A cyberattack on an oil and gas company can start as an IT security problem and become an operational problem very quickly.
Imagine that unusual activity is detected on a corporate network connected to systems supporting a processing facility. The cyber security team begins investigating and takes steps to contain the threat. At the same time, the OT security team is checking whether operational technology has been affected.
The Plant Manager now needs to know whether production can continue safely. Operations may need to change procedures. HSE needs to understand whether the change creates additional risks. The Business Continuity Manager is assessing how long the facility could operate under restricted conditions. Senior leadership wants to know what has happened, what could happen next and what decisions are needed.
The technical investigation is still underway, but the organisation already has an operational incident to manage.
This is where Incident Response Software can provide a coordination layer between cyber security and the wider business response. It does not replace SIEM, EDR, OT security or other specialist security tools. Instead, it helps the people responsible for operations, safety, continuity and leadership coordinate the decisions, communications and actions that follow a cyber incident.
When A Cyber Incident Becomes An Operational Incident
A cyber incident affecting an office application can cause serious disruption. An incident involving operational technology raises a different set of questions because OT systems interact with physical processes, equipment and industrial operations.
NIST guidance recognises that OT environments have requirements around performance, reliability and safety that can differ from conventional IT environments.
That means the response cannot focus only on removing the attacker.
The organisation may also need to establish:
- Whether the affected process remains safe to operate
- Which systems can still be trusted
- Whether equipment or processes need to be isolated
- Whether operators need to use manual procedures
- Whether the incident could affect another facility
- Whether HSE needs to become directly involved
- What employees and contractors need to know
- Whether business continuity arrangements need to be activated
- When senior leadership needs to make a decision
The security team may lead the technical investigation, but the consequences of the incident can quickly involve the whole organisation.
The Operational Questions Start Before The Technical Investigation Is Finished
Cyber incidents rarely provide a neat sequence of events.
The security team may know that suspicious activity has been detected, while the OT team is still establishing whether plant systems have been affected. Operations may already be considering temporary procedures, even though the full technical picture is not yet available.
This creates a difficult situation for decision-makers.
Act too early and people may respond to assumptions. Wait for complete technical certainty and the organisation may lose valuable time preparing for an operational impact that is already developing.
The answer is not to make every decision immediately. It is to separate what is known from what is being investigated and make responsibilities clear.
A Plant Manager might need to know whether a process can continue. The OT Security Manager may need to establish whether a particular system has been compromised. HSE may need to assess the safety implications of changing how equipment is operated.
Each person needs different information, but their decisions are connected.
A structured response gives these teams a way to share relevant updates without turning every technical finding into a company-wide communication.
Why IT Cannot Be Expected To Own The Whole Response
Cyber security teams are responsible for detecting, investigating and containing threats. They should not also be expected to manage every operational consequence of an attack.
Consider the difference between these two questions.
- The security analyst asks: What has been compromised?
- The Plant Manager asks: What does that mean for the facility?
- The OT Security Manager asks: Can this system still be trusted?
- HSE asks: Does the change in operating conditions introduce another risk?
- The Business Continuity Manager asks: What happens if normal production cannot resume?
- Leadership asks: What decisions need to be made now?
None of these questions is less important than the others. They simply belong to different areas of expertise.
A cross-functional response may involve:
- IT and cyber security
- OT security and engineering
- Plant and Operations management
- HSE
- Business continuity and risk
- Corporate communications
- Senior leadership
- External specialists or authorities where required
The challenge is connecting these functions without creating another collection of disconnected calls, emails and messages.
What Happens When Normal Plant Operations Change?
One of the most difficult consequences of an OT cyber incident can be the need to operate differently from normal.
A facility may rely on automated controls, digital monitoring and connected systems for routine operations. If some of those systems are isolated or considered unreliable, operators may need to use alternative processes.
That change creates its own workload and risks.
People need to know which systems are affected, which remain available, who has authorised temporary procedures and who is responsible for monitoring the situation.
A response should therefore make it clear:
- What has changed
- Why it has changed
- Who authorised the change
- Which temporary procedures apply
- Who owns each action
- What information still needs to be confirmed
- What conditions need to be met before normal operations resume
This is where cyber security and operational decision-making need to work together.
