize protections that reduce exploitability and strengthen resilience, rather than relying solely on replacement timelines,” Saunders said.
A warning sign for the private sector
Although the directive is binding only for federal agencies, it may influence private-sector cybersecurity investment and expectations, particularly in regulated industries and critical infrastructure sectors where federal guidance often shapes best practices.
For industrial operators, BOD 26-02 reinforces the message that unsupported edge devices are no longer a maintenance issue to be addressed “when convenient.” They are high-value targets with high-impact vulnerabilities.
As cyberattacks continue shifting toward infrastructure devices as initial access points, industrial organizations may need to accelerate lifecycle planning, improve asset visibility and strengthen security controls around edge infrastructure that connects critical operations to the outside world.
LEARNING OBJECTIVES
- Explain what CISA’s Binding Operational Directive 26-02 requires and why unsupported edge devices are considered a high-priority federal cybersecurity risk.
- Identify how end-of-support edge devices create unique vulnerabilities for industrial and OT environments, including the potential impact on physical operations.
- Describe practical security strategies industrial organizations can implement to reduce risk when replacing legacy edge infrastructure is not immediately feasible.
CONSIDER THIS
Do we have a complete inventory of our internet-facing edge devices and a clear plan to secure or replace any that are already end-of-support?