Glossary · OT cybersecurity
Incident response
Also known as: Security incident response, Incident handling
German: Reaktion auf Sicherheitsvorfälle
In cybersecurity, incident response is the organized process of preparing for, detecting, analyzing, containing, eradicating and recovering from security incidents, followed by lessons learned. In OT, it must also keep people, the process and the environment safe while systems are isolated or shut down.
- OT security
In one sentence
Incident response is the organized process of detecting, analyzing, containing and recovering from security incidents, in OT with process safety in mind.
Example
When unknown traffic from an engineering station was detected, the incident response team isolated the station, moved the affected line to a safe state and preserved logs for analysis.
How it applies
- Preparation: An OT incident response plan names roles (including process and safety experts), escalation paths, decision rights for shutting down production, contacts at suppliers and authorities, and forensic procedures that do not disturb running controllers. NIST SP 800-61 describes a widely used process.
- Operation: Containment in OT differs from IT: pulling a network cable can stop a process mid-cycle. Plans should describe how to reach a safe state first.
- Recovery: Restoration follows Disaster recovery and Backup restore procedures, with verification of safety-related configurations before restart.
- Documentation: Operating manuals should describe safe manual shutdown and restart, so responders can act without the HMI. Suppliers should state in their security documentation which logs a device keeps and how to export them for analysis.
Incident response vs. emergency response
Incident response addresses a Security incident. Emergency response addresses immediate danger to people or plant. A cyberattack can trigger both; plans should define how they interact.