OT & plant floor

OT and IT incident response are not the same discipline

Law & Forensics Editorial
Editorial illustration for the article "OT and IT incident response are not the same discipline".

Operational technology incident response is a different discipline from IT incident response, and treating the two as interchangeable can convert a contained cyber event into a physical safety incident. The containment moves that IT teams practice, isolating hosts, pulling network cables, killing processes, and reimaging machines, are tolerable in environments built on general-purpose operating systems. On a plant floor, the same actions applied to a human-machine interface, a programmable logic controller, or a protection relay can halt production, damage equipment, or create unsafe operating conditions. SANS instructor Dean Parsons frames the distinction plainly: ICS/OT response must be engineering-led and safety-first, not a reuse of IT recovery playbooks.

Why is OT incident response different from IT incident response?

IT incident response is optimized around confidentiality, data protection, and rapid isolation of compromised systems. Dean Parsons of SANS notes that this approach works well for IT and should not change there. In OT the priority order inverts. Safety and operational integrity come first, followed closely by reliability. Availability and physical safety, not data confidentiality, define success.

The reason is structural. Many industrial control systems do not run traditional operating systems, cannot be rapidly rebuilt with standard IT processes, and cannot be taken offline without affecting safety, reliability, and physical processes. SANS describes the result as a dangerous gap: applying IT-centric actions such as aggressive containment, indiscriminate isolation, or automated shutdowns in an OT environment risks turning a cyber event into a self-inflicted control system outage. The scale of exposure is not hypothetical. The 2025 SANS State of ICS/OT Security Survey found that more than one in five organizations reported an ICS/OT cyber incident in the past year, with many causing operational disruption and extended recovery timelines. That survey also found that while detection and containment times have improved in some sectors, remediation and safe recovery remain persistent challenges.

Why can IT containment steps be dangerous on the plant floor?

The core hazard is that a defensive action carries physical consequences in OT that it does not carry in IT. Taking an HMI, PLC, or protection relay offline, isolating a production line segment, or terminating access at the wrong moment may reduce cyber risk while introducing immediate physical risk, disrupting critical services, or creating unsafe process conditions. A protection relay dropped at the wrong time removes a safety function; an isolated line segment can strand a process mid-cycle.

Containment in ICS/OT therefore does not always mean shutdown. SANS makes this the central distinction of industrial response: when a threat is understood, constrained, and not actively affecting the physical process, maintaining controlled operations while containing the threat may be safer than aggressive isolation or shutdown. That judgment depends on real-time situational awareness and close coordination between security responders and the engineers who run the process. It cannot be automated on the assumption that faster isolation is always safer, and it cannot be made by a responder who lacks the operational context to know what a given asset controls.

The convergence of IT and OT compounds the problem. The Cloud Range analysis by Dave Neuman of TAG Infosphere describes integrating IT and OT systems as a primary challenge, because changes to IT can directly affect OT. Industrial Cyber makes the same point, that IT/OT integration improves data sharing and efficiency while broadening the attack surface and leaving OT environments more exposed. Ensuring that IT security measures do not disrupt OT operations is the specific tradeoff a converged response has to manage.

IT versus OT response priorities

The following comparison summarizes how the two disciplines diverge, drawing on the SANS and Cloud Range descriptions.

Dimension IT incident response OT/ICS incident response
Top priority Confidentiality, data protection Safety and operational integrity, then reliability
Typical containment Isolate hosts, pull cables, kill processes Contain without shutdown where the process is unaffected
Recovery Reimage and rebuild systems Many systems cannot be rapidly rebuilt or taken offline
Guiding expertise Security operations Engineering and process awareness
Consequence of error Data loss, downtime Physical risk, unsafe process conditions, equipment damage

The right column is not a stricter version of the left. It is a different objective function, which is why SANS characterizes traditional IT controls as sometimes causing more harm than good when applied directly to industrial environments.

What does an OT-aware incident response plan require?

An effective ICS/OT plan is built around engineering context, process awareness, and operational continuity rather than IT recovery steps. The Cloud Range framework organizes the plan around preparation, identification, containment, eradication, recovery, and lessons learned, adapted to the constraints of legacy systems and critical infrastructure. Two structural elements recur across the sources.

The first is a cross-functional team. Cloud Range calls for a response team that combines expertise in IT, OT, and the specific industrial processes at issue, because detecting and analyzing an incident requires people who understand both the cyber intrusion and what the affected equipment does. Industrial Cyber reinforces that the human element remains decisive, since interpreting data and executing response plans depends on qualified staff, and human error can itself introduce danger. A recognized shortage of professionals who combine cybersecurity, ICS technology, and process knowledge is part of what makes OT response difficult, per the Cloud Range analysis.

The second is a persistent skills gap around specialized tooling. Cloud Range observes that generic IT security solutions may be less effective in OT and that tools designed for these environments are needed. Industrial Cyber adds that emerging automation, machine learning, and AI can speed threat identification and automatic containment, but their reliability has to be judged carefully to confirm they support continuous operational flow in sensitive conditions rather than triggering the automated shutdowns SANS warns against.

How should tabletop exercises reflect the difference?

Exercises are where the divergence between IT and OT response gets tested before an incident forces the question. Both Cloud Range and Industrial Cyber treat regular training and simulation as core preparation. Cloud Range describes attack simulations on cyber ranges as a way to let a cross-functional team practice response strategies in a controlled environment, and Industrial Cyber recommends running simulations to build a cybersecurity-aware culture and raise team performance. For OT, the value of a realistic exercise is that it surfaces the specific decision that distinguishes the discipline: whether isolating a segment or dropping a relay reduces net risk once physical consequences are counted.

An exercise that imports an IT playbook without adaptation trains the wrong reflex. A scenario worth running puts the containment-versus-continuity tradeoff in front of both security responders and process engineers, forces them to coordinate under time pressure, and tests whether the team can distinguish a threat that is constrained and safe to monitor from one that demands intervention. The general lesson across the sources is consistent. Organizations that respond to an OT incident with IT assumptions risk operational disruption or a safety event, and the place to discover that gap is a simulation rather than a live control system outage.

Written by

Law & Forensics Editorial

Editorial team, Law & Forensics

The editorial team at Law & Forensics, the firm behind Tabletop.ai.

Get started

Make cyber readiness a board-visible program.

Pick a plan and run your first drill this week. One subscription covers your whole organization and every business unit under it.