Shared Attack Paths
Two ATT&CK Matrices, One Attack Path
Most detection programs map only to MITRE ATT&CK for Enterprise and miss the IT-to-OT pivot. Industrial defense needs both matrices and the path between them.
Two ATT&CK Matrices, One Attack Path
A ransomware responder finds an encrypted Windows server, documents it as an IT incident, and moves on. What the report never captures is that the server was an engineering workstation running SCADA software, the machine that programs the controllers on the plant floor. The attack had reached the edge of the physical process, and the paperwork filed it under laptops and email.
That gap is not a documentation quirk. It is how most detection programs are built. They map their detections to MITRE ATT&CK for Enterprise, the framework for IT attacks, and treat operational technology as a separate monitoring problem. The move between the two, the pivot from IT into OT, becomes a footnote. That pivot is the attack. Dragos, in its 2026 Year in Review, reports that OT incidents are routinely mischaracterized as IT-only for exactly this reason. Industrial environments need both ATT&CK matrices, and the path between them is the most important thing to detect.
One Path, Two Matrices
MITRE maintains two ATT&CK matrices, and the split is deliberate. ATT&CK for Enterprise, as of its October 2025 release, catalogs 222 techniques across 15 tactics. ATT&CK for ICS catalogs 79 techniques across 12 tactics.
The two describe different halves of the same intrusion. Enterprise is how attackers travel. ICS is what they do when they arrive. A detection program mapped to only one sees half the attack in industrial environments where the attacks that matter cross both layers. Mapped together, the matrices provide end-to-end coverage from initial access to controller-level consequence.
The IT-to-OT Pivot Is the Whole Game
Industrial attacks rarely begin on the factory floor. A synthesis of Dragos, Sophos, and CISA reporting points to roughly three-quarters of OT attacks starting as an IT breach, a consequence of how tightly connected the two environments are.
When Colonial Pipeline was hit by ransomware in May 2021, the compromise sat in IT business systems, yet the operator shut down the pipeline itself as a precaution. An intrusion that never reached a controller still produced an operational outcome because the company could not confirm where IT impact ended and OT risk began.
US advisories on Volt Typhoon show the path in sequence: exploit public-facing infrastructure, steal domain controller data, crack credentials offline, abuse jump hosts, and move toward engineering workstations that can program Level 1 controllers. Read that chain against ATT&CK and the pattern is clear. Most steps map to Enterprise techniques before the final operational effect maps to ICS.
Why the Boundary Stays Invisible
The pivot often goes undetected because engineering workstations and HMIs run Windows. Responders log a familiar host as an IT incident and miss the OT role of the system. Dragos describes this mislabeling as a persistent industry problem.
Valid credentials are the connective tissue. A stolen account that looks routine on the IT side becomes OT access on the other side. Through 2025, Dragos also observed attackers using compromised remote access and valid credentials to reach VMware ESXi layers hosting SCADA, HMI, historian, and engineering workloads.
The blind spot is measured in dwell time. Dragos reports average ransomware dwell time in OT environments at 42 days. For organizations with comprehensive OT visibility, the average falls to 5 days.
Make the Pivot a First-Class Detection Target
If the pivot is the attack, it needs dedicated detections, not leftovers from separate programs. In practice that means detections for domain-controller credential theft, jump-host misuse, remote access behavior toward control networks, engineering-workstation anomalies, and access to virtualization hosts running OT workloads.
Many teams still treat operational technology as a separate monitoring problem, which leaves boundary detections unowned. A unified coverage map should show both Enterprise and ICS techniques and expose where the path between them is not covered.
That is why a coverage review can show where Enterprise techniques and ICS techniques are covered, and where the seam is open. NERC CIP-015 now requires Internal Network Security Monitoring, east-west visibility precisely where movement toward OT first appears.
How PhishCloud Approaches It
We baseline every detection engagement against both ATT&CK matrices, Enterprise and ICS, and treat IT-to-OT pivot detection as a primary target. We build and tune detections for credential abuse, jump-host misuse, remote access anomalies, engineering-workstation activity, and OT-hosting hypervisors.
If your detections map to one matrix and your OT monitoring is isolated, a dual-matrix detection coverage review will show the exact path an attacker would take from email to controllers, and where to place the first detection that can stop the campaign early.
Sources: MITRE ATT&CK for Enterprise, MITRE ATT&CK for ICS, CISA and NSA Volt Typhoon advisory AA24-038A, Dragos 2026 OT Cybersecurity Year in Review, NERC CIP Standards.
One attacker path crosses two matrices.
The blind spot is the boundary.
Detect the pivot first.
Enterprise ATT&CK captures the travel path through IT, which is where most OT campaigns start and stage.
ICS ATT&CK captures what adversaries do when they reach operational systems and physical process control.
Identity misuse is the connective thread from domain compromise to engineering access, often with low noise.
Compromise of OT-hosting hypervisors can remove visibility and control in one move without direct controller access.
Pivot-focused detections need explicit ownership across SOC, OT monitoring, and identity telemetry workflows.
Start with domain controller credential theft, jump-host abuse, remote access behavior toward control zones, and engineering workstation anomalies.
Run one detection map that includes Enterprise and ICS techniques together so seams are visible and remediation is prioritized by attack path, not team boundary.
Industrial incidents should be triaged by potential process impact so teams can detect and interrupt campaigns before controller-level effect.
Travel is primarily Enterprise ATT&CK activity, initial access, credential theft, and lateral movement through IT systems.
Pivot is where identity abuse, remote access misuse, and bastion pathways cross from IT into operational environments.
Impact is where ICS ATT&CK behaviors affect process control, safety posture, and production continuity.
Enterprise and ICS ATT&CK are not alternatives. They are two halves of one industrial intrusion.
The IT-to-OT pivot is the most important detection target because it links attacker movement to physical consequence.
Dual-matrix mapping exposes blind seams and tells teams exactly where to place first-detection controls.
