Home Capabilities Security Focus Areas Reports Events Team Insights R&D Contact Client Portal
Cyberpert R&D
Lab ProjectPublic research note

OT/ICS Resilience Twin

A research model for testing OT/IT containment decisions without touching production industrial systems.

A research model for testing OT/IT containment decisions without touching production industrial systems.

Research question

How can a critical infrastructure operator rehearse cyber containment while respecting safety, uptime, engineering authority, vendor support, maintenance windows, and physical process constraints?

The question matters because many enterprise response actions are unsafe or unacceptable in OT environments unless they are reviewed by operations and engineering leadership.

Twin structure

Cyberpert builds a scenario twin of dependencies: remote access, identity paths, engineering workstations, jump hosts, vendor support, historian connectivity, backup procedures, network choke points, and priority mission services.

The twin is not a full digital replica of production. It is a decision model used to test which containment actions are safe, which require engineering approval, and which may degrade mission services.

Exercise method

Scenarios include suspicious vendor access, compromised IT identity with OT reachability, ransomware in adjacent business systems, engineering workstation compromise, and degraded visibility during a maintenance window.

Participants must decide whether to disable remote access, isolate a network zone, move to manual operations, preserve forensic evidence, or restore from known-good configuration.

Public output

The public outputs are an OT containment boundary map, scenario inject library, mission-service dependency model, and resilience scorecard for infrastructure leaders.

The practical goal is a response plan that is fast enough for cyber pressure and disciplined enough for physical safety.

Critical infrastructure relevance

Energy, transport, telecommunications, water, logistics, and industrial services are strategic dependencies for NATO member states and private-sector operators. OT containment therefore cannot be copied from enterprise IT; a blocked session, isolated zone, or credential reset may affect safety, production, or public continuity.

The resilience twin gives leaders a way to rehearse cyber-physical decisions without touching live systems. It maps remote access, identity paths, vendor dependencies, engineering authority, historian connectivity, backup procedures, and mission-service priorities.

Public research output

The public output is a containment decision library, not a sensitive network map. It defines decision thresholds, authority roles, safe isolation tiers, engineering review points, evidence requirements, and recovery sequencing that other operators can adapt.

The method helps institutions answer the hardest OT question: which response action reduces cyber risk without creating a larger safety, reliability, or continuity risk?