Talk With an Expert

Industrial Control System / OT Incident Response

Industrial Control System / OT Incident Response (PDF, 0.67MB)Published: 19 May, 2025
Created by:
SANS Institute
SANS Institute

ICS / OT Incident Response: A Guide to Industrial Cyber Resilience

This free SANS poster provides practical guidance for building and executing OT incident response plans in industrial environments. It outlines how to adapt traditional cybersecurity practices for Operational Technology (OT) systems, focusing on the unique needs of industrial control systems (ICS), critical infrastructure, and safety-critical operations.

What You’ll Learn:

  • Key differences between IT and OT incident response, including system architecture, safety priorities, and legacy constraints.
  • Essential components of OT cyber incident response, from asset inventory and network monitoring to triage, containment, and recovery.
  • How to establish a Safe Cyber Position, a tested configuration that prioritizes safety while enabling containment and threat eradication.
  • Roles and responsibilities in OT IR, including coordination with engineering, safety, and physical security teams.
  • Real-world tabletop exercises and jump bag checklists, designed to improve readiness for ransomware, unauthorized access, or physical-cyber attacks.
  • Steps to build a converged IT/OT incident response plan, incorporating threat intelligence, forensics, and regulatory compliance (e.g., CIRCIA 72-hour reporting).

Meet Your Author

SANS Institute
SANS Institute

SANS Institute

Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cybersecurity professionals with the practical skills and knowledge they need to make our world a safer place.

Read more about SANS Institute