All scenarios
OT / ICS

Industrial control-system compromise

An attacker reaches SCADA and PLC systems. Manage safety-critical processes, physical impact and the friction between IT security and operations-technology teams.

Free to use for your own tabletop, no email gate.

Scenario brief

Industrial control-system compromise, OT / ICS

The threat

A compromised engineering workstation gives the adversary a path to the control network. Setpoints drift, a safety instrumented system trips, and the plant faces a genuine physical-safety decision, not just a data one.

Key injects

  • 01A PLC heartbeat is lost on a critical line; the interlock trips.
  • 02Operations wants to keep running; security wants to isolate.
  • 03Sensor readings look manipulated: can they be trusted?
  • 04A regulator asks whether public safety is at risk.

What's assessed

  • Safety-first decision-making under adversarial conditions
  • IT/OT authority and escalation clarity
  • Trustworthiness of telemetry and manual fallback
  • Public-safety communication

Exercise objectives

  • Reach a documented safe-state decision (run, degrade or shut down) within 45 minutes, with safety explicitly outranking uptime.
  • Resolve the IT-security-versus-operations conflict through one accountable decision-maker instead of a standoff.
  • Assess which telemetry can still be trusted and move affected lines to manual or local control where needed.
  • Have the regulator briefing (KRITIS/NIS2 reporting chain) and a public-safety statement ready before the exercise closes.

Roles at the table

  • Crisis team lead · Keeps safety, security and operations in one decision loop; owns the log and the clock.
  • IT / SOC · Scopes the path from the engineering workstation into the control network; hunts persistence without breaking operations.
  • OT engineering lead · Knows what the PLCs, interlocks and the safety instrumented system actually do, and what manual control really means.
  • Communications · Public-safety wording, workforce information and the line to press and neighbours.
  • Legal / regulatory · KRITIS/NIS2 reporting chain, liability of a restart decision, evidence preservation.
  • Plant management (executive) · Carries the run/stop decision and its production cost; the safety veto ends every debate.

Discussion prompts

  • 01The safety system tripped once. Do you trust it to trip again, and would you bet a life on it?
  • 02Operations wants to restart; security cannot rule out persistence in the control network. Who wins, on what evidence?
  • 03Which sensor readings do you still trust once manipulation is on the table, and what does your manual fallback actually look like?
  • 04A regulator asks whether public safety is at risk. What do you say when the honest answer is 'we don't know yet'?
  • 05Engineering workstations bridge IT and OT. Who owns them today, and who should?
  • 06If you isolate the plant network, what fails silently with it: interlocks, historians, remote maintenance?

Suggested timeline

  • 00:00–00:25Loss of PLC heartbeat, interlock trip: first situation picture
  • 00:25–01:05Safe-state decision: run, degrade or shut down, safety holds the veto
  • 01:05–02:00Telemetry trust, manual control, persistence hunt vs. operations
  • 02:00–02:40Regulator and public-safety communication (KRITIS/NIS2 chain)
  • 02:40–03:00Hot wash: restart preconditions and decision review

Run this scenario with your team.