Incident Management Software: When A SCADA Cyberattack Stops Being An IT Problem

Incident Management Software

Written by Dr Shalen Sehgal | Crises Control  

A cyberattack is detected at 02:17 in the morning at a gas processing facility.

Operators in the control room notice that several SCADA screens have stopped updating. Pressure readings appear frozen, and valve positions can no longer be verified. At almost the same time, the IT security team detects suspicious activity across part of the operational network and immediately isolates several systems to contain the threat.

Production is still running. No emergency alarms have activated. Yet nobody can say with confidence whether the information displayed in the control room can still be trusted.

Within minutes, the focus shifts from the cyberattack itself to the decisions that follow.

  • Should production continue?
  • Should manual operating procedures be activated?
  • Who has the authority to declare an operational incident?
  • Should contractors working near affected equipment remain on site?
  • Does the regulator need to be informed?

These are no longer technical questions. They are operational decisions that affect safety, production and business continuity.

This is the point where a cyber incident stops being an IT problem and becomes an operational one.

Incident Management Software helps organisations activate, coordinate and document complex incidents involving multiple teams. When a SCADA or operational technology (OT) system is compromised, the challenge is no longer just investigating the attack. It is making sure IT, operations, engineering, HSE and senior leadership can share reliable information, coordinate their decisions and respond as one organisation while the incident is still unfolding.

The solution is not simply restoring affected systems as quickly as possible. It is creating a structured response where technical containment and operational decision-making happen together, giving every team the information they need to protect people, maintain safe operations and make informed decisions under pressure.

What Is An Operational Response To A SCADA Cyber Incident?

An operational response begins when a cyber incident has the potential to affect production, safety or the reliable operation of a facility.

At that point, the incident is no longer confined to the IT department. It becomes a business-wide response that requires technical teams and operational leaders to make decisions together.

The cybersecurity team is responsible for identifying the attack, containing affected systems and preserving evidence. At the same time, operations must decide whether production can continue safely, engineering needs to verify the condition of critical equipment, HSE must assess risks to personnel and leadership requires reliable information before making strategic decisions.

Each team has a different role, but they are responding to the same incident and their decisions are closely connected. An action taken by IT can influence production, while an operational decision may affect the way the cybersecurity investigation progresses.

One of the most common mistakes organisations make is treating these as separate phases. They assume the operational response begins after the technical investigation is under control. In reality, both responses need to progress together. Cybersecurity teams investigate what happened, while operational teams manage the consequences of what is happening.

Why This Becomes An Operational Challenge

Much of the discussion around operational technology security focuses on preventing cyberattacks. Strong cybersecurity controls are essential, but once a control system can no longer be trusted, preventing the attack is no longer the immediate challenge.

The challenge becomes managing operational uncertainty.

Operations may not know whether process readings are accurate. Engineering may be unsure whether equipment is responding correctly. HSE needs to understand whether there is any additional risk to personnel, while leadership is expected to make decisions that could affect production, customers and regulatory obligations.

None of those questions can wait until the investigation is complete.

This is why a SCADA cyber incident should never be viewed as purely a technical event. It quickly becomes an operational coordination challenge where communication, decision-making and clear responsibilities are just as important as technical expertise. The organisations that respond well are not necessarily those with the most advanced cybersecurity capability. They are the ones that can bring the right people together, establish a shared understanding of the situation and make informed decisions while information is still emerging.

A SCADA cyberattack becomes an operational incident the moment uncertainty affects decisions about people, production or safety.

When Communication Starts To Break Down

The first few minutes of a SCADA cyber incident often reveal another weakness that has little to do with technology.

Communication.

Many organisations still rely on phone calls, emails and messaging applications to coordinate their initial response. IT contacts operations. Operations contact engineering. Engineering contacts supervisors, while leadership requests updates from everyone involved.

At first, the process appears manageable.

As more people become involved, each team begins working from a slightly different understanding of the situation. IT believes the affected network has been isolated. Operations are preparing for a controlled shutdown. Engineering is still validating field instrumentation, while HSE is waiting for confirmation before deciding whether contractors should remain in the affected area.

None of these teams are making poor decisions. They are making decisions based on different pieces of information. Without a shared operational picture, those differences quickly become coordination problems rather than technical ones.

The difficulty is that no single person has a complete operational picture. Updates arrive through different channels, responsibilities are confirmed in separate conversations and important decisions may depend on information that has not yet reached the people who need it.

The longer this continues, the harder it becomes to coordinate the response. Time is spent chasing updates instead of managing the incident, and uncertainty begins influencing decisions that affect safety, production and business continuity.

