Getting Started in OT/ICS Cybersecurity 2026 (Part 9A): Real-World Detection & Response Tactics
Mike Holcomb
0:00 / 0:00
Getting Started in OT/ICS Cybersecurity 2026 (Part 9A): Real-World Detection & Response Tactics
990 просмотров · 3 дня назад
Mike Holcomb
28,1 тыс. подписчиков
990 просмотров · 3 дня назад
In the Operational Technology (OT) and industrial control world, a cyber incident isn't a matter of "if"—it's a matter of "when". While an IT ransomware attack can cripple business systems overnight, an incident in an industrial control environment puts human lives, critical equipment, and physical plant availability at risk. You cannot simply pull network cables, reboot servers, or push aggressive scans across an operational plant floor without courting disaster. In this comprehensive guide, we break down what it actually takes to detect, contain, and survive a cyber incident on the OT network. From setting up bulletproof incident response playbooks and running realistic tabletop simulations to establishing high-fidelity network visibility and manual fallback procedures, this video gives you the field-tested strategies needed to defend critical infrastructure.
Getting Started in OT/ICS Cybersecurity (OnDemand): https://courses.mikeholcomb.com/offer...
Access more FREE OT/ICS cybersecurity resources at https://www.mikeholcomb.com.
In the Video:
00:00 - It’s Not If, But When: The Reality of OT Cyber Attacks
00:32 – The Jaguar Land Rover Outage: When IT Ransomware Halts Production
02:06 – The Golden Rule of OT: Safety Over Everything
03:00 – Cyber Attack vs. Loose Wire: Performing Root Cause Analysis 07:36 – The Containment Dilemma: Why You Can Never "Just Unplug" in OT
10:55 – The Visibility Crisis: Why 95% of OT Environments Are Completely Blind
14:38 – The 6 Phases of the OT Incident Response Lifecycle
18:56 – Phase 1: Why Preparation Is 90% of the Battle
21:42 – Drafting Incident Response Policies That Work (Using AI Templates)
29:53 – Building the OT Incident Response Team & Chain of Command 36:46 – Incident Command System for Industrial Control Systems (ICS4ICS)
40:36 – Out-of-Band Communications: Assume Your Email & Phones Are Tapped
44:39 – Step-by-Step Runbooks & The 2015 Ukraine Grid Lesson
46:58 – Manual Fallback Operations: Keeping the Plant Running Without Computers
48:01 – Legal Ticking Clocks: TSA, NERC CIP, NIS2, and SEC Mandatory Reporting
52:08 – Incident Response Retainers: Dragos, Mandiant, and Zero-Cost Options
01:03:00 – How to Run a High-Impact OT Tabletop Exercise
01:16:25 – Tabletop Do's and Don'ts: Building Collaboration vs. Assigning Blame
01:20:48 – Phase 2: Identification & Incident Detection on Industrial Networks
01:22:15 – Real-World Case Study: The Overheating PLC
01:28:22 – The Reality of Encryption on OT Networks
01:29:30 – Indicators of Compromise (IOCs), Volt Typhoon & The Pyramid of Pain
01:34:49 – MITRE ATT&CK for ICS: Mapping Threat Actor TTPs to Industrial Devices
01:43:29 – Network Security Monitoring vs. Host-Based EDR in Industrial Environments
01:54:30 – Network Hardware Evolution: Hubs, Managed Switches & SPAN/Mirror Ports
02:05:54 – Layer 3 Routing, VLANs, and Industrial Network Segmentation
02:08:26 – Detecting Anomaly Spikes and Sags with NetFlow
02:12:05 – Full Packet Capture (PCAP) in OT: Storage Realities & Trade-offs
Thank you for watching!!!
Looking for more on OT/ICS cybersecurity?
🔔 Subscribe for more technical OT/ICS training: https://mikeholcomb.com