Response
OT incident response
IT instincts — isolate, wipe, rebuild — can be dangerous in a plant. Response here is a joint engineering and security activity where safety leads.
Safety firstOperations in command
Hour 0–1 · Establish safety and command
- Confirm the process is in a safe state; safety decisions belong to operations and engineering
- Stand up a joint bridge: plant manager, control engineer, OT security, IT security, safety
- Do not pull cables or isolate devices before understanding the process consequence
- Start a written timeline immediately, with timestamps and named decision owners
Hour 1–4 · Scope without disruption
- Collect volatile evidence from IT-side hosts; use passive capture on the OT network
- Identify affected zones, conduits and any crossing of the IT/OT boundary
- Verify integrity of the operator view against independent instrumentation
- Check controller mode, program change history and safety system status
Hour 4–12 · Contain with operations
- Choose containment jointly: disable a conduit, isolate a zone, revoke remote access, or move to manual operation
- Prefer boundary-level containment over touching controllers
- Preserve forensic images before rebuilding engineering workstations
- Communicate status on a fixed cadence to the plant and to leadership
Hour 12–24 · Stabilise and plan recovery
- Confirm backups of logic, configurations and HMI projects are valid and offline
- Plan restoration order around process dependencies, not IT convenience
- Engage vendors, regulators and national authorities where required
- Decide what enhanced monitoring stays in place through recovery
Recovery and after
- Restore from validated backups; verify logic against a known-good baseline before startup
- Run a controlled startup with engineering supervision and heightened observation
- Hold a blameless review that produces architecture and detection changes, not just documents
- Feed the case into hunt playbooks and tabletop scenarios
Why should I care?
The wrong containment action can trip a unit, damage equipment or endanger people. In OT, "do nothing yet" is sometimes the correct security decision.
Prepare before you need it
- An OT-specific plan with named roles, not an IT plan with OT appended
- Offline, tested backups of controller logic, HMI projects and network configs
- Pre-agreed containment options per zone, approved by operations in advance
- Out-of-band communications that survive a network outage
- Regular tabletop exercises with plant staff, not only with the SOC
Evidence in OT
- Passive network capture is the highest-value and lowest-risk evidence source
- Photograph HMI screens and panel states before anything is changed
- Export controller event logs and project files rather than re-imaging in place
- Record who was on site, what was connected and which removable media were used