Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Incident response

Also known as: Security incident response, Incident handling

German: Reaktion auf Sicherheitsvorfälle

In cybersecurity, incident response is the organized process of preparing for, detecting, analyzing, containing, eradicating and recovering from security incidents, followed by lessons learned. In OT, it must also keep people, the process and the environment safe while systems are isolated or shut down.

  • OT security

In one sentence

Incident response is the organized process of detecting, analyzing, containing and recovering from security incidents, in OT with process safety in mind.

Example

When unknown traffic from an engineering station was detected, the incident response team isolated the station, moved the affected line to a safe state and preserved logs for analysis.

How it applies

  • Preparation: An OT incident response plan names roles (including process and safety experts), escalation paths, decision rights for shutting down production, contacts at suppliers and authorities, and forensic procedures that do not disturb running controllers. NIST SP 800-61 describes a widely used process.
  • Operation: Containment in OT differs from IT: pulling a network cable can stop a process mid-cycle. Plans should describe how to reach a safe state first.
  • Recovery: Restoration follows Disaster recovery and Backup restore procedures, with verification of safety-related configurations before restart.
  • Documentation: Operating manuals should describe safe manual shutdown and restart, so responders can act without the HMI. Suppliers should state in their security documentation which logs a device keeps and how to export them for analysis.

Incident response vs. emergency response

Incident response addresses a Security incident. Emergency response addresses immediate danger to people or plant. A cyberattack can trigger both; plans should define how they interact.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on NIST SP 800-61 and IEC 62443-2-1

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!