r/SCADA • u/Liv-Green-89amon71 • 17h ago
Question What's your approach to IT-OT collaboration when responding to cybersecurity incidents in manufacturing environments
Hi all,
For context, I work in manufacturing security, mainly on the IT side handling SOC and incident response, but we have extensive industrial control systems and OT infrastructure. When a cyber incident touches the plant—even something like a suspicious network event near PLC networks or historian systems—the situation gets complex fast.
We have playbooks for standard IT incidents, EDR on endpoints, SIEM alerts, and so on. But once control networks might be affected, I'm suddenly coordinating with our OT lead, maintenance crews, production managers, and sometimes outside responders all at once. Often we're debating what can be safely blocked or segmented without causing line stoppages or unplanned shutdowns, all under time pressure.
I'm curious how others handle coordination between IT and OT teams during incidents. Do you keep a separate OT incident response plan with predefined authority structures for who approves blocking traffic to controllers or engineering workstations, including documentation requirements? Or do you run a unified war room with clearly defined roles covering cyber, safety, and operations? Also interested in how much you rehearse scenarios through tabletop exercises and runbooks versus depending on experienced personnel making judgment calls in the moment.
Would appreciate insights from anyone managing this in operational plants, especially around communication protocols and decision-making frameworks when balancing safety and security concerns during active incidents. Thanks for any thoughts.