12:00 – 12:25

Operational Technology (OT) environments are increasingly targeted by sophisticated cyber threats that can disrupt industrial processes, impact safety, and halt business operations. To prepare for these high impact scenarios, organizations must move beyond theoretical plans and embrace hands on crisis simulations that reveal how resilient their teams, systems, and processes truly are.
In this presentation, we take the audience step by step through how to design, structure, and execute an effective OT Cyber Drill, a realistic crisis exercise designed specifically for industrial environments such as manufacturing plants, utilities, water management facilities, and critical infrastructure.

Key Themes Covered

1. Why OT Crisis Simulations Are Essential
We begin by exploring the unique threat landscape of OT systems, the growing convergence between IT and OT, and why standard tabletop exercises are no longer sufficient. Attendees learn how live or hybrid simulations expose gaps in incident response, communication, detection, and decision-making that only emerge under pressure.

2. Preparing the Scenario: Building Realism Without Creating Risk
A successful drill relies on a carefully crafted scenario that reflects real vulnerabilities and operational constraints. We discuss how to:
• Select relevant OT attack vectors (ransomware, PLC manipulation, network segmentation failure, etc.)
• Ensure safety while maintaining realistic tension
• Integrate insights from past incidents and known threat actor tactics (eg, ICS Kill Chain, MITER ATT&CK for ICS)
• Align the simulation with regulatory frameworks such as NIS2, IEC 62443, or internal resilience objectives

3. Roles, Responsibilities & Stakeholder Engagement
An OT crisis affects more than just engineering teams. We break down how to involve:
• OT Engineers and Control Room Operators
• IT Security and SOC Analysts
• Management and Crisis Leadership
• External stakeholders such as vendors or emergency services
The presentation shows how to define decision points, injects, and communication flows that reflect real-world escalation paths.

4. Running the OT Cyber Drill
Participants are guided through the structure of an actual simulation:
• Kick-off & rules of engagement: ensuring a safe, controlled environment
• Scenario progression: timed injects, unexpected twists, system behavior changes
• Decision-making under pressure: testing protocols, leadership, and cross-team coordination
• Maintaining operational continuity: balancing production, safety, and security priorities
We provide concrete examples of injects used in previous exercises, without revealing sensitive details, to illustrate what “realistic pressure” truly looks like in an OT context.

5. Debriefing & Turning Lessons Into Action
The value of an OT Cyber Drill lies in what organizations do after the exercise. The session highlights how to:
• Identify procedural gaps and communication bottlenecks
• Evaluate technical readiness (monitoring, detection, access control, backups)
• Improve crisis leadership and interdepartmental cooperation
• Prioritize remediation steps to strengthen OT resilience
• Document findings for audits, compliance, and continuous improvement
A structured after action report (AAR) ensures that insights become concrete improvements in the organization's cybersecurity posture.

6. Practical Templates and Best Practices
To help attendees implement their own OT crisis simulation, we share:
• Scenario templates
• Stakeholder matrices
• Timeline structures
• Evaluation checklists
• Dos and don'ts learned from conducting drills across industrial sectors

By the end of the presentation, attendees will understand how to confidently design and execute an OT Cyber Drill that reinforces resilience, enhances incident response maturity, and prepares their organization for the complex challenges of modern OT cyber threats.

Back to the program overview

 

 

FHI, federatie van technologiebranches