Industrial Control System Incident Response: A Tabletop Guide

How to run a tabletop exercise for an industrial incident, with a sample scenario, roles, discussion questions and follow-up items for operations and IT.

3 min readBy Ironfield Cyber Team

When something goes wrong in an industrial environment, the response involves more than IT. Operators decide whether to run manually, engineers assess the process, safety staff weigh the risk, and executives manage customers and regulators. Those groups seldom practice working together. A tabletop exercise is a low-cost way to find out what happens when they have to.

A tabletop is a facilitated discussion of a scenario. No systems are touched. People talk through what they would do, and the facilitator notes where the plan is unclear, missing, or unrealistic.

Who should attend

Include people from across the organization.

  • Operations and plant or field supervisors.
  • Control system engineers and technicians.
  • IT and security staff, or your managed provider.
  • Safety and environmental personnel.
  • Executive leadership.
  • Finance, legal, HR, and communications representatives as appropriate.
  • Key vendors, if they have a role in support.

Prepare

Set objectives

Decide what you want to learn: decision authority, communication, manual operating procedures, vendor engagement, or recovery priorities.

Choose a facilitator

Pick someone who can keep the discussion on track and who is not defensive about gaps. An outside facilitator can help.

Gather the plan

Bring the incident response plan, network diagrams, contact lists, and any manual operating procedures. If these do not exist, that is the first finding.

A sample scenario

Consider a hypothetical mid-sized energy services company with a central control room and several remote sites. Here is how a scenario might unfold in stages.

Stage 1: The first signal

A control room operator reports that the supervisory screen is responding slowly and several tags show stale data. A short time later, the IT help desk reports that business computers are showing a ransom message.

Discuss: Who is notified first? Who decides whether this is related? Who has the authority to disconnect the business network from the control network?

Stage 2: Escalation

The business network appears fully encrypted. Operators lose visibility at one remote site. The vendor who supports the control software says they can connect remotely to help.

Discuss: Do you allow the vendor in? What controls apply to their access? Can operators run the process safely by hand? For how long? Who makes that call?

Stage 3: External pressure

A customer calls asking about delivery commitments. A reporter hears about the outage. The attacker claims to have stolen data.

Discuss: Who speaks to customers, regulators, and the media? What are your notification obligations? Who contacts the insurer and counsel?

Stage 4: Recovery

The team needs to restore systems. Backups of the business systems exist, but the last known good controller configuration is uncertain.

Discuss: What is the restoration order? Where are the offline configuration copies? How do you verify that restored systems are clean and safe to reconnect?

Questions to ask throughout

  • Who has authority, and do they know it?
  • What do operators do if screens go dark?
  • How do we communicate without email?
  • Which decisions require safety review?
  • What does each person need from the others?

Capture findings

Assign a note taker. Record gaps in three categories: plan gaps, such as missing procedures; capability gaps, such as no offline backups; and communication gaps, such as unclear contacts. Assign each finding an owner and a due date.

After the exercise

Within a couple of weeks, update the response plan and contact list, address the highest priority gaps, and schedule the next exercise. Share a short summary with leadership. Aim to run an exercise at least annually and after major changes.

Align with recognized guidance

CISA offers tabletop exercise resources, and NIST's Cybersecurity Framework 2.0 includes response and recovery as core functions. Regulated operators, including utilities under NERC CIP and pipeline operators under TSA directives, have specific planning and testing expectations to meet as well.

Working with Ironfield Cyber

Ironfield Cyber facilitates tabletop exercises for energy and construction companies, tailored to your operations and including both IT and operations staff. If you have never tested your plan, a short session can reveal more than another document review.