In previous scenarios, we analyzed crises where data, reputation, and GDPR compliance were at stake. Now we’re entering the level of strategic risk, where the stakes become the physical continuity of business operations, and even human safety. We’re talking about an attack on industrial control systems (ICS) and operational technology (OT).
In modern industry, from manufacturing plants to critical infrastructure, once isolated factory networks have been connected to office networks (IT). This IT/OT convergence, while necessary for efficiency, has opened Pandora’s box, creating new, terrifying attack vectors. For the management of a manufacturing plant, operations director, or logistics head, the greatest fear is not email leaks, but “stopping the production line.” Every minute of downtime means gigantic financial losses and chaos in the supply chain. Thus, a fundamental problem arises: how do we test our readiness for a cyberattack on a factory without risking… accidentally stopping the factory during the test? This is exactly why tabletop exercises in the OT/ICS world are not “one of the options” but the only fully safe and ideal testing method. They allow conducting a “dry run” simulation in a conference room without any risk to ongoing production.
How Does IT Security Differ from OT (Operational Technology) Security?
Understanding the fundamental difference in priorities between IT and OT is key to understanding why this tabletop scenario is so unique.
In the classical IT (Information Technology) world – that is, office networks, email systems, CRM, and ERP – the paramount priority is Confidentiality. The traditional “CIA Triad” (Confidentiality, Integrity, Availability) places data protection from unauthorized access first. In the OT (Operational Technology) world – that is, industrial control systems (ICS), SCADA, PLC controllers on the production floor – the priority pyramid is turned upside down. Here, the absolute king is Availability and Physical Safety. The production process or energy transmission must operate uninterruptedly 24/7/365. Integrity is second (ensuring the PLC controller executes proper commands), and Confidentiality comes last.
This fundamental difference has dramatic consequences for incident response. The standard, “correct” IT team reaction to a virus is: “Immediately isolate the infected system from the network!” Applying the same logic in the OT world can be catastrophic. Suddenly disconnecting a PLC controller in a chemical plant can cause an uncontrolled reaction or physical damage to the reactor. This is a conflict of priorities that the tabletop must resolve.
📚 Read the complete guide: OT/ICS Security: Bezpieczeństwo systemów OT/ICS - różnice z IT, zagrożenia, praktyki
Why is “Stopping the Production Line” the Greatest Fear in Industry?
For a CISO or CTO talking to an operations director (COO) or CEO of a manufacturing company, the language must change. In this world, losses are not counted in “lost data records” but in “minutes of downtime.”
Stopping the production line is not an IT problem; it’s an immediate, catastrophic business incident. In industries such as automotive, steel mills, or food production, every minute of unplanned assembly line downtime means tens or hundreds of thousands of dollars in direct losses. It generates a domino effect: disrupting supply chains, leading to missed contractual deadlines, and generating massive contractual penalties. The value of unavailability is measurable, immediate, and devastating to the financial result.
Moreover, as we mentioned, in some industries (chemical, petrochemical, energy, pharmaceutical), the stakes are even higher. Uncontrolled shutdown or erroneous process modification (e.g., temperature change in a reactor) can lead to irreversible damage to machines worth tens of millions, and in extreme cases – to explosions, fires, or contamination, posing a direct threat to human life and health.
Why is Tabletop the Ideal Testing Method for OT/ICS Environments?
Given such enormous stakes, an obvious problem arises: how do we test the resilience of these systems? The answer is: very carefully. In the OT world, conducting “live” penetration tests or Red Team exercises on an active production network is an extremely risky and in most cases unacceptable action.
OT environments often consist of older, sensitive devices that were not designed with security in mind and can “crash” just from port scanning. The risk that a security test itself will cause the catastrophe it’s trying to simulate – that is, accidentally stop the production line – is simply too high. This is exactly why tabletop exercises in this context are the ideal and often the only fully safe tool. Tabletop allows testing “dry,” in sterile conference room conditions, exactly the same attack scenario on PLC controllers or SCADA system. It allows bringing engineers, operators, and the IT team together at one table to discuss response procedures without generating absolutely any risk to ongoing production, availability, or physical safety.
