Correcting Prevention Bias in Your OT Cyber Incident Response
ID: f243764b-3ade-579b-98f1-439fe9d0b272
STIX ID: report--f243764b-3ade-579b-98f1-439fe9d0b272
Feed Name: Dragos Blog
Dragos analyzed multiple OT/ICS and IT cybersecurity standards and found a systemic "prevention bias"—controls and requirements heavily favor Identify and Protect functions while Detect, Respond, and Recover are underrepresented—leading to inadequate detection and incident response capabilities in industrial environments. The report supports this with standards metrics (e.g., NIST CSF, NIST 800-53, ISA/IEC 62443), IR case examples like misconfigured segmentation, and recommends adopting continuous improvement, increasing OT visibility, and conducting regular tabletop exercises to build active defense and resilience.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