A technical containment action might reduce the immediate cyber risk while creating a production or safety consideration. The answer is not to delay containment. It is to make sure the people responsible for the physical operation are involved in understanding its consequences.
Where Traditional Incident Response Can Struggle
Most organisations already have cyber incident procedures. They may include detailed playbooks for malware, ransomware, compromised accounts, network isolation and system recovery.
Those procedures are necessary, but they do not always cover the coordination problem that appears when IT, OT and Operations are dealing with the same incident.
- Who tells the Plant Manager that a system has been isolated?
- Who tells Operations that a normal process has changed?
- Who keeps HSE informed while the technical investigation continues?
- Who records decisions about production?
- Who tracks recovery actions that sit outside the cyber security team’s responsibilities?
In a smaller incident, people may solve these problems informally. Someone makes a phone call, another person sends an email and a manager keeps notes.
The approach becomes harder to manage when several sites, departments or response teams are involved.
Information can become scattered across inboxes, spreadsheets, messaging channels and individual notes. People may have different versions of the situation, while the Incident Manager spends time asking for updates instead of coordinating the response.
The problem is not that phones, email or radio are bad tools. They are useful communication methods. They simply do not provide a shared operational record by themselves.
What Incident Response Software Should Actually Do
The value of Incident Response Software is not that it replaces specialist cyber security technology.
A useful coordination process should sit alongside those systems and help manage the organisational response.
A practical structure might look like:
Detection → Assessment → Operational Decision → Containment → Recovery → Review
These activities will not always happen in this exact order. Some will happen at the same time. The important point is that the organisation can identify what is happening, who is responsible and what needs to happen next.
A predefined response plan could identify the relevant teams, communication routes, decision owners, escalation points and recovery actions.
The response team can then see:
- Who has been notified
- Who has acknowledged an instruction
- Which actions are underway
- Who owns each action
- Which decisions remain outstanding
- When escalation is required
- What recovery work has been completed
This reduces the need for one person to keep the entire response together through memory, spreadsheets and repeated phone calls.
Communication Needs To Follow The Incident
A cyber incident can generate a surprising amount of communication, but more messages do not necessarily create more clarity.
The first message may need to be simple because people need to know what to do without being given unverified technical information.
Later, different groups may need different updates.
Operations may need instructions about a process. HSE may need information about a safety assessment. Leadership may need the current business impact and available options. Employees may simply need to know whether their normal working arrangements have changed.
Role-based communication helps keep these messages relevant.
It also reduces the temptation to send every preliminary finding to everyone. During an uncertain incident, unconfirmed information can quickly become accepted as fact, especially when people are already under pressure.
The goal is not to communicate everything. It is to communicate the right information to the right people as the situation develops.
Recovery Needs The Same Level Of Coordination
Containing the attack is not the end of the incident.
Recovery may involve restoring systems, validating them, checking operational dependencies and deciding when temporary procedures can be withdrawn. Different teams may need to complete different actions before normal operations can resume.
For example, cyber security may confirm that containment is complete. OT specialists may then assess affected systems. Engineering may validate equipment and process conditions. Operations may confirm whether normal procedures can resume, while HSE reviews any relevant safety considerations.
Business Continuity may need to assess whether temporary arrangements are still required, while leadership receives a consolidated recovery update.
The exact sequence will depend on the incident, but the principle is consistent: recovery needs ownership.
An action without a clear owner can become an action that everyone assumes someone else is handling.
A Common Assumption Worth Challenging
A common assumption is that the best cyber response is always the fastest technical containment.
Containment is essential, but operational environments require another question: what happens when the containment action changes the way the facility operates?
Isolating a system could reduce cyber risk while affecting production. Taking a process offline could protect equipment while creating another operational dependency. Moving from automated to manual procedures could reduce reliance on a compromised system while increasing workload for operators.
This does not mean technical teams should wait until every operational question has been answered before taking action.
It means the response should connect technical containment with operational decision-making.
For an oil and gas organisation, cyber resilience is not only about protecting networks. It is also about understanding what happens to the physical operation when digital systems cannot be relied upon.
How To Test Your Cyber Incident Response
A written cyber incident plan can look complete until people have to use it.
