Перейти к содержимому

Getting Started in OT/ICS Cybersecurity 2026 (Part 9A): Real-World Detection & Response Tactics

Mike Holcomb

0:00 / 0:00

Getting Started in OT/ICS Cybersecurity 2026 (Part 9A): Real-World Detection & Response Tactics

990 просмотров · 3 дня назад
Mike Holcomb
28,1 тыс. подписчиков
990 просмотров · 3 дня назад
In the Operational Technology (OT) and industrial control world, a cyber incident isn't a matter of "if"—it's a matter of "when". While an IT ransomware attack can cripple business systems overnight, an incident in an industrial control environment puts human lives, critical equipment, and physical plant availability at risk. You cannot simply pull network cables, reboot servers, or push aggressive scans across an operational plant floor without courting disaster. In this comprehensive guide, we break down what it actually takes to detect, contain, and survive a cyber incident on the OT network. From setting up bulletproof incident response playbooks and running realistic tabletop simulations to establishing high-fidelity network visibility and manual fallback procedures, this video gives you the field-tested strategies needed to defend critical infrastructure. Getting Started in OT/ICS Cybersecurity (OnDemand): https://courses.mikeholcomb.com/offer... Access more FREE OT/ICS cybersecurity resources at https://www.mikeholcomb.com. In the Video: 00:00 - It’s Not If, But When: The Reality of OT Cyber Attacks 00:32 – The Jaguar Land Rover Outage: When IT Ransomware Halts Production 02:06 – The Golden Rule of OT: Safety Over Everything 03:00 – Cyber Attack vs. Loose Wire: Performing Root Cause Analysis 07:36 – The Containment Dilemma: Why You Can Never "Just Unplug" in OT 10:55 – The Visibility Crisis: Why 95% of OT Environments Are Completely Blind 14:38 – The 6 Phases of the OT Incident Response Lifecycle 18:56 – Phase 1: Why Preparation Is 90% of the Battle 21:42 – Drafting Incident Response Policies That Work (Using AI Templates) 29:53 – Building the OT Incident Response Team & Chain of Command 36:46 – Incident Command System for Industrial Control Systems (ICS4ICS) 40:36 – Out-of-Band Communications: Assume Your Email & Phones Are Tapped 44:39 – Step-by-Step Runbooks & The 2015 Ukraine Grid Lesson 46:58 – Manual Fallback Operations: Keeping the Plant Running Without Computers 48:01 – Legal Ticking Clocks: TSA, NERC CIP, NIS2, and SEC Mandatory Reporting 52:08 – Incident Response Retainers: Dragos, Mandiant, and Zero-Cost Options 01:03:00 – How to Run a High-Impact OT Tabletop Exercise 01:16:25 – Tabletop Do's and Don'ts: Building Collaboration vs. Assigning Blame 01:20:48 – Phase 2: Identification & Incident Detection on Industrial Networks 01:22:15 – Real-World Case Study: The Overheating PLC 01:28:22 – The Reality of Encryption on OT Networks 01:29:30 – Indicators of Compromise (IOCs), Volt Typhoon & The Pyramid of Pain 01:34:49 – MITRE ATT&CK for ICS: Mapping Threat Actor TTPs to Industrial Devices 01:43:29 – Network Security Monitoring vs. Host-Based EDR in Industrial Environments 01:54:30 – Network Hardware Evolution: Hubs, Managed Switches & SPAN/Mirror Ports 02:05:54 – Layer 3 Routing, VLANs, and Industrial Network Segmentation 02:08:26 – Detecting Anomaly Spikes and Sags with NetFlow 02:12:05 – Full Packet Capture (PCAP) in OT: Storage Realities & Trade-offs Thank you for watching!!! Looking for more on OT/ICS cybersecurity? 🔔 Subscribe for more technical OT/ICS training: https://mikeholcomb.com