24/7 incident response telephone: 24/7 incident response · +34 902 540 891

IT and OT incident response

The worst time to write a response plan is during an incident. We write it beforehand—for IT and OT—with your plant in view, and we are on the phone when needed.

The problem

Most incidents that eventually stop a plant do not originate there: they begin on the corporate network—with an email or stolen credentials—and move across. Responding only in OT or only in IT leaves half the organisation uncovered. This service therefore covers both networks and, above all, the point where an attacker crosses from one to the other.

Response plans inherited from IT also give instructions that may be impossible in a plant. “Isolate the affected system” sounds reasonable until that system runs a wastewater plant or controls a furnace that cannot be cooled abruptly. In OT, containment without process judgement can cause more damage than the attack itself.

The regulatory clock adds further pressure: NIS2 requires an early warning to the authority within 24 hours and notification within 72. An organisation that has not decided in advance who assesses, who notifies and with what data wastes those hours looking for a telephone number instead of containing the incident.

Scope

  • A retainer with contractually guaranteed response times and a 24/7 activation line.
  • Plant-specific playbooks by scenario: ransomware on the corporate network threatening OT, control manipulation, loss of SCADA visibility and an incident at a connected third party.
  • Containment criteria agreed with operations: what can be isolated, what cannot and who authorises it.
  • Forensic analysis compatible with control systems: evidence acquisition without aggravating the incident.
  • Regulatory notification support: preparation of technical information within NIS2 or ENS deadlines.
  • An annual tabletop exercise with management and operations to keep the plan current.

Deliverables

  • An OT response plan specific to your plant, not a template.
  • Scenario playbooks with decision trees and contacts.
  • An activation line with contractually defined response times.
  • After every activation: an incident report, root cause and applicable lessons learned.
  • An annual exercise report with identified gaps and corrective actions.

Facing ransomware

Ransomware is now the costliest threat to industry, and it almost never enters through the plant. It arrives through corporate email, encrypts the corporate network and, if nothing stops it, moves into the control network. Many production shutdowns were caused not by malware touching a PLC, but by a rushed decision to stop the plant “just in case”. Encryption-based extortion is also increasingly followed by a second threat: publication of stolen data.

That is why ransomware has its own playbook, and the first decision is not technical: whether to stop the process. That decision is made with operations, not in the heat of the moment. The second is to close the IT-to-OT path before the problem crosses. The third is to have decided beforehand who makes the call, what is isolated and which backup is used for recovery.

  • A ransomware-specific playbook covering double extortion through encryption and data exfiltration.
  • Process shutdown criteria agreed in advance with operations: neither stopping out of fear nor continuing through inertia.
  • Emergency IT/OT isolation: how to close the path between networks without leaving the plant blind.
  • Recovery from backups following the 3-2-1-1-0 rule—with one immutable or offline copy—tested beforehand rather than discovered during the incident.
  • Support with the decision on payment (not legal advice) and coordination with the insurer and authority.
  • Verified eradication before reconnection, to avoid being encrypted again two days later.

Questions we are asked before engagement

I have an incident right now and I am not a client. Will you help?

Call +34 902 540 891. We respond first and discuss paperwork afterwards; nobody will ask you for a signed contract while the plant is down. If we can help, we will.

How do you work with our IT provider or insurer?

Coordinating with them is part of the service. A real incident involves the IT forensic team, the insurer's expert and plant operations. Our role is to ensure that OT is not left unsupported and nobody contains the incident blindly.

Do you cover notification to the authority?

We work with you to prepare the technical information and meet the deadlines—early warning within 24 hours and notification within 72 under NIS2—and join communications if you want us on the call. The decision and signature always remain with your organisation.

Before the incident

The earlier the detection, the better the response

Titanium · Legal information
Titanium · Legal information
Titanium · Legal information