Group Purchasing
Group Purchasing

A Simple Framework for OT Ransomware Preparation

A Simple Framework for OT Ransomware Preparation (PDF, 3.45MB)Published: 15 Apr, 2025
Created by:
Lesley Carhart
Lesley Carhart

A Simple Framework for OT Ransomware Preparation, authored by Lesley Carhart and published by SANS Institute, presents a structured approach for building, testing, and refining ransomware response playbooks specifically for operational technology (OT) and industrial control system (ICS) environments. The paper focuses on the Incident Response critical control, applying the SANS PICERL lifecycle to the unique safety, architecture, and operational constraints of industrial networks.

Key findings:

  • Ransomware rarely compromises lower-level process systems such as programmable logic controllers (PLCs) directly; it more often disrupts higher-level systems like HMIs, engineering workstations, and SCADA platforms that manage process visibility and control
  • Modern ransomware affiliates typically purchase network access from initial access brokers, and months can pass between initial compromise and ransomware deployment
  • Containment in OT environments typically requires physical or logical whole-network isolation at a firewall, router, or switch, unlike IT environments where individual hosts can be isolated remotely
  • Containment decisions in OT are usually made by facility or safety managers advised by cybersecurity teams, not by cybersecurity personnel alone
  • OT ransomware detection relies heavily on human reporting from operators and engineers, since endpoint detection and response (EDR) and extended detection and response (XDR) tools are rarely deployed on industrial hosts
  • Tabletop exercises for OT ransomware playbooks should occur at least annually, with critical technical procedures drilled regularly in maintenance windows, labs, or digital twin environments
  • Organizations generally have two paths to system recovery: using third-party decryptor tools when available, or manual restoration from tested backups
  • Paying a ransom does not remove the initial access broker or ransomware affiliate from the environment, and still requires a full post-incident investigation and containment effort
  • The Five ICS Cybersecurity Critical Controls framework names ICS Incident Response as one of five essential capability areas, alongside Defensible Architecture, ICS Network Visibility Monitoring, Secure Remote Access, and Risk-Based Vulnerability Analysis
  • Ransomware playbooks should be kept concise for use during a crisis, with detailed tactical workflows such as metadata collection, evidence preservation, and eradication procedures placed in appendices

The framework's core argument is that OT ransomware response cannot mirror standard IT incident response. Decisions around detection, containment, and recovery must be filtered through safety and process-continuity consequences rather than conventional cybersecurity severity models, and playbooks succeed only when built collaboratively across IT, cybersecurity, and OT teams. Treating the playbook as a living document, tested through regular drills, is what turns a paper plan into real operational resilience. This framework draws on the author's incident response experience in industrial environments and builds on two prior SANS/Dragos reference works: the Five ICS Cybersecurity Critical Controls and the Community Defense Model for ICS, applying the SANS PICERL incident response lifecycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) as its organizing structure.

FAQ

Meet Your Author

Lesley Carhart
Lesley Carhart

Lesley Carhart

Certified Instructor Candidate

Lesley is Technical Director of Industrial Incident Response for North America for Dragos and teaches SANS Industrial Control System courses. She's a recognized leader in cybersecurity and has won a number of prestigious awards in the field.

Read more about Lesley Carhart