OT Security All-in-One · Volume 4

Ransomware Resilience, Recovery and AI Risk by Kai London

The final volume assumes the control layer is gone. What keeps running, who runs it by hand, how long that can last, and what has to be true before anything is reconnected — plus the new risk introduced by the AI and digital twin systems now embedded in operations.

Available on Amazon.

What is inside

OT incident response

Command, safety, isolation and evidence in an environment where stopping is itself a serious decision.

Manual fallback

Procedures, competence and staffing for running the process without the digital layer — and how long it holds.

Cyber recovery for control systems

Golden configurations, offline backups of engineering assets, and validated rebuild sequences.

Digital twins in recovery

Using simulation to plan and rehearse restoration, with clear limits on what a twin can tell you.

AI risk in operations

Dependencies on models and vendors that become single points of failure during an incident.

Continuity and exercising

Impact tolerances for essential services, and exercises that test people and decisions, not just runbooks.

Who it is for: OT incident responders and continuity planners, plant and operations leadership, CISOs in critical infrastructure, and regulators assessing recovery capability.

IEC 62443NIST SP 800-82ISO 22301NIST SP 800-61NIS2

Resilience is not the plan. It is whether the people named in it can do it on a bad night.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.