Cyber-physical systems can incorporate modern technological mechanisms to harden the security of their information technology (IT) elements. However, the operational technology (OT) elements at the edge are not directly addressed by IT solutions. In this talk, we visit the core problem of adding verification of trust to existing cyber-physical systems via vetting-based verification of standards and via dynamic, passive, runtime monitoring of sensor streams to identify, characterize and monitor elements beyond the conventional IT surfaces. We illustrate how recent advances including digital twins, natural language processing and machine learning are directly useful in advancing this trust-but-verify approach to security and resilience of cyber-physical systems.