OT response combines cyber analysis with operating authority. GDF works under the plant, facility, or system owner's safety, environmental, and production rules. The response order is life safety, environmental protection, stable operation, process integrity, and then evidence collection and security testing as conditions permit. The team preserves controller, HMI, historian, engineering workstation, network, identity, remote-access, and security records while helping leaders assess credible paths to operational impact.
Operating authority stays in the room
Cyber responders do not unilaterally scan, reboot, isolate, or reconfigure control assets. Operator-designated authority approves each material action and the conditions under which it can proceed. Stop points, safe states, environmental limits, manual alternatives, rollback steps, escalation contacts, and evidence priorities are set before hands-on work begins. The operator can stop the work whenever process conditions require it.
Scope the path across IT and OT
Analysis considers remote access, domain trust, engineering laptops, removable media, vendor support, file transfer, historians, shared services, firewalls, controllers, and operator stations. Available logs are time-aligned with alarms, process data, shift notes, and configuration changes. The chronology separates cyber activity from normal process behavior and equipment faults.
- 24/7 triage with OT-aware escalation
- Low-impact evidence collection and log preservation
- IT-to-OT attack-path and remote-access analysis
- Controller project, configuration, and change comparison
- Recovery validation and lessons-learned tracking
Readiness for the sources that disappear first
OT incident readiness planning documents clocks, log locations, retention, account ownership, network capture options, controller backups, vendor contacts, spares, safe collection methods, and offline communications. A tabletop should force real decisions and expose missing access before an outage does.