Operational technology

OT ICS and SCADA Incident Response

Get experienced help with a cyber incident affecting your industrial systems. GDF works with your operators to preserve evidence, understand the event and support a response that protects the process.

Water treatment and electrical utility infrastructure.

The engagement

Protect the process while preserving evidence

OT incident response operates under physical constraints. Safety, environmental consequence, process stability, vendor dependencies and limited redundancy shape every acquisition and containment decision.

GDF works with operators and control-system specialists to preserve relevant evidence, establish a defensible sequence of events and support safe response. Methods are adapted to the process, not imported unchanged from enterprise IT.

Scope

  • OT incident triage

    Joint technical and operational framing of affected processes, critical assets, safety limits and evidence priorities.

  • Passive evidence collection

    Use of available logs, captures, historian data and engineering records before intrusive methods are considered.

  • Engineering workstation forensics

    Examination of supported HMIs, engineering stations, jump hosts and related Windows systems.

  • Controller and configuration review

    Comparison of logic, configuration, firmware and change records where supported and operationally safe.

  • IT/OT boundary analysis

    Correlation of identity, remote access, firewall, network and enterprise events with control-system activity.

  • Recovery evidence and lessons

    Preserve restoration decisions, validated configurations and the record needed for oversight or later claims.

When the controller changed and nobody knows why

A setpoint moved and no one in the control room touched it. An operator display went blank for four minutes. A remote session showed up in the logs from a vendor account that should have been disabled last year. Leadership wants to know whether this is an attack, and they want to know in the next hour. GDF brings OT ICS and SCADA incident response to that moment: forensic method, industrial systems experience, and reporting that tells you what is known, what is not, and what can safely be done next.

Call 1-800-868-8189. We answer 24/7. When you call, tell us the affected operation, its current state and who holds operational authority on site. If you suspect accounts or systems are compromised, call from a phone and use a channel the attacker would not be reading.

The operator decides what is safe. We work inside that.

Nobody should assume that disconnecting, rebooting or scanning an industrial device is harmless. It can trip a process or leave a controller half-written. The operator determines process safety, environmental limits and acceptable operating conditions. GDF plans evidence preservation and analysis inside those limits, and we do not move without the operator's approval.

The initial response includes agreeing what evidence matters most and what approvals are needed before anyone touches a device. That plan accounts for fragile equipment, vendor dependencies, available backups, communication channels and stop conditions. If pulling a memory image from an HMI would put the process at risk, we write that limitation into the record and look for corroborating evidence in safer sources, such as the historian, the engineering workstation's project files or available switch logs. Those sources may answer part of the question, but they do not replace the contents of memory.

Attack, fault, or someone doing their job

A process anomaly is a symptom. Equipment failure, authorized maintenance nobody logged, a configuration error and a cyber intrusion can all produce the same one. We line up the technical and operational records and work out which explanations survive contact with the evidence.

The sources we go to: engineering workstation records, remote access logs, operator shift notes, alarm history, historian data and configuration backups. A historian stores process measurements and events over time, so it can show what the system reported during the window in question. It is also easy to over-read. Collection intervals, clock settings and gaps in the data all affect what a historian trace can and cannot prove.

Clocks are the trap. A PLC, an HMI, a historian and a domain controller frequently disagree by seconds or minutes, and by hours if a time zone was set wrong. We measure the offsets, record the uncertainty and build the chronology around it. Forcing events onto a single clean timeline when the clocks disagree produces a sequence that looks convincing and is wrong. The chronology GDF delivers shows what was observed, what changed, which access paths were involved and what remains unresolved.

Restoring the plant without erasing the record

Recovery changes the systems that hold the evidence. Rebuilding an engineering workstation or reloading a controller project is often the right call, and it also overwrites what the compromised state looked like. Before that happens, the response record should capture what was preserved, which source was used for the restore, and who approved the change. When conditions allow, we image first. When they do not, we say so.

GDF has spent decades producing forensic reports and expert testimony, so the incident record is built with the later questions in mind: what happened, how the response was handled and what supports each conclusion. Regulators, insurers, auditors and opposing counsel ask those questions months afterward. The scope can include a chronology, an evidence register, analysis of each affected system and readiness recommendations that name the log source, the retention gap or the missing backup owner that slowed you down this time.

Methodology

How incident response works

  1. Protect

    Establish safety, process and authority boundaries before collection or containment.

  2. Preserve

    Acquire the most volatile relevant evidence using passive or approved methods.

  3. Correlate

    Align engineering, process, network, identity and enterprise events on one timeline.

  4. Recover

    Support a controlled restoration sequence and preserve the factual record of what changed.

Evidence commonly examined

Evidence reviewed

  • HMI and engineering workstations
  • Historians, alarms and sequence-of-events data
  • Remote-access and jump-host records
  • Firewalls and passive network captures
  • Controller logic and configuration backups
  • Maintenance, change and operator logs

What you can expect

What you receive

  • OT incident chronology
  • Evidence and operational-constraint register
  • Affected-asset and pathway assessment
  • Safe remediation and readiness recommendations

Frequently asked

Common questions

Can you tell us whether a change was malicious?

Sometimes. We examine the surviving records and test the competing explanations against them. Some events support a firm conclusion. Others need more evidence, and some stay unresolved. We tell you which is which rather than guessing.

Do you direct plant operations?

No. Operational decisions stay with the authorized operator. We provide the technical analysis and propose actions; the operator decides.

Can we prepare before an incident?

Yes. Readiness work identifies your log sources and their retention, who owns the backups, what collection is possible on each system type, and who needs to be on the call at 2 a.m.

Can you collect evidence without stopping production?

Often some evidence can be collected passively, but feasibility depends on the architecture and incident. Operators must approve methods and safety boundaries.

Do you follow an OT-specific framework?

Our approach is consistent with OT-focused incident-handling principles, including the operational and safety distinctions described in NISTIR 8428.

Can you determine whether a process anomaly was malicious?

We test cyber, configuration, equipment and human explanations against the surviving evidence. Some events remain indeterminate, and the report should say so.

Speak with GDF about an active event

If you are dealing with an active OT, ICS or SCADA event, call GDF at 1-800-868-8189 now. Be ready to describe the affected operation, current process condition, known changes and the authorized operational contact. We can help preserve evidence, coordinate safe next steps and support incident response decisions without treating your production systems like office laptops.

Speak with GDF about an active event

Related services and resources: OT ICS SCADA forensics, critical infrastructure OT security.

Talk with an examiner

Discuss your matter and next step

Tell us the systems, evidence and deadline. We can review relevant experience, potential conflicts and the scope before engagement.

Since 1992 · 24/7 dispatch · Court-tested experts

Or call 1-800-868-8189

Email or phone is required. A submission does not create an engagement. For an active incident, please call. Read what we send with the request.

Talk with an examiner

Discuss the matter and the next step.

Tell us what happened and what you need to find out. Speak with a GDF expert about how we can help.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.