OT Cyber Weekly - What Does a Real OT/ICS Cybersecurity Incident Look Like

OT Cyber Weekly - What Does a Real OT/ICS Cybersecurity Incident Look Like

🎙 Mike Holcomb 👥 27K 📅 May 6, 2026 ⏱ 62 min 👁 512 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT securityICSincident responseMITRE ATT&CKColonial Pipeline

Summary

In this episode of OT Cyber Weekly, Mike Holcomb discusses incident response in OT/ICS environments, contrasting it with IT. He outlines the phases of incident response (preparation, identification, containment, eradication, recovery) and highlights key differences in OT, such as the priority on safety and availability over data confidentiality. He references real incidents like Colonial Pipeline and Frosty Goop to illustrate challenges. He emphasizes the lack of monitoring tools in most OT environments, making root cause analysis difficult. He introduces MITRE ATT&CK for ICS as a framework to understand attacker behaviors. He also mentions his own resources, including a TryHackMe room and a GitHub repository with OT simulation tools. The session includes practical advice on tabletop exercises and the importance of planning for disconnecting IT and OT networks.

127 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into OT incident response, emphasizing the unique challenges compared to IT. The argumentation is based on the author’s experience and references to well-known incidents, which strengthens credibility. However, the discussion is largely anecdotal and lacks in-depth technical detail or data-driven analysis. The emphasis on the lack of monitoring and root cause analysis is a critical point, but the argument could be more robust with specific examples or statistics.

Scientific Rigor, Source Quality, Title Accuracy

The video references MITRE ATT&CK for ICS and mentions incidents like Colonial Pipeline and Frosty Goop, but does not provide direct citations or links to these sources. The title accurately reflects the content. The author’s expertise is evident, but the lack of verifiable sources reduces the scientific rigor. The video is more of an expert opinion than a rigorously sourced analysis.

149 words

Title / Content Match

The title accurately reflects the content, which discusses real OT/ICS incidents and incident response.

Quality & Reliability

7/10

The video is an expert opinion from a practitioner with relevant experience. It references well-known incidents and frameworks (MITRE ATT&CK for ICS, Colonial Pipeline, Frosty Goop) but lacks detailed citations and verification of claims.

Key Moments

Cited Sources

Concurring Sources

  • MITRE ATT&CK for ICS — Framework used to categorize attacker techniques in ICS.
  • CISA Advisory on Frosty Goop — Official advisory on the Frosty Goop malware.

Dissenting Sources

  • No direct discordant sources found — The video does not present conflicting sources; it aligns with common knowledge in OT security.

Contribution & Novelties

The video offers a practitioner’s perspective on OT incident response, highlighting the unique challenges and the importance of preparation. It emphasizes the lack of monitoring and root cause analysis capabilities in most OT environments, which is a critical insight. The discussion of real incidents like Colonial Pipeline and Frosty Goop provides concrete examples.

Pour aller plus loin :

  • MITRE ATT&CK for ICS — Official framework for understanding ICS attacker behaviors.
  • NIST SP 800-82 — Guide to Industrial Control Systems Security.
  • SANS ICS Security — Training and resources for OT security.

90 words

Radar Profile

The radar profile shows high scores in quantity of information and technical level, reflecting the depth of discussion. Quality and reliability are moderate, indicating the need for more rigorous sourcing. Overall, the video is informative but relies on anecdotal evidence.

Reliability 7/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.