Skip to content
IACS RadarIndustrial Cyber Exposure & Intelligence
Back to blog

Incident Response

Practising incident response in an OT environment: where to start

Applying an IT incident response plan one-to-one to OT does not work. Practical points to get started.

Admin·20 May 2026· 6 min
#incident response#exercises#OT

Many organisations have a well-developed IT incident response plan, but no equivalent for OT — or worse, the same plan is assumed to apply to OT without adaptation. That does not work, for a number of fundamental reasons.

Why OT incident response is different

In IT, "isolate and restore from backup" is often the first reflex. In OT, abruptly isolating a system can have direct operational consequences: a station controller that is disconnected can disrupt the local control of a substation. Incident response in OT therefore requires close coordination with operational staff, not only with IT security.

Where to start

  1. Map critical functions, not just systems. What must never become unavailable, and what can be missed temporarily?
  2. Define who decides. In an OT incident, both a security officer and an operational manager are often needed to take an isolation decision — record in advance who they are and how quickly they can be reached.
  3. Practise with a realistic scenario. A tabletop exercise around, for example, unusual GOOSE messages in a substation yields different insights than a generic ransomware scenario from an IT exercise.
  4. Involve vendors and integrators beforehand, not only during an incident. Know who to contact for forensic investigation or recovery of specialised equipment.
  5. Document recovery procedures per critical system, including who is authorised to put a system back into operation after an incident.

What is often underestimated

Detection in OT works differently from IT: many environments have limited logging at device level, which means network-based monitoring is often the first and sometimes the only source of signals. Investing in OT-aware monitoring is therefore not only a preventive measure but also a response measure: without visibility, response is hardly possible.

Starting is better than waiting for the perfect plan

A first, simple tabletop exercise with the most important operational and security stakeholders often already yields valuable insights into where coordination is lacking. Waiting until a fully worked-out plan exists often means that no practising happens at all.

About the author

Admin

IACS Radar editorial team

Editorial account of IACS Radar.