Back to threat intel
OT / ICS

When ransomware crosses into the plant floor

SBS Incident Response29 July 20268 min read

Ransomware operators rarely set out to hit the plant floor — but flat networks make it inevitable. When an office-side intrusion reaches shared infrastructure, production stops whether the attacker intended it or not. Here is what we keep finding, and how to contain it.

The segmentation that wasn't

In most incidents the 'air gap' turned out to be a single firewall rule that had been widened for a maintenance vendor and never closed.

Shared services — Active Directory, DNS, file shares — bridged IT and OT far more than the network diagram suggested.

Containment without stopping production

The instinct to pull the plug can cause more damage than the ransomware. We prioritise isolating the propagation path while keeping safety-critical systems running.

Pre-identified choke points and a rehearsed decision tree are what separate a controlled shutdown from a chaotic one.

Before the next one

Segment OT from IT at the identity layer, not just the network layer.

Maintain offline, tested backups for engineering workstations and historian data.

Key takeaways

  • Verify segmentation continuously — maintenance rules are the usual culprit.
  • Plan containment that preserves safety-critical operations.
  • Keep offline, tested backups for OT-specific systems.