What problem does it solve?
Generic IT incident response playbooks fail in industrial environments because they ignore safety-critical systems, limited downtime tolerance, and the need to coordinate IT SOC, OT engineering, and plant operations teams. This Skill provides OT-specific response procedures that address ICS/SCADA realities like PLC firmware, SIS integrity, and regulatory reporting clocks.
Core Features & Use Cases
- OT Incident Classification: Categorizes incidents by severity (SEV1-SAFETY through SEV5-IT-SPILLOVER) and category (ransomware, SIS compromise, process manipulation, insider threat).
- Category-Specific Playbooks: Executes structured response procedures for OT ransomware and safety system compromise, including immediate actions, containment steps, recovery priority order, and reporting requirements (CIRCIA 72-hour, NERC 1-hour, sector ISAC).
- PICERL Phase Guidance: Maps SANS Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned phases to OT-specific actions such as offline PLC backups, conduit isolation at the DMZ, and staged process restart.
- Use Case: When ransomware spreads from IT to Level 3 historian servers, activate the OT ransomware playbook to sever IT-OT conduits, verify PLC and SIS integrity, restore HMIs from offline backups, and meet CISA reporting deadlines.
Quick Start
Ask the AI to generate an OT incident response playbook for a ransomware incident affecting historian servers and HMIs, including containment steps and reporting timelines.