OT Ransomware Incident Response Playbook by Kai London
In an industrial ransomware event the first decisions are not technical. They are about safety, about whether the process can keep running, and about who is allowed to say stop. This playbook walks the first 24 hours in order — and is written to be picked up during the incident, not read before it.
Available on Amazon.
What is inside
Safety first, always
Confirming safe state, protecting personnel, and the conditions under which a process must be brought down.
Isolation without blindness
Cutting the path the attacker is using while keeping the visibility operators need to run the plant.
Manual operations
Running without the digital layer — procedures, staffing, and the limits of how long it can be sustained.
Command and communications
Who leads, who decides, and what is said to staff, customers, insurers and regulators in the first hours.
Recovery sequencing
Rebuilding control systems in a validated order, with integrity checks before anything touches the process.
Return to production
The evidence and sign-offs needed to restart, and the post-incident record that stands up to scrutiny later.
Who it is for: incident responders and OT security teams, plant and operations managers, crisis leadership and business continuity teams, and the executives who will be asked why the line stopped.
Safe state first. Evidence second. Restart only when you can prove what you restarted.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.