The Biggest Misconception

One assumption deserves to be challenged.

Many organisations continue treating SCADA cyber incidents as technical problems until production is interrupted or safety systems begin behaving unexpectedly.

By then, valuable time may already have been lost.

The operational response should begin as soon as there is uncertainty about the safe operation of the facility, not only when systems stop working.

This misconception is understandable. Cyber incidents are usually detected by IT teams, so the instinct is to let the technical investigation progress before involving the wider organisation. The problem is that operations cannot always wait for technical certainty.

Decisions about production, workforce safety, contractor activity and business continuity often need to be made while the investigation is still unfolding. Waiting for IT to complete its analysis before bringing together the people responsible for running the facility can delay important actions, including:

  • Activating manual operating procedures
  • Restricting access to affected areas
  • Informing contractors and site personnel
  • Preparing for a controlled shutdown
  • Escalating to senior leadership
  • Notifying regulators or other external stakeholders where required

The strongest responses recognise that cyber containment and operational decision making are not separate phases. They happen at the same time, with each team providing the information the other needs to respond effectively.

Who Needs To Be Involved?

A successful oil and gas SCADA incident response depends on several teams working together from the moment the operational incident is declared.

Team

Primary Responsibility

IT Security

Investigate the cyberattack, contain affected systems and preserve evidence

Operations

Maintain safe production or coordinate a controlled shutdown

Engineering

Verify equipment status and assess process integrity

HSE

Protect personnel and assess operational safety risks

Leadership

Make strategic, operational and business decisions

Communications

Coordinate internal and external messaging

Every team brings a different perspective to the incident.

IT understands the technical threat and the steps needed to contain it. Operations understand how the facility is running. Engineering knows how equipment should behave under normal conditions. HSE focuses on protecting people, while leadership considers the wider operational, commercial and regulatory impact.

No single team has all the answers.

A successful response depends on bringing those different perspectives together quickly so decisions are based on a shared understanding of the situation rather than separate conversations taking place across the organisation.

Every team owns a different part of the response, but all of them are working towards the same operational outcome.

Manual Coordination Versus Structured Coordination

As more teams become involved, coordinating the response can become just as challenging as managing the cyber incident itself.

Someone needs to know:

  • Which teams have been notified?
  • Who has acknowledged the incident?
  • Which actions have started?
  • Which tasks remain outstanding?
  • Who owns each decision?
  • Does leadership have the same information as frontline teams?
  • Has the situation changed enough to require further escalation?

In many organisations, those answers are spread across phone calls, emails, messaging platforms and individual notebooks.

The issue is not that people stop communicating. In fact, they often communicate more than ever. The challenge is that important information becomes fragmented. Different teams receive updates at different times, responsibilities are confirmed in separate conversations and critical decisions may depend on information that has not yet reached the people who need it.

A structured response helps prevent that fragmentation by giving everyone a common framework to work from.

Rather than relying on a series of individual conversations, the response follows a clear sequence:

  1. Declare the operational incident.
  2. Activate the appropriate response teams.
  3. Assign role specific responsibilities.
  4. Maintain a shared operational picture.
  5. Review escalation requirements as the situation develops.

This approach allows cybersecurity specialists to focus on investigating the attack while operations, engineering, HSE and leadership concentrate on protecting people, maintaining safe operations and making informed decisions. Instead of spending valuable time chasing updates, the incident team can focus on managing the response itself.

Operational Incident Management Software

Interested in our Incident Management Software?

Flexible Incident Management Software to keep you connected and in control.

IT Response And Operational Response Are Different

Although they happen at the same time, the IT response and the operational response are trying to achieve different outcomes.

IT Response

Operational Response

Contain the cyberattack

Protect people and operations

Preserve evidence

Maintain safe production where possible

Restore systems

Coordinate operational decisions

Investigate the cause

Manage the operational impact

Recover infrastructure

Support business continuity

Neither response is more important than the other, but they cannot succeed in isolation.

The cybersecurity team focuses on understanding and containing the threat. Operations focus on running the facility safely despite the uncertainty the incident has created. One team investigates what happened, while the other manages what is happening.

Understanding this distinction helps organisations avoid one of the most common mistakes during a SCADA incident: waiting for technical certainty before making operational decisions. The two responses have different objectives, but they should support each other from the moment the incident is declared.

How Incident Management Software Supports Operational Response

Once several teams are responding at the same time, the greatest challenge is rarely a lack of expertise.

It is making sure everyone is working from the same information.

