Advanced cyber incident handling techniques for OT in DSOs
Shyam Musunuri, Mika Loukkalahti, Roman Gruber, Joose Haapaniemi, Benjamin Mitsch · IET conference proceedings. · 2025
Operational Technology (OT) systems were traditionally air-gapped, ensuring isolation from external networks. However, the growing integration of these systems with external networks has significantly expanded the attack surface, increasing their vulnerability to cyber threats. Detecting cyber incidents within the OT domain is inherently challenging due to the complexity of these systems. Even when incidents are identified, comprehending their full impact on the entire system during an attack can be difficult. OT personnel are adept at maintaining maximum system availability, they often lack the expertise required to manage cyber incidents effectively. This skills gap can have severe repercussions on various aspects of Distribution System Operator (DSO) operations, including reliability, operational efficiency, financial stability, environmental metrics, and reputation. The incident handling is the practical implementation of a blueprint which is the Incident Response Plan to handle any cyber incident. This paper will focus on developing a robust step by step Incident Handling process which can be followed by the OT domain in a DSO and shall recommend the use of advanced modern technologies in the various phases of the incident handling process. Following the recommended incident handling process helps DSOs reduce downtime, improve efficiency, comply with regulations, and save costs.