Exercises should therefore test the operational consequences, not just the technical playbook.
Ask:
- Can IT notify OT security and Operations immediately?
- Does the Plant Manager know who can authorise operational changes?
- Can HSE join the response without searching through separate contact lists?
- Can leadership receive a clear assessment without interrupting technical teams repeatedly?
- Can temporary operating instructions reach the correct people?
- Does every important recovery action have a named owner?
- Can overdue actions be escalated?
- Can the organisation identify which information was confirmed at each stage?
- Can the organisation reconstruct important decisions and communications afterwards?
These questions reveal whether the cyber response plan can work across the business, rather than simply whether the security team has a good technical procedure.
NIST’s revised SP 800-61 Rev. 3, published in 2025, also places incident response within wider cybersecurity risk management rather than treating it as an isolated technical activity.
For organisations working with operational technology, that broader view is particularly useful.
How Crises Control Can Support The Wider Response
Crises Control can provide the coordination layer around an operational cyber incident without replacing specialist IT security or OT systems.
Authorised users can activate predefined response plans and notify relevant response groups. Its Incident Manager provides a structured workspace for coordinating communications and maintaining an incident record, while tasks can be assigned and tracked as the response develops.
This can be useful when responsibility is spread across several functions. Cyber security might own technical containment, while Operations manages temporary plant procedures, HSE completes a safety assessment and Business Continuity tracks the wider business impact.
Cloud access can also support authorised personnel working across locations, while a structured incident record helps keep communications, updates and actions connected.
The technology is not the response itself. The people making operational, safety and business decisions remain responsible for the outcome. The value comes from giving those people a clearer way to coordinate their part of the response.
For a related look at the wider emergency response challenges facing oil and gas organisations, see Oil And Gas Emergency Response: Why The First 10 Minutes Determine Everything.
The Better Question Is What Happens To The Plant
Stopping an attack is clearly a priority. For an oil and gas organisation, it is not the only question that matters.
The harder question is what happens to the facility when normal digital systems cannot be trusted.
Can Operations continue safely? Can OT Security and IT communicate effectively with the people running the plant? Can HSE understand the consequences of operational changes? Can Business Continuity track the wider impact? Can leadership see what has been decided, what remains uncertain and which actions are still outstanding?
A cyberattack affecting operational technology can quickly cross the boundary between information security and physical operations. That means the response needs to cross organisational boundaries too.
Crises Control can help organisations structure that wider response by connecting communication, incident coordination, responsibilities and recovery actions in one process.
The strongest cyber incident response is not simply the one that detects an attacker quickly. It is the one that allows the organisation to keep operating safely, make informed decisions and coordinate recovery when normal systems and procedures are under pressure.
If you are reviewing how your organisation would respond to a cyber incident affecting operational technology, ask whether your current process gives IT, OT, Operations, HSE, Business Continuity and leadership a practical way to work together.
Frequently Asked Questions
What Is Incident Response Software?
Incident Response Software helps organisations coordinate people, communications, actions and recovery activities during an incident. In oil and gas, it can provide a coordination layer between cyber security, OT, Operations, HSE, Business Continuity and leadership.
Why Is Cyber Incident Response Different For Oil And Gas?
Oil and gas facilities depend on operational technology that interacts with physical processes and equipment. A cyber incident affecting OT can therefore create operational and safety concerns alongside the technical security problem.
What Is The Difference Between Incident Response And Incident Management Software?
Incident response focuses on the actions taken to address an incident, while incident management provides the wider structure for coordinating people, communications, tasks, decisions and records throughout the event.
Should IT And OT Manage Cyber Incidents Separately?
They may have different technical responsibilities, but serious incidents affecting operational technology require coordination between IT, OT Security, Operations, HSE, Business Continuity, Risk and leadership.
How Should Oil And Gas Companies Test Cyber Incident Response?
Exercises should test more than technical containment. Organisations should involve IT, OT Security, Operations, HSE, Business Continuity and leadership, then test communication, decision-making, task ownership, escalation and recovery. NIST guidance recommends incident response capabilities that cover planning, detection, analysis, containment, communication and reporting.
This article was drafted with AI assistance and reviewed by the Crises Control team. Featured image: AI-generated.


