ServingNew York, New Jersey, and Connecticut
24/7 incident response1-800-868-8189Contact GDF

OT response / safety / continuity

Respond to the cyber event and protect the process

Life safety, environmental protection, and stable operation govern containment. Evidence preservation, cyber scoping, and recovery follow within the authority and limits set by the operator.

OT incident coordination model joining operator authority, process stability, containment, evidence, vendor work, and recovery validation
Operator authority, process stability, containment, evidence, and recovery proceed on coordinated tracks.

OT response combines cyber analysis with operating authority. GDF works under the plant, facility, or system owner's safety, environmental, and production rules. The response order is life safety, environmental protection, stable operation, process integrity, and then evidence collection and security testing as conditions permit. The team preserves controller, HMI, historian, engineering workstation, network, identity, remote-access, and security records while helping leaders assess credible paths to operational impact.

Operating authority stays in the room

Cyber responders do not unilaterally scan, reboot, isolate, or reconfigure control assets. Operator-designated authority approves each material action and the conditions under which it can proceed. Stop points, safe states, environmental limits, manual alternatives, rollback steps, escalation contacts, and evidence priorities are set before hands-on work begins. The operator can stop the work whenever process conditions require it.

Scope the path across IT and OT

Analysis considers remote access, domain trust, engineering laptops, removable media, vendor support, file transfer, historians, shared services, firewalls, controllers, and operator stations. Available logs are time-aligned with alarms, process data, shift notes, and configuration changes. The chronology separates cyber activity from normal process behavior and equipment faults.

  • 24/7 triage with OT-aware escalation
  • Low-impact evidence collection and log preservation
  • IT-to-OT attack-path and remote-access analysis
  • Controller project, configuration, and change comparison
  • Recovery validation and lessons-learned tracking

Readiness for the sources that disappear first

OT incident readiness planning documents clocks, log locations, retention, account ownership, network capture options, controller backups, vendor contacts, spares, safe collection methods, and offline communications. A tabletop should force real decisions and expose missing access before an outage does.

Start an OT response call

For an active event, call from a trusted channel and identify the affected process, current operating state, and designated authority.

Call 1-800-868-8189