When ransomware crosses into the plant floor
SBS Incident Response29 July 20268 min read
Ransomware operators rarely set out to hit the plant floor — but flat networks make it inevitable. When an office-side intrusion reaches shared infrastructure, production stops whether the attacker intended it or not. Here is what we keep finding, and how to contain it.
The segmentation that wasn't
In most incidents the 'air gap' turned out to be a single firewall rule that had been widened for a maintenance vendor and never closed.
Shared services — Active Directory, DNS, file shares — bridged IT and OT far more than the network diagram suggested.
Containment without stopping production
The instinct to pull the plug can cause more damage than the ransomware. We prioritise isolating the propagation path while keeping safety-critical systems running.
Pre-identified choke points and a rehearsed decision tree are what separate a controlled shutdown from a chaotic one.
Before the next one
Segment OT from IT at the identity layer, not just the network layer.
Maintain offline, tested backups for engineering workstations and historian data.
Key takeaways
- Verify segmentation continuously — maintenance rules are the usual culprit.
- Plan containment that preserves safety-critical operations.
- Keep offline, tested backups for OT-specific systems.
