Osmos Global Publication · Osmos Perspective
OT Incident Response Must Preserve Safe Operations
Cyber recovery and physical recovery need one coordinated plan.

The building does not disappear during a cyber incident
When a building-management interface becomes unavailable, ventilation, cooling, access and other services still affect people and operations. An incident plan designed only around restoring servers may miss those physical dependencies. Conversely, an operations team focused only on restoring service can unintentionally disrupt evidence collection or reconnect a compromised system.
NIST SP 800-61 Rev. 3 recommends integrating incident response throughout cybersecurity risk management [NIST]. It is not a building-safety manual. Osmos’s application is to coordinate cyber decisions with the engineers and operational leaders who understand the consequences of changing a building’s state.
Prepare an operational dependency map
Identify which services depend on supervisory platforms, networks, remote suppliers and local controllers.
Record who can assess the safe operating condition if the usual interface is unavailable. The map should distinguish loss of visibility from loss of control; they may require different responses and should not be treated as the same failure.
Maintain current contact routes and escalation authority. A supplier support number is insufficient if nobody knows who can authorise an emergency change or which team owns the physical asset. Exercises should include a key contact being unavailable so the plan does not depend on one individual.
Figure 1. Choose the authority boundary explicitly Original Osmos Global conceptual framework, 2026. Categories are not a maturity score. Prepared 1 September 2026.
What this means: More accurate predictions do not automatically justify more control authority.
Use qualified, coordinated containment decisions
Cyber containment can have operational consequences. Decisions to isolate, shut down or reconnect equipment should be made through the agreed incident structure with competent engineering input. This article does not prescribe a universal action because different systems have different fail states and safety requirements.
The plan should explain how teams communicate when ordinary channels are affected, how critical information is retained and how operational changes are recorded. It should also identify the point at which specialist emergency or safety procedures take precedence. Cybersecurity and physical safety are connected responsibilities, not competing departments.
Reconnection is not recovery
NIST’s recovery guidance includes verifying integrity and confirming normal operations [NIST]. For a building, the responsible team should establish what confirmation means for the affected services. A dashboard loading again does not demonstrate that schedules, alarms, permissions and physical responses are correct.
Use an approved sequence for restoring services and validating dependencies. Record which checks passed, which exceptions remain and who accepted the remaining risk. Where evidence or model outputs depend on affected data, flag the relevant period so later performance reports do not treat it as ordinary operation.
Illustrative decision rehearsal
A useful tabletop scenario is the loss of a building-management workstation while local equipment continues to operate. One team may assume the plant has stopped; another may assume everything remains safe because occupants have not complained. Neither assumption is a substitute for an engineering assessment of the actual state. This scenario is hypothetical and should be adapted by the responsible specialists.
Ask the teams to identify their first information needs, available communication channels and decision authority. The exercise should reveal whether staff know which observations can be trusted and how to obtain physical confirmation without making uncontrolled changes. It should also establish how the incident commander receives operational advice.
Include the supplier in the rehearsal if its remote service is part of the recovery path. Check the contractual contact route, availability of competent support and responsibility for preserving relevant records. The organisation should know what it can do independently if the supplier cannot respond immediately.
The exercise ends with a recovery decision, not merely successful contact. Who confirms that restored digital access reflects the correct physical configuration? Who communicates residual restrictions to users? Who closes the incident after remaining actions are assigned? Answering these questions before an outage reduces the need to improvise across organisational boundaries when time and information are constrained.
Exercise the joint plan
A tabletop exercise can test decision rights without changing live plant. Use a bounded scenario such as loss of a remote interface during occupied hours, and ask each team what information it needs. Record delays, conflicting assumptions and supplier dependencies as corrective actions with owners.
No universal recovery time is proposed here. Targets depend on criticality, engineering design and business tolerance. The article is an original application of cross-sector guidance, not a claim of NIST endorsement. The practical objective is a plan in which restoring digital capability and maintaining safe physical service are verified together.
Source notes
[NIST] Alexander Nelson, Sanjay Rekhi, Murugiah Souppaya and Karen Scarfone. Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. National Institute of Standards and Technology, 2025-04-03. Section 2; Table 2 GV.SC-05/08; Table 3 RC.RP. DOI: 10.6028/NIST.SP.800-61r3. Accessed 1 September 2026.
https://csrc.nist.gov/pubs/sp/800/61/r3/final
[HONG] Tianzhen Hong and Han Li. Good practices for documenting AI-based studies on energy and buildings. Energy & Buildings / Elsevier; author copy hosted by Lawrence Berkeley National Laboratory, 2026-01-20. Sections 2, 3.1–3.6 and 4; pp. 1–4. DOI: 10.1016/j.enbuild.2026.117043. Accessed 1 September 2026. https://eta-publications.lbl.gov/sites/default/files/2026-06/1-s2.0-s0378778826001039-main.pdf
Editorial and visual note
This is original Osmos Global analysis informed by the cited publications. Reported findings are distinguished from Osmos recommendations and illustrative scenarios. Source findings and trademarks remain attributable to their owners. Original visual designs do not imply endorsement by source organisations. The content is general research and does not replace site-specific professional advice.
Cite this
Osmos Global Research & Knowledge Centre (2026). OT Incident Response Must Preserve Safe Operations. Osmos Perspective, Osmos Global. https://www.osmosglobal.org/articles/ot-incident-response-must-preserve-safe-operations
Keep reading

Smart-Building Pilots Need an Operating Owner
An experiment becomes useful only when someone owns the decision it is meant to improve.
1 Sept 2026 · Osmos Global Research & Knowledge Centre · 5 min read

An Alert Is Not a Maintenance Outcome
Analytics creates value through verified correction, not the number of faults displayed.
1 Sept 2026 · Osmos Global Research & Knowledge Centre · 5 min read

Sensor Coverage Is Not Data Quality
Connected points need identities, context and a known level of trust before they can support decisions.
1 Sept 2026 · Osmos Global Research & Knowledge Centre · 5 min read
Download this paper
The full PDF, formatted for circulation. Downloads are for members, so that we know who our research reaches.
Discussion
Add what you are seeing on the ground.