IT needs to understand the progress of containment activities. Operations need visibility of decisions affecting production. Engineering needs to know which systems can still be trusted, while HSE and leadership need reliable information before making decisions that could affect people, compliance or business continuity.

This is where Incident Management Software supports the response.

Rather than relying on separate phone calls, emails and messaging applications, a structured platform allows organisations to activate predefined response plans, notify the appropriate teams, assign role-based tasks and maintain a live view of the incident as it develops.

Platforms such as Crises Control are designed to support this type of coordination. For example, IT teams can receive technical containment tasks while operations receive manual operating procedures and HSE receives workforce safety actions. Leadership can monitor progress through a shared incident record instead of requesting updates from multiple teams.

When combined with Emergency Notification Software, critical information can be delivered through SMS, voice calls, email, push notifications and mobile applications, helping organisations communicate even if one channel becomes unavailable.

The technology does not replace operational judgement or technical expertise. Its value lies in reducing manual coordination, improving visibility and helping every team work from the same operational picture while the incident is still unfolding.

For more insight into coordinating the opening stages of major operational incidents, read our article Oil And Gas Emergency Response: Why The First 10 Minutes Determine Everything.

Questions To Ask During Your Next Exercise

Many organisations invest significant time testing how their IT teams respond to cyber incidents.

Far fewer exercises examine how operations, engineering, HSE and leadership coordinate while that technical response is still taking place.

A realistic SCADA exercise should test more than system recovery. It should examine whether the organisation can make safe, informed decisions while reliable information is still emerging.

Useful questions include:

  • Who has the authority to declare an operational incident?
  • Who decides whether production should continue or be reduced?
  • When are HSE and senior leadership informed?
  • How are contractors and other site personnel notified?
  • Can IT and operations work in parallel without waiting for one another?
  • How are conflicting updates investigated and resolved?
  • Can leadership see the same operational picture as frontline teams?

If these questions cannot be answered confidently during an exercise, they are unlikely to become easier during a real incident.

The objective is not simply to restore systems. It is to protect people, maintain safe operations and ensure every decision is based on the best information available at the time.

The NIST Cybersecurity Framework 2.0 reflects this principle by recognising that effective response requires coordination across business functions rather than treating cybersecurity as an isolated technical activity.

When Cybersecurity Becomes Operational Resilience

A SCADA cyberattack rarely becomes an operational crisis because malicious software spreads through a network.

It becomes an operational crisis because uncertainty spreads through the organisation.

Operations lose confidence in process data. Engineering questions whether equipment is behaving as expected. Leadership needs to make decisions before every answer is available, while HSE must continue protecting people throughout the response.

The organisations that respond most effectively are rarely those with the largest cybersecurity teams. They are the ones that can bring IT, engineering, operations, HSE and leadership together around a shared understanding of what is known, what remains uncertain and what needs to happen next.

That is the difference between responding to a cyberattack and managing an operational incident.

A structured response combines clearly defined responsibilities, reliable communication, coordinated workflows and operational visibility. Incident Management Software supports that approach by helping technical and operational teams work together while the investigation and recovery continue.

The quality of your response will not be determined by how quickly the cyberattack is detected. It will be determined by how effectively your organisation can coordinate once uncertainty begins.

If your organisation is reviewing its oil and gas SCADA incident response capability, Crises Control can help support secure incident activation, cross-functional communication and structured incident management from the first alert through to post-incident review.

Get a free personalised demo.

1. What Is A SCADA Cyber Incident?

A SCADA cyber incident is a cybersecurity event that affects Supervisory Control and Data Acquisition (SCADA) systems or other operational technology (OT) used to monitor and control industrial processes. In oil and gas operations, these incidents can affect production, process control and operational safety, requiring a coordinated response across multiple teams.

A cyber incident becomes an operational incident when it has the potential to affect production, safety, environmental protection or the reliable operation of a facility. At that point, the response extends beyond IT and requires coordination between operations, engineering, HSE, leadership and cybersecurity teams.

Incident Management Software helps organisations activate response plans, notify the right teams, assign responsibilities, track actions and maintain a shared operational picture throughout an incident. It supports coordination between IT and operational teams while creating an audit trail for post-incident review.

IT and operations should respond in parallel rather than waiting for one team to finish before the other begins. While IT focuses on containing and investigating the cyberattack, operations, engineering and HSE should assess safety, production and operational risks so critical decisions can be made without unnecessary delays.

A SCADA cyber exercise should test more than technical recovery. It should assess how IT, operations, engineering, HSE and leadership communicate, share information, make decisions, escalate issues and coordinate their response while the incident is still developing. The objective is to ensure people, processes and technology work together under operational pressure.