Operational technology
OT ICS and SCADA Incident Response
Get experienced help with a cyber incident affecting your industrial systems. GDF works with your operators to preserve evidence, understand the event and support a response that protects the process.
The engagement
Protect the process while preserving evidence
OT incident response operates under physical constraints. Safety, environmental consequence, process stability, vendor dependencies and limited redundancy shape every acquisition and containment decision.
GDF works with operators and control-system specialists to preserve relevant evidence, establish a defensible sequence of events and support safe response. Methods are adapted to the process, not imported unchanged from enterprise IT.
Scope
OT incident triage
Joint technical and operational framing of affected processes, critical assets, safety limits and evidence priorities.
Passive evidence collection
Use of available logs, captures, historian data and engineering records before intrusive methods are considered.
Engineering workstation forensics
Examination of supported HMIs, engineering stations, jump hosts and related Windows systems.
Controller and configuration review
Comparison of logic, configuration, firmware and change records where supported and operationally safe.
IT/OT boundary analysis
Correlation of identity, remote access, firewall, network and enterprise events with control-system activity.
Recovery evidence and lessons
Preserve restoration decisions, validated configurations and the record needed for oversight or later claims.
When the controller changed and nobody knows why
A setpoint moved and no one in the control room touched it. An operator display went blank for four minutes. A remote session showed up in the logs from a vendor account that should have been disabled last year. Leadership wants to know whether this is an attack, and they want to know in the next hour. GDF brings OT ICS and SCADA incident response to that moment: forensic method, industrial systems experience, and reporting that tells you what is known, what is not, and what can safely be done next.
Call 1-800-868-8189. We answer 24/7. When you call, tell us the affected operation, its current state and who holds operational authority on site. If you suspect accounts or systems are compromised, call from a phone and use a channel the attacker would not be reading.
The operator decides what is safe. We work inside that.
Nobody should assume that disconnecting, rebooting or scanning an industrial device is harmless. It can trip a process or leave a controller half-written. The operator determines process safety, environmental limits and acceptable operating conditions. GDF plans evidence preservation and analysis inside those limits, and we do not move without the operator's approval.
The initial response includes agreeing what evidence matters most and what approvals are needed before anyone touches a device. That plan accounts for fragile equipment, vendor dependencies, available backups, communication channels and stop conditions. If pulling a memory image from an HMI would put the process at risk, we write that limitation into the record and look for corroborating evidence in safer sources, such as the historian, the engineering workstation's project files or available switch logs. Those sources may answer part of the question, but they do not replace the contents of memory.
Attack, fault, or someone doing their job
A process anomaly is a symptom. Equipment failure, authorized maintenance nobody logged, a configuration error and a cyber intrusion can all produce the same one. We line up the technical and operational records and work out which explanations survive contact with the evidence.
The sources we go to: engineering workstation records, remote access logs, operator shift notes, alarm history, historian data and configuration backups. A historian stores process measurements and events over time, so it can show what the system reported during the window in question. It is also easy to over-read. Collection intervals, clock settings and gaps in the data all affect what a historian trace can and cannot prove.
Clocks are the trap. A PLC, an HMI, a historian and a domain controller frequently disagree by seconds or minutes, and by hours if a time zone was set wrong. We measure the offsets, record the uncertainty and build the chronology around it. Forcing events onto a single clean timeline when the clocks disagree produces a sequence that looks convincing and is wrong. The chronology GDF delivers shows what was observed, what changed, which access paths were involved and what remains unresolved.
Restoring the plant without erasing the record
Recovery changes the systems that hold the evidence. Rebuilding an engineering workstation or reloading a controller project is often the right call, and it also overwrites what the compromised state looked like. Before that happens, the response record should capture what was preserved, which source was used for the restore, and who approved the change. When conditions allow, we image first. When they do not, we say so.
GDF has spent decades producing forensic reports and expert testimony, so the incident record is built with the later questions in mind: what happened, how the response was handled and what supports each conclusion. Regulators, insurers, auditors and opposing counsel ask those questions months afterward. The scope can include a chronology, an evidence register, analysis of each affected system and readiness recommendations that name the log source, the retention gap or the missing backup owner that slowed you down this time.
Methodology
How incident response works
-
Protect
Establish safety, process and authority boundaries before collection or containment.
-
Preserve
Acquire the most volatile relevant evidence using passive or approved methods.
-
Correlate
Align engineering, process, network, identity and enterprise events on one timeline.
-
Recover
Support a controlled restoration sequence and preserve the factual record of what changed.
Evidence commonly examined
Evidence reviewed
- HMI and engineering workstations
- Historians, alarms and sequence-of-events data
- Remote-access and jump-host records
- Firewalls and passive network captures
- Controller logic and configuration backups
- Maintenance, change and operator logs
What you can expect
What you receive
- OT incident chronology
- Evidence and operational-constraint register
- Affected-asset and pathway assessment
- Safe remediation and readiness recommendations
Frequently asked
Common questions
Can you tell us whether a change was malicious?
Sometimes. We examine the surviving records and test the competing explanations against them. Some events support a firm conclusion. Others need more evidence, and some stay unresolved. We tell you which is which rather than guessing.
Do you direct plant operations?
No. Operational decisions stay with the authorized operator. We provide the technical analysis and propose actions; the operator decides.
Can we prepare before an incident?
Yes. Readiness work identifies your log sources and their retention, who owns the backups, what collection is possible on each system type, and who needs to be on the call at 2 a.m.
Can you collect evidence without stopping production?
Often some evidence can be collected passively, but feasibility depends on the architecture and incident. Operators must approve methods and safety boundaries.
Do you follow an OT-specific framework?
Our approach is consistent with OT-focused incident-handling principles, including the operational and safety distinctions described in NISTIR 8428.
Can you determine whether a process anomaly was malicious?
We test cyber, configuration, equipment and human explanations against the surviving evidence. Some events remain indeterminate, and the report should say so.
Speak with GDF about an active event
If you are dealing with an active OT, ICS or SCADA event, call GDF at 1-800-868-8189 now. Be ready to describe the affected operation, current process condition, known changes and the authorized operational contact. We can help preserve evidence, coordinate safe next steps and support incident response decisions without treating your production systems like office laptops.
Speak with GDF about an active event
Related services and resources: OT ICS SCADA forensics, critical infrastructure OT security.
Talk with an examiner
Discuss your matter and next step
Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.
Since 1992 · 24/7 dispatch · Court-tested experts
Talk with an examiner
Discuss the matter and the next step.
Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.
24/7 hotline: 1-800-868-8189