Table of Contents
ToggleWhen ransomware hits the office, the fix is often to isolate and rebuild, but pulling cables in a control room can stop a plant or create a hazard. Control system incidents need a plan that keeps the process safe while the attack is contained.
Cyber attacks on industrial systems can disrupt production, damage equipment and threaten safety. A tested plan tells engineers, operators and security staff exactly who does what when something looks wrong.

What Is ICS Incident Response?
ICS incident response is the planned set of actions an organisation takes to detect, contain, remove and recover from cyber incidents affecting industrial control systems, while keeping people, equipment and the environment safe. It addresses the threats described in types of cyber attacks, but with safety as the first priority.
Cloud Range lists six phases for an OT response: preparation, identification, containment, eradication, recovery and lessons learned. It stresses a cross functional team with IT, OT and process expertise.

The UK NCSC and ICS COI guidance adds that plans must consider manual operation, safety systems and vendor support. An IT playbook alone is not enough.
The plan must respect the independence of safety systems, explained in SIS and BPCS differences.
The 6 Vital Phases
Preparation is where most of the value lies. Offline backups of PLC logic, HMI projects and server images decide how fast recovery can happen.
Store logic backups offline and verify them regularly, using the upload and compare features described in PLC online and offline programming.
IT vs OT Response Priorities
| Aspect | IT Response | OT Response |
|---|---|---|
| First priority | Protect data | Protect people and process |
| Isolation | Disconnect quickly | Coordinate with operations first |
| Evidence | Disk images | Also controller logic and historian data |
| Recovery | Rebuild servers | Verify logic, set points and calibrations |
| Team | Security staff | Security, control engineers, operators, vendors |
Historian trends and sequence of events records help show what the attacker changed and when. Preserve them early.
Operators may need to run the plant manually or shut it down in a controlled way. Those procedures belong in the plan, not in improvisation.
How a Response Unfolds
Planned isolation points follow the zones in the Purdue model. Cutting the IT to OT link is usually the first containment step.
Segmentation designs such as air gapped vs segmented networks make containment far easier.
Team Roles
Cloud Range recommends regular training with attack simulations on cyber ranges. Tabletop exercises twice a year keep contact lists and decisions fresh.
Agree in advance who has the authority to shut down a unit because of a cyber event. That single decision often causes the longest delay during a real incident.
Downtime Cost Estimate
Example:
Detection 6 h, containment 10 h, recovery 32 h = 48 h
Lost production 25000 per hour
Response and forensics 150000
Total ≈ 48 × 25000 + 150000 = 1350000
Cutting recovery time through tested backups usually gives the biggest saving. Use this figure to justify preparation spending.
Downtime Cost Calculator
Run the numbers with recovery halved to show the value of offline backups and practised procedures.
- Written, tested OT playbooks.
- Offline backups of logic and images.
- Planned isolation points.
- Regular tabletop exercises.
- IT only plans.
- No verified backups.
- Unclear authority to shut down.
- Vendor contacts out of date.
Train responders with resources such as free OT cybersecurity training and include operators in every exercise.
NCSC ICS Incident Response Guidance PDF
SANS OT Incident Response Video
ICS Incident Response FAQ
Related Articles
- Types of Cyber Attacks
- Purdue Model ICS Cybersecurity
- SCADA Security Checklist
- Air Gapped vs Segmented Networks
- IEC 62443 Zones and Conduits
External References
- Response Planning Within ICS and OT, NCSC ICS COI
- Creating an OT Response Plan, Cloud Range
- Security Incident Management, Wikipedia
What We Learn Today
- ICS incident response puts people and process safety first.
- Preparation with offline backups and clear roles decides recovery speed.
- Test the plan regularly with operators and vendors.
