Cyber Fusion Center Series

OT IR as Operational Discipline

Running OT Incident Response as an Operational Discipline

According to the 2025 Dragos and Marsh McLennan OT Security Financial Risk Report, OT incident response planning delivered the strongest measurable risk reduction among the controls studied.

Running OT Incident Response as an Operational Discipline

Of all the OT security controls an industrial organization can invest in, the one with the strongest correlation to measurable risk reduction is incident response planning. That finding from the 2025 Dragos and Marsh McLennan OT Security Financial Risk Report sits next to another reality from the 2025 SANS State of ICS/OT Cybersecurity Survey: only 14% of OT organizations feel fully prepared for emerging threats.

Most organizations have an IR plan. Far fewer have a capability they can execute safely under live industrial pressure. That gap between having a plan and running one is where incidents escalate. The OT Cyber Fusion Center closes that gap by turning documentation into practiced discipline through named playbooks, exercised coordination, and a program-level feedback loop that improves readiness between incidents.

Why OT Incident Response Is Not IT Incident Response

IT incident response is structured around the CIA triad, confidentiality, integrity, then availability. OT operations prioritize safety first, then availability, integrity, and confidentiality. In March 2026, Siemens VP Michael Metzler noted that a secure state and a safe state are not always the same state. Containment actions have to be evaluated for physical consequence before execution.

Dean Parsons reinforced the same point in February 2026: in OT, containment does not always mean shutdown. If a threat is constrained and not impacting physical process, maintaining controlled operations may be safer than aggressive isolation. That reverses standard IT instincts.

Detection ownership is also different. Dragos reported in its 2026 Year in Review that 30% of OT incidents in 2025 began with operational staff reporting abnormal behavior rather than security alerting. OT engineering is frequently first detection. A resilient OT IR program must be built around that operational fact.

Before the Incident: The Playbook Library and the Tabletop Program

Most organizations with an IR program maintain a plan document and annual review. The CFC model builds standing infrastructure used continuously between incidents: an OT-specific playbook library and a tabletop exercise program. Both are owned, scheduled, and measured.

Playbooks are written against recurring industrial scenarios: ransomware disrupting HMIs and historians, IT-to-OT lateral movement, control-system manipulation where process logic is reachable, and vendor-originated incidents. SANS 2025 found that roughly half of OT incidents started with unauthorized external access. Lesley Carhart reported in April 2025 that 52% of ICS facilities have no ransomware-specific IR plan and 20% do not know whether one exists.

Operational playbooks define system-level actions and authority in advance. They pre-delegate emergency isolation authority when safety is at immediate risk and include prebuilt notification templates for regulatory and customer communications. The tabletop program then pressure-tests those playbooks. SANS 2025 documented a 1.7x readiness multiplier for organizations that involve frontline technicians and operators in tabletop exercises.

During the Incident: The Coordination Architecture

The during-incident phase succeeds only when accountability is already mapped. If authority is undefined before the event, it is negotiated during the event while impact grows.

The CFC acts as the coordination hub. The SOC leads detection and technical analysis. OT engineering and plant operations lead decisions that affect physical process. Mature programs run three communication tiers in parallel: technical, operational, and executive, with continuous bridge calls to keep decision quality high and signal fidelity intact.

SANS 2025 showed nearly half of OT incidents are detected within 24 hours and 60% are contained within 48 hours. Remediation still extends into days or weeks in many environments, especially where visibility is incomplete. Detection has improved. Remediation discipline remains the differentiator.

After the Incident: The Discipline That Closes the Loop

Post-incident work is where many programs lose accumulated value. Dragos noted in 2026 that fewer than 10% of global OT/ICS environments perform security monitoring at a level sufficient to reconstruct events reliably. Restarting without root-cause clarity can reintroduce the same exposure.

The CFC runs post-incident review as routine workflow: structured stakeholder review, root-cause analysis such as Five Whys, and a formal report covering timeline, scope, business impact, and recommendations. What creates capability gain is ownership and closure. Each action is assigned, tracked, and routed back into playbooks, tabletop scenarios, and visibility architecture.

The IBM 2025 Cost of a Data Breach Report quantified the value of this loop. Faster detection and containment reduced global average breach cost to $4.44M, down 9% year over year, and incidents identified in under 200 days cost $1.14M less than slower cases.

What Comes Next

The OT Cyber Fusion Center unifies the playbook library, tabletop program, coordination architecture, and post-incident review loop into one operational discipline. Without a structured model, plans do not get exercised, exercises do not update plans, and reviews do not drive change. With one, each cycle sharpens the next.

Incident response capability determines how incident pressure unfolds. Recovery capability determines what comes after. In OT environments, both must be prepared in advance as operational sequences, not documentation artifacts.

Sources: 2025 Dragos and Marsh McLennan OT Security Financial Risk Report; 2025 SANS State of ICS/OT Cybersecurity Survey; SANS Institute blog, OT and ICS Incident Response in the Era of Living-off-the-Land Attacks (February 2026); Industrial Cyber, Crisis Lessons from OT Incident Response (March 2026), featuring Siemens VP Michael Metzler; SANS Institute, A Simple Framework for OT Ransomware Preparation (April 2025), by Lesley Carhart of Dragos; SANS Institute, Top 5 ICS Incident Response Tabletop Exercise Scenarios (January 2026); CISA Tabletop Exercise Packages; Dragos 2026 OT Cybersecurity Year in Review; CSO Online, How to Conduct an Effective Post-Incident Review (June 2025); IBM Cost of a Data Breach Report 2025; NIST SP 800-82 Revision 3; IEC 62443.

Plans do not stop incidents.
Practiced operating models do.
OT IR is a discipline.

14%OT organizations fully prepared per SANS 2025
30%OT incidents first reported by operations staff in 2025
1.7xReadiness multiplier when operators join tabletop exercises
<10%OT ICS environments with sufficient security monitoring
$1.14MAverage cost gap for breaches detected under 200 days
Before

Playbook library and tabletop cadence create readiness.

Click to explore

Operational playbooks predefine authority, system actions, and notifications before pressure distorts execution.

During

Three-tier coordination keeps technical and executive layers aligned.

Click to explore

SOC, OT engineering, and executive teams run in parallel with shared incident rhythm and clear authority boundaries.

After

Post-incident reviews must produce owned action plans.

Click to explore

Findings are assigned, tracked, and fed back into playbooks, exercises, and telemetry architecture.

Safety Priority

OT containment decisions are physical risk decisions.

Click to explore

In OT, safe-state decisions can differ from secure-state instincts, so operational leadership must co-own containment choices.

CFC Outcome

One model unifies four disconnected work streams.

Click to explore

The CFC turns plan, exercise, coordination, and review into one repeatable capability cycle that improves between incidents.

Playbook Maturity TestCan frontline operators execute it safely at 2 a.m.

A mature OT IR playbook names systems, owners, and escalation criteria in operational language that plant teams can execute immediately.

Coordination Maturity TestDo technical and executive tiers stay synchronized

Mature programs preserve detail from SOC to executive decisions through structured bridge rhythm and explicit ownership boundaries.

Post-Incident Maturity TestAre findings closed with owners and deadlines

Without assigned ownership and closure tracking, incident reviews become documents instead of capability upgrades.

Prepare means maintaining live OT playbooks and operator-inclusive tabletop cadence, not annual paperwork review.

Coordinate means running SOC, operations, engineering, and executive communication tiers in parallel under documented authority.

Improve means closing the post-incident loop by routing findings into playbooks, exercises, and visibility controls with ownership.

Takeaway 1

OT incident response capability is measured by execution discipline, not by plan existence.

Takeaway 2

Operational staff are core to OT detection and response and must be built into the program by design.

Takeaway 3

The CFC model closes before, during, and after gaps through one continuous operating loop.

Scroll to Top