Resilience
Ransomware Preparedness
Be able to keep operating, or stop safely, if the enterprise environment is lost.
Defensive guide
Why should I care?
Documented incidents show operations halting even when controllers were untouched.
How to implement it
- Identify business dependencies that would force an operational stop
- Define and practise a rapid IT/OT isolation procedure
- Ensure OT can run for a defined period without enterprise services
- Protect and test backups
What good looks like
- A rehearsed isolation decision with named authority
- Documented manual operating procedures
Common failure modes
- Isolation never tested
- OT dependent on enterprise DNS, identity and licensing with no fallback
How to verify it
- Tabletop or scheduled test of the isolation procedure