Most OT environments either don’t have an incident response plan, or they have one that only exists as a PDF on a shared drive. On paper, it looks reassuring: roles, steps, contacts, diagrams. In a real incident, that kind of plan often turns out to be decoration.
The reality is that an OT incident doesn’t wait for you to find the right folder. It lands in the middle of shift change, or during maintenance, or when the one person who “owns” the plan is on leave.
When the plan fails its first real test
Imagine this. An engineer notices something off: alarms behaving oddly, operator stations lagging, systems behaving unusually without a clear cause. Someone says it might be cyber. That’s the moment the plan is supposed to earn its keep.
Instead, you get:
“I think there is a plan, but I’ve never seen it.”
“Is this an IT incident or an OT incident? Who’s actually in charge?”
“Do we call the vendor first, or corporate security, or the control room?”
Ten minutes are lost trying to find the latest version of the plan. Another twenty are spent arguing about whether the environment can be isolated safely. By the time everyone agrees on the first move, the window for a clean, contained response is already closing.
What makes a plan usable on a bad day
From the outside, most incident response plans look similar. The difference is whether people can use them under pressure.
The organisations that handle OT incidents best tend to have three things in common. Their OT-specific playbooks are short, written in plain language, and specific to each environment, not a generic corporate template. The key contacts – operations, engineering, vendors, cyber, safety – are current, printed, and accessible where people actually work, not buried three links deep on a portal. And they regularly run tabletop exercises that walk through realistic OT scenarios, so roles, decisions and comms channels are familiar before anything goes wrong.
In those organisations, the plan isn’t something you “go and get”. It’s something people already know how to move with, because they’ve practised it when nothing was on fire.
Thought for this week
If you had a serious OT cyber incident tomorrow, would your teams reach for a plan they’ve used before, or would the first fifteen minutes be spent asking where the plan is and who is supposed to go first?
Have a good week,
Damien Pope
News by Others – What caught our eye this week
1. Vulnerability – AVEVA Pipeline Simulation
AVEVA Pipeline Simulation has a critical flaw that lets attackers without passwords take admin-level control of… Read more →
2. Vulnerability – New Linux ‘Copy Fail’ Vulnerability Enables Root Access on Major Distributions
A serious flaw in Linux kernel code has been discovered that lets anyone with basic system access take full control of… Read more →
Need help securing your OT environment? IEC 62443 • Essential Eight • Gap analysis • Network segmentation • OT incident response and more – Talk to us