OT SOC & Detection Engineering by Kai London
You cannot install an agent on a PLC, and an enterprise SOC playbook does not survive contact with a control room. This field guide builds industrial detection from the traffic and behaviour you can actually observe — and a triage process that respects who owns the decision to stop a process.
Available on Amazon.
What is inside
Visibility without disruption
Passive network monitoring, span and