A Simple Framework for OT Ransomware Preparation, authored by Lesley Carhart and published by SANS Institute, presents a structured approach for building, testing, and refining ransomware response playbooks specifically for operational technology (OT) and industrial control system (ICS) environments. The paper focuses on the Incident Response critical control, applying the SANS PICERL lifecycle to the unique safety, architecture, and operational constraints of industrial networks.
Key findings:
- Ransomware rarely compromises lower-level process systems such as programmable logic controllers (PLCs) directly; it more often disrupts higher-level systems like HMIs, engineering workstations, and SCADA platforms that manage process visibility and control
- Modern ransomware affiliates typically purchase network access from initial access brokers, and months can pass between initial compromise and ransomware deployment
- Containment in OT environments typically requires physical or logical whole-network isolation at a firewall, router, or switch, unlike IT environments where individual hosts can be isolated remotely
- Containment decisions in OT are usually made by facility or safety managers advised by cybersecurity teams, not by cybersecurity personnel alone
- OT ransomware detection relies heavily on human reporting from operators and engineers, since endpoint detection and response (EDR) and extended detection and response (XDR) tools are rarely deployed on industrial hosts
- Tabletop exercises for OT ransomware playbooks should occur at least annually, with critical technical procedures drilled regularly in maintenance windows, labs, or digital twin environments
- Organizations generally have two paths to system recovery: using third-party decryptor tools when available, or manual restoration from tested backups
- Paying a ransom does not remove the initial access broker or ransomware affiliate from the environment, and still requires a full post-incident investigation and containment effort
- The Five ICS Cybersecurity Critical Controls framework names ICS Incident Response as one of five essential capability areas, alongside Defensible Architecture, ICS Network Visibility Monitoring, Secure Remote Access, and Risk-Based Vulnerability Analysis
- Ransomware playbooks should be kept concise for use during a crisis, with detailed tactical workflows such as metadata collection, evidence preservation, and eradication procedures placed in appendices
The framework's core argument is that OT ransomware response cannot mirror standard IT incident response. Decisions around detection, containment, and recovery must be filtered through safety and process-continuity consequences rather than conventional cybersecurity severity models, and playbooks succeed only when built collaboratively across IT, cybersecurity, and OT teams. Treating the playbook as a living document, tested through regular drills, is what turns a paper plan into real operational resilience.
This framework draws on the author's incident response experience in industrial environments and builds on two prior SANS/Dragos reference works: the Five ICS Cybersecurity Critical Controls and the Community Defense Model for ICS, applying the SANS PICERL incident response lifecycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) as its organizing structure.