OT, ICS & SCADA field guides · Detection

OT SOC & Detection Engineering by Kai London

You cannot install an agent on a PLC, and an enterprise SOC playbook does not survive contact with a control room. This field guide builds industrial detection from the traffic and behaviour you can actually observe — and a triage process that respects who owns the decision to stop a process.

Available on Amazon.

What is inside

Visibility without disruption

Passive network monitoring, span and tap placement, and the telemetry available from historians, jump hosts and engineering workstations.

Industrial protocols as signal

Reading Modbus, DNP3, OPC and their relatives well enough to tell a normal engineering change from an intrusion.

Detection content for ICS

Writing, tuning and versioning detections against ATT&CK for ICS, with coverage tracked rather than assumed.

SIEM and architecture

Where OT telemetry should land, what to keep, and how to integrate with the enterprise SOC without collapsing the boundary.

Triage and escalation

Joint IT and OT workflows, and the standing agreement on who may authorise a process-affecting action.

Threat hunting in OT

Hypothesis-led hunting using process knowledge that no enterprise analyst has by default.

Who it is for: OT SOC analysts and detection engineers, ICS and control engineers supporting monitoring, MSSP teams taking on industrial clients, and security leaders funding OT visibility.

MITRE ATT&CK for ICSIEC 62443NIST SP 800-82NIS2Purdue model

In OT the alert is the easy part. Knowing who may act on it is the control.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.