How Does CISA CTEP Support Scenarios for Industrial Control Systems (ICS)?
Organizations are not left alone in designing these complicated scenarios. The American agency CISA, aware of the critical importance of these systems, has created and made publicly available dedicated Tabletop Exercise Packages (CTEP) focused specifically on industrial control systems (ICS).
As we discussed in a previous article, CTEP packages are complete “starter kits” for conducting exercises. In the case of ICS scenarios, they provide ready-made narrative, modules, “injects,” and – most importantly – key discussion questions developed by OT security experts. For nFlo customers in the industrial, manufacturing, or critical infrastructure sectors, these packages are an invaluable resource. They allow using a world-class, proven template as a foundation, which we can then customize together to the specifics of a particular plant, its technology, and procedures.
What is the “Cyber-Physical Convergence” Scenario in the Context of a Factory?
This is the central theme and most important concept in OT security. The “cyber-physical convergence” scenario is a simulation in which a digital attack has direct, tangible consequences in the physical world (or vice versa). This is exactly what happens in a modern factory where the boundary between IT and OT is blurring.
This scenario typically proceeds in two directions. The first, more popular type, is cyberattack causing physical effects. The facilitator describes: “The attacker (e.g., through phishing an office employee) gains access to the IT network. From there, exploiting weak segmentation, they penetrate the OT network. They take control of the engineering station and modify the logic in the PLC controller of a key robot on the assembly line.” Result: the robot performs incorrect movements, physically destroying the product or the machine itself. The second type is physical incident causing cyber effects. Scenario: “A forklift on the floor hits a network cabinet (physical incident), breaking the fiber optic connecting the floor to the central server room.” Result: operators in the SCADA control room lose visualization and control over the process (digital effect). A good tabletop should test both paths.
What Does the “Ransomware on SCADA Systems” Scenario Look Like?
This is an increasingly common and terrifying scenario that paralyzes operators. SCADA (Supervisory Control and Data Acquisition) or HMI (Human-Machine Interface) systems are screens and computers on which operators monitor and control the production process (e.g., they see temperature, pressure, belt speed).
The scenario (Inject) is: “2:00 PM. A ransom note appears on all screens in the central control room. Operators lose visualization and control over the process. They don’t know what’s happening on the floor.” Importantly, machines on the floor may still be running, but “blindly,” which risks catastrophe. The facilitator must ask key questions: “Do we have an emergency manual line shutdown procedure (red button) and who has the authority for it?” “Can we control machines locally, from floor panels?” “Where do we have SCADA/HMI software backups and are they isolated from the network, or have they just been encrypted?”
What Questions Must the Facilitator Ask About Network Segmentation (IT vs. OT)?
Every attack scenario from IT to OT is actually a test of network segmentation. In an ideal world, the office network (IT) and production network (OT) should be completely isolated or connected at one, strictly monitored point (so-called DMZ zone). In practice, this segmentation is often weak or non-existent.
The facilitator must test this bridge. Questions should be ruthless: “How did the attacker get from the office network to the OT network? Did segmentation (firewalls) work? If not, why? If yes, how was it bypassed?” The answer is often one of the classic mistakes: “We have segmentation, but a production engineer (OT persona) needed internet access from their computer on the floor, so the IT team ‘temporarily’ opened a port for them, which remained open permanently.” Or: “IT administrators use the same passwords on the IT and OT networks.” Tabletop immediately exposes these mortally dangerous practices.
How to Practice Response to Attack via “Technician’s Laptop”?
