Operational technology

OT, ICS & SCADA Incident Response

Examine the event without treating a control environment like an office network or allowing containment to cause the next operational incident.

Water treatment and electrical utility infrastructure.

The engagement

Protect the process while preserving evidence

OT incident response operates under physical constraints. Safety, environmental consequence, process stability, vendor dependencies and limited redundancy shape every acquisition and containment decision.

GDF works with operators and control-system specialists to preserve relevant evidence, establish a defensible sequence of events and support safe response. Methods are adapted to the process, not imported unchanged from enterprise IT.

Scope

  • OT incident triage

    Joint technical and operational framing of affected processes, critical assets, safety limits and evidence priorities.

  • Passive evidence collection

    Use of available logs, captures, historian data and engineering records before intrusive methods are considered.

  • Engineering workstation forensics

    Examination of supported HMIs, engineering stations, jump hosts and related Windows systems.

  • Controller and configuration review

    Comparison of logic, configuration, firmware and change records where supported and operationally safe.

  • IT/OT boundary analysis

    Correlation of identity, remote access, firewall, network and enterprise events with control-system activity.

  • Recovery evidence and lessons

    Preserve restoration decisions, validated configurations and the record needed for oversight or later claims.

Methodology

How incident response works

  1. Protect

    Establish safety, process and authority boundaries before collection or containment.

  2. Preserve

    Acquire the most volatile relevant evidence using passive or approved methods.

  3. Correlate

    Align engineering, process, network, identity and enterprise events on one timeline.

  4. Recover

    Support a controlled restoration sequence and preserve the factual record of what changed.

Evidence commonly examined

Evidence reviewed

  • HMI and engineering workstations
  • Historians, alarms and sequence-of-events data
  • Remote-access and jump-host records
  • Firewalls and passive network captures
  • Controller logic and configuration backups
  • Maintenance, change and operator logs

What you can expect

What you receive

  • OT incident chronology
  • Evidence and operational-constraint register
  • Affected-asset and pathway assessment
  • Safe remediation and readiness recommendations

Frequently asked

Common questions

Can you collect evidence without stopping production?

Often some evidence can be collected passively, but feasibility depends on the architecture and incident. Operators must approve methods and safety boundaries.

Do you follow an OT-specific framework?

Our approach is consistent with OT-focused incident-handling principles, including the operational and safety distinctions described in NISTIR 8428.

Can you determine whether a process anomaly was malicious?

We test cyber, configuration, equipment and human explanations against the surviving evidence. Some events remain indeterminate, and the report should say so.

Talk with an examiner

Discuss the matter and the next step.

Call to discuss timing, scope and the safest way to share information. Do not send evidence or credentials by email.

24/7 hotline: 1-800-868-8189

Privacy center

Choose your site settings

Optional technology stays off until you choose otherwise. You can change these browser settings at any time. Access to the core site does not depend on optional technologies.

Technology preferences
Sale or cross-context sharing: not used GDF does not sell or share website personal information for cross-context behavioral advertising.