OT, ICS and SCADA Forensics for Post-Incident Reconstruction
When an incident touches a control system, the useful reconstruction has to answer three questions: what actually happened in the process, how the attacker (or the misconfiguration, or the third-party device) reached the position from which it happened, and what artifacts survive to support the record. All three answers depend on evidence that has a very short half-life in OT environments.
What OT Forensics Actually Answers
- What happened in the process. Reconstruction of the operational sequence: which setpoint changes, which control-loop actions, which safety-instrumented-system responses, in what order, at what precise times.
- How the actor reached the position that produced the outcome. Whether through a compromised HMI, a compromised engineering workstation, a third-party maintenance device, a vendor remote-access path or the IT/OT boundary. The answer determines the corrective action.
- Whether the operator is responsible. The initial narrative in many OT incidents blames the human on shift. The reconstruction determines whether the record supports that or contradicts it. Both outcomes matter to the operator and to the operator’s counsel.
- What the compliance and reporting obligations are. CISA reporting under CIRCIA, sector-specific notification, USCG reporting for MTSA facilities, and the operator’s own regulator engagement all depend on the technical facts.
- What corrective action the environment actually requires. A defensible finding on causation is the input to a defensible corrective-action plan.
Evidence Acquisition in OT Environments
OT evidence has a short half-life. Volatile memory is lost when the affected device is power-cycled to restore operation. Historian rings roll over. Switch and firewall telemetry is often retained only briefly by default. Restoration of a controller from backup destroys the compromised state. Every acquisition decision has to balance the evidentiary value of preserving state against the operational requirement to restore the process.
- Immediate triage of what can be captured without disturbing operations, and what will require a coordinated operational pause.
- Volatile-memory capture from HMIs, engineering workstations and historians before any restart.
- Controlled disk imaging of the affected systems, coordinated with the operations team and with counsel.
- Network-telemetry preservation across the switches, firewalls, IDS sensors and any OT-native monitoring the environment carries, before the retention window rolls over.
- Controller-state acquisition where the analytical question requires it, including PLC program dumps and firmware capture where the on-device state is potentially compromised.
- Third-party device analysis where a contractor, maintenance or vendor device is potentially the initial vector.
- Chain of custody documented from the first touch, because the record often lands in regulatory proceedings or litigation.
Analysis and Reconstruction
Acquisition produces the raw material. Reconstruction produces the answer. The two-layer report anchors on a technical account of the acquired evidence and a plain-language narrative that counsel, executives, regulators and the tribunal can work with.
- Timeline reconstruction across all acquired sources, cross-referenced to the operational record and to any human-recorded log.
- Control-logic and firmware analysis where the on-device state is potentially compromised or where a specific attack technique targeted the logic.
- Network reconstruction across the OT and boundary telemetry, identifying the paths the actor traversed and the artifacts the traversal left.
- Attribution posture where the evidence supports it, distinguishing between opportunistic commodity activity and targeted attribution based on what the evidence actually shows.
- Corrective-action support that ties the causation finding to the specific architectural or procedural change required to close the exposure.
Full Critical Infrastructure Cybersecurity Compliance
Post-incident forensic work is one arm of the full Critical Infrastructure Cybersecurity Compliance suite our Miami practice runs, integrated with the vulnerability management, network assessment, testing and program-level compliance work the operator relies on continuously. Incident engagements are scoped against the specific reporting and evidence-preservation obligations the operator carries under the applicable framework, so the causation record supports both the immediate response and the compliance file the incident produces.
Incident reports are structured so the record supports both the immediate response and the compliance file that the incident produces: CISA reporting under CIRCIA where triggered, sector-specific notification (NERC event reporting for bulk electric system incidents, EPA notification for public water systems, USCG reporting for MTSA facilities, TSA reporting for pipeline and rail), and the operator’s own regulator engagement. Evidence preservation runs to the retention expectation the compliance framework requires, not to the operator’s default IT retention.
Where Our Miami OT Forensics Practice Runs Deepest
Water and wastewater incidents
Treatment plant and distribution SCADA incidents, with EPA notification support and the coordination with local health authority that many incidents in this sector require.
Manufacturing and cold-chain incidents
Production-line disruptions, safety-instrumented-system trips, product-quality incidents traced to control-system anomalies. Coordination with the operator’s product-liability and insurance carrier on any downstream exposure.
Port and maritime incidents
Terminal operating system incidents, crane and gate system incidents, and vessel-side incidents that reach into shore infrastructure. USCG reporting coordination for MTSA facilities.
Power and generation incidents
Substation, generation, and cogeneration control-system incidents, with NERC event reporting coordination for bulk electric system entities and coordination with the operator’s reliability compliance team.
Airport and aviation-adjacent OT
Airport ground-system, fuel-infrastructure and terminal-facility control-system incidents. Coordinates with the aviation cybersecurity practice on airworthiness-adjacent scope.
Third-party and supply-chain vector incidents
Where the initial vector is a contractor device, a vendor remote-access path or a supply-chain compromise, the analysis documents the specific vector and supports the operator’s recovery matter against the responsible third party.
Standards and Standing
Methodology draws on NIST SP 800-82 Rev.3, NIST SP 800-61 Rev.2, IEC 62443, SWGDE best practices, and the sector-specific incident reporting frameworks each operator is accountable to. Analysts hold GICSP, GRID, GCFR, GCFA, GREM and CISSP among other credentials. Reports are structured for authentication under Fla. Stat. § 90.901 and Federal Rules of Evidence 902(13) and 902(14), and for admissibility analysis under Daubert / Frye. The analyst who performed the acquisition is available for deposition and trial testimony.
Last updated: September 4, 2026
Preserve the Record Before the Restart
OT evidence is lost fast. Volatile state disappears on power cycle. Historian rings roll over. Network telemetry retention windows close. Rapid engagement preserves the fullest evidence base and produces the causation finding the operator, counsel and the regulator will need.
OT Incidents Require OT Forensic Rigor
Volatile-memory capture, coordinated acquisition across HMI, historian, workstation and network, and reconstruction structured for the regulator, the tribunal and the corrective-action plan.