Operational technology
OT, ICS & SCADA Incident Response
Examine the event without treating a control environment like an office network or allowing containment to cause the next operational incident.
The engagement
Protect the process while preserving evidence
OT incident response operates under physical constraints. Safety, environmental consequence, process stability, vendor dependencies and limited redundancy shape every acquisition and containment decision.
GDF works with operators and control-system specialists to preserve relevant evidence, establish a defensible sequence of events and support safe response. Methods are adapted to the process, not imported unchanged from enterprise IT.
Scope
OT incident triage
Joint technical and operational framing of affected processes, critical assets, safety limits and evidence priorities.
Passive evidence collection
Use of available logs, captures, historian data and engineering records before intrusive methods are considered.
Engineering workstation forensics
Examination of supported HMIs, engineering stations, jump hosts and related Windows systems.
Controller and configuration review
Comparison of logic, configuration, firmware and change records where supported and operationally safe.
IT/OT boundary analysis
Correlation of identity, remote access, firewall, network and enterprise events with control-system activity.
Recovery evidence and lessons
Preserve restoration decisions, validated configurations and the record needed for oversight or later claims.
Methodology
How incident response works
-
Protect
Establish safety, process and authority boundaries before collection or containment.
-
Preserve
Acquire the most volatile relevant evidence using passive or approved methods.
-
Correlate
Align engineering, process, network, identity and enterprise events on one timeline.
-
Recover
Support a controlled restoration sequence and preserve the factual record of what changed.
Evidence commonly examined
Evidence reviewed
- HMI and engineering workstations
- Historians, alarms and sequence-of-events data
- Remote-access and jump-host records
- Firewalls and passive network captures
- Controller logic and configuration backups
- Maintenance, change and operator logs
What you can expect
What you receive
- OT incident chronology
- Evidence and operational-constraint register
- Affected-asset and pathway assessment
- Safe remediation and readiness recommendations
Frequently asked
Common questions
Can you collect evidence without stopping production?
Often some evidence can be collected passively, but feasibility depends on the architecture and incident. Operators must approve methods and safety boundaries.
Do you follow an OT-specific framework?
Our approach is consistent with OT-focused incident-handling principles, including the operational and safety distinctions described in NISTIR 8428.
Can you determine whether a process anomaly was malicious?
We test cyber, configuration, equipment and human explanations against the surviving evidence. Some events remain indeterminate, and the report should say so.
Related capabilities
Related services
Talk with an examiner
Discuss the matter and the next step.
Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.
24/7 hotline: 1-800-868-8189