Blackglass Response

Industrial cyber incident response

Open brief

106 · Industrial cyber incident response

Contain first. Preserve evidence. Rebuild only what you can explain.

Blackglass Response is a fictional incident-response team for factories, utilities and logistics operators where shutting everything down can be as dangerous as staying online. The site is structured like a live incident room with decisions, evidence custody and recovery gates.

Blackglass Response visual study for Industrial cyber incident response

Native record

incident timeline

Measured through host images, log sources, containment decisions, recovery tests and owner sign-off.

About / field note

Blackglass Response is a fictional incident-response team for factories, utilities and logistics operators where shutting everything down can be as dangerous as staying online. The site is structured like a live incident room with decisions, evidence custody and recovery gates.

Unit: incident timelineEvidence: host images, log sources, containment decisions, recovery tests and owner sign-off

Process / field sequence

A method should tell you what happens next.

01

Declare severity

Declare severity is the entry control point for a incident timeline. The team records host images, log sources, containment decisions, recovery tests and owner sign-off so the next decision is made from an explicit state, not memory or assumption.

02

Preserve before change

Preserve before change is the next control point for a incident timeline. The team records host images, log sources, containment decisions, recovery tests and owner sign-off so the next decision is made from an explicit state, not memory or assumption.

03

Contain by consequence

Contain by consequence is the next control point for a incident timeline. The team records host images, log sources, containment decisions, recovery tests and owner sign-off so the next decision is made from an explicit state, not memory or assumption.

04

Recover through gates

Recover through gates is the next control point for a incident timeline. The team records host images, log sources, containment decisions, recovery tests and owner sign-off so the next decision is made from an explicit state, not memory or assumption.

24/7 incident command /OT containment planning /Forensic acquisition /Recovery validation /24/7 incident command /OT containment planning /Forensic acquisition /Recovery validation /

24/7 incident command

24/7 incident command is scoped through the incident timeline, with host images, log sources, containment decisions, recovery tests and owner sign-off. The boundary, exclusions and handover evidence are stated before work begins.

OT containment planning

OT containment planning is scoped through the incident timeline, with host images, log sources, containment decisions, recovery tests and owner sign-off. Capacity, constraints and decision ownership stay visible from intake to closeout.

Forensic acquisition

Forensic acquisition is scoped through the incident timeline, with host images, log sources, containment decisions, recovery tests and owner sign-off. The boundary, exclusions and handover evidence are stated before work begins.

Recovery validation

Recovery validation is scoped through the incident timeline, with host images, log sources, containment decisions, recovery tests and owner sign-off. Capacity, constraints and decision ownership stay visible from intake to closeout.

People

Named responsibility

P01

Ada Mensah

Incident commander

Ada Mensah leads incident commander and owns the decisions that touch each incident timeline. The role is described by responsibility, not decorative biography.

P02

Ruan Jacobs

OT forensics lead

Ruan Jacobs leads ot forensics lead and owns the decisions that touch each incident timeline. The role is described by responsibility, not decorative biography.

P03

Mia Chen

Recovery assurance

Mia Chen leads recovery assurance and owns the decisions that touch each incident timeline. The role is described by responsibility, not decorative biography.

Selected work

01

Cold-store ransomware / IR-226

Segmented affected office systems from refrigeration controls, rebuilt identity services and validated temperature telemetry before reconnecting business applications.

02

Port terminal credential theft / IR-219

Revoked exposed access, reconstructed authentication history and introduced privileged session controls without stopping vessel gate operations.

03

Packaging line compromise / IR-207

Isolated one engineering workstation, captured PLC project files and proved logic integrity before production restart.

Evidence

Proof is useful when the denominator is visible.

17 min

fictional median commander acknowledgement

100%

acquisitions hashed at capture

3

independent recovery gates

0

evidence copies edited in place

Objections / answers

No accordion required

Will you immediately disconnect the plant?
Not by reflex. Safety, process state, redundancy and evidence risk are considered with operations before isolation actions are taken.
Do you negotiate with extortion groups?
Blackglass can coordinate specialist legal and negotiation partners, but the response plan does not assume payment is the recovery strategy.
Can you work with our existing MSSP?
Yes. Existing telemetry and provider relationships are valuable; Blackglass establishes incident authority, evidence handling and recovery criteria across all parties.

Reading room

1

Why an OT shutdown is a safety decision

Why an OT shutdown is a safety decision. A working note from Blackglass Response on the decisions hidden inside industrial cyber incident response. It connects the claim back to incident timeline and names where professional judgement or uncertainty remains.

2

The first twenty minutes after privileged credential theft

The first twenty minutes after privileged credential theft. A working note from Blackglass Response on the decisions hidden inside industrial cyber incident response. It connects the claim back to host images, log sources, containment decisions, recovery tests and owner sign-off and names where professional judgement or uncertainty remains.

3

Recovery is not complete when the login screen returns

Recovery is not complete when the login screen returns. A working note from Blackglass Response on the decisions hidden inside industrial cyber incident response. It connects the claim back to host images, log sources, containment decisions, recovery tests and owner sign-off and names where professional judgement or uncertainty remains.

Conversion / next step

Declare an incident or request an industrial response readiness review.

Write to the fictional team