Evidence boundary. The podcast and LinkedIn discussion are editorial context, not evidence. Restart assurance claims below rely on independent guidance and engineering judgement.

The operational problem

Industrial recovery has a milestone that conventional IT recovery often does not: a system can be technically available while the physical process is still not safe enough, trustworthy enough or understood well enough to resume. A virtual machine may boot, a PLC may answer and a backup may restore cleanly, yet the plant still needs confidence in recipes, logic, remote-access paths, engineering workstations and privileged identities.

That distinction is consistent with NIST SP 800-82 Rev. 3, which treats OT security as inseparable from reliability and safety constraints. Recovery therefore cannot be reduced to server availability. It needs evidence that the restored technical state matches an acceptable operational state.

What this diagram shows

A defensible restart decision depends on evidence that survives the compromised domain and can be interpreted consistently by IT and OT.

Restart evidence chainA restart decision is credible only when critical evidence survives outside the suspected compromise boundary
Suspected / cannot self-attest Question to resolve Independent evidence
Suspected domainHypervisor · AD · engineering station · PLC backup serverEvidence generated only here may share the attacker’s trust boundary
Assurance questionCan this domain prove its own integrity?If the answer depends only on its own logs, assurance becomes circular
Independent evidence
Golden logicKnown provenancePLC logic retained outside the affected administration plane
Signed firmwareTrusted hash / signatureBinary identity anchored in independent signing evidence
External telemetryOut-of-band recordsNetwork or security evidence collected outside the suspect domain
Process validationOperator + engineeringPhysical state and process behaviour agree with the expected baseline
Restart gate

Do independent cyber and process records converge on one defensible plant state?

GORestart with documented residual-risk authority.
NO-GOContinue containment or validation before production resumes.

What trustworthy restart evidence requires

The first rule is independence. If the hypervisor, identity plane or engineering workstation sits inside the suspected compromise boundary, relying exclusively on logs produced by that same domain creates circular assurance. Restart-critical evidence should be tamper-evident and, where practical, collected or replicated out of band.

The second rule is provenance. A recently approved baseline is not automatically known-good. If the possible attacker dwell time predates the baseline, that baseline becomes part of the investigation. The useful comparison points are independent PLC logic, signed firmware, validated recipes, remote-session records and privileged-account history. ISA/IEC 62443 provides the broader lifecycle and system-security context, while NIS2 reinforces the governance expectation around resilience and incident handling.

The third rule is a shared IT/OT decision language. At 03:00, a SOC analyst may interpret a connection as persistence while an operator sees a normal industrial cycle. Pre-agreed go/no-go criteria, evidence owners and restart authority reduce the need to renegotiate acceptable risk while production is waiting.

OT recovery finishes when the organisation can defend the restart decision, not when the server boots.
The decision
Build the restart evidence package before the incident: baselines, owners, thresholds, escalation and residual-risk authority.
Operational checks
  • Define which PLC logic, recipes, firmware, accounts and remote sessions are restart-critical.
  • Protect evidence sources from the same administrative domain they are intended to validate.
  • Assess whether baselines predate the possible attacker dwell time.
  • Agree IT/OT interpretation rules for common industrial behaviours before an outage.
  • Name the individual or forum with authority to accept residual restart risk.
Related episodeThe Restart Bottleneck Is Not the Backup. It Is the Evidence.LinkedInJoin the discussion
Source record

Sources & further reading

4 cited sourcesHow we source →
← Stadler RailNext: Automotive IDPS →Companion episode →