This is a classic attack vector on OT environments that we’ve mentioned many times. It’s so dangerous because it completely bypasses all perimeter defenses (firewalls). The scenario (Inject) is very simple:
“11:00 AM. An external technician from machine X supplier arrives for scheduled maintenance. He connects his company laptop directly to the PLC controller port on the production line to diagnose the machine. Five minutes later, the entire production line #3 stops uncontrollably. The technician’s laptop was infected.” The facilitator asks: “Who has the authority to physically approach the technician and immediately disconnect their laptop? Who is their company liaison?” And most importantly: “What are our security procedures for external vendors? Do we scan their laptops before letting them on the floor? Do we require them to work only on our ‘clean,’ dedicated service laptops?”
Who Must Absolutely Participate in the OT Tabletop (Production Engineers, Plant Manager, IT)?
This is absolutely the most important and critical element of this exercise’s success. Conducting an OT tabletop with only the IT and security team is a complete waste of time and resources. The IT team doesn’t understand physical processes, downtime tolerance, or Safety procedures.
The goal of this exercise is to build a bridge between IT culture and OT culture. These two worlds must learn to talk to each other and respond together. Therefore, at the table must sit:
-
IT and Security Team (CISO, admins): Responsible for network, firewalls, detection (SOC).
-
Automation/Maintenance Engineers: People who physically program PLC controllers and know the machines.
-
SCADA/HMI Operators: People who work daily at the control station and will be the first to notice anomalies.
-
Plant Manager/Production Manager: Key business decision-maker. They have the authority to say “Stop the line!” or “You can’t shut that down!”
Without engineers and the plant manager, the discussion will be purely theoretical and worthless. They are the ones who know the consequences of technical decisions.
IT vs. OT Conflict: Why is This Tabletop Essential? (Flashcard)
Scenario: Active network worm detected on HMI computer on production line.
| Role | Standard Response (Based on Priorities) | Potential Consequence |
|---|---|---|
| IT Team (Priority: Confidentiality) | “Immediately disconnect the entire line from the network to stop the worm from spreading!” | Uncontrolled machine shutdown, product damage, physical danger. |
| OT Team (Priority: Availability/Safety) | “You can’t disconnect anything! We must first complete this production cycle, otherwise the reactor will explode.” | Worm spreads further to other systems, attacker gains more time. |
Tabletop Goal: Find the “golden mean” – a procedure that allows safe Containment with minimal, controlled operational risk, acceptable to both sides.
How Does Tabletop Help Test the PLC/SCADA Emergency Recovery Plan?
This scenario is actually a BCP/DRP test for the OT world. Standard IT recovery plans (e.g., virtual server backups) are insufficient here. In the OT world, “data” are proprietary SCADA system configurations and logic (programs) loaded into PLC controllers.
The facilitator must ask questions that only automation engineers (exercise participants) know the answers to: “Do we have current backups of the logic for every PLC controller on the floor? Where are they stored? Are they online (risking encryption along with the rest of the network) or offline on a dedicated medium?” And most importantly: “Assuming we have a backup. Who physically has the knowledge, software, and (often) specialized cable to connect to the controller and reload this logic? Is this our maintenance employee, or do we have to call an external integrator who will arrive in 3 days?” The answer to this question defines the real recovery time (RTO) for the production line.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
- Cybersecurity Incident Management — Cybersecurity incident management is the process of identifying, analyzing,…
- NIST Cybersecurity Framework — NIST Cybersecurity Framework (NIST CSF) is a set of standards and best…
- IT Security Architecture — IT security architecture is a structural approach to designing, implementing,…
- Security Architecture — Security architecture is a comprehensive approach to designing, implementing,…
Learn More
Explore related articles in our knowledge base:
- Tabletop Exercise at the Factory: How to test your plan in case of a cyber attack without stopping the production line?
- Backup that saves production: 3 disaster recovery scenarios for SCADA and PLC systems after an attack
- OT network segmentation for the reluctant: A practical guide to segmenting a flat network without stopping production
- What is SCADA? A complete guide to industrial systems security
- OT vs IT security: How to effectively monitor and protect industrial networks?
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
