The Six Critical Phases of Incident Response in ICS/OT and IT

Listen to this Post

The steps are the same in industrial (ICS/OT) and traditional IT environments. Even though the incidents might look very different between the two. If you are new to these, or need a refresher, here they are in all their glory!

1. Preparation

  • The most important phase
  • Develop a simple IR Process
  • Identify your initial IR team
  • Train your initial IR team members
  • Run some Tabletop Exercises for practice
  • Prepare for an incident BEFORE it happens!!!

2. Identification

  • Deploy network and host security monitoring
  • Review alerts for suspicious activity to investigate
  • Do not forget to ask for help when necessary – you aren’t alone!
  • In ICS/OT, get the right people involved – engineers, technicians, operators, etc.

3. Containment

  • Prevent further damage
  • Disconnect systems as necessary
  • Eliminate the attackers’ access to your systems
  • Determine the next steps which are right for your company

4. Eradication

  • Disconnect from the Internet and reset all passwords (at a minimum)
  • Take the steps necessary to remove attackers completely from the environment
  • Ensure all attack vectors, C2 Channels and other paths into the network are eliminated

5. Recovery

  • Ultimately why we have jobs…
  • Getting the business back up and running
  • Restore data from known good backups (if they exist)
  • Rebuild systems/apps as necessary to ensure free of compromise

6. Lessons Learned

  • Identify opportunities for improvement
  • Do not forget to highlight what went well
  • Be thankful for the Incident Response Team members

Practice Verified Codes and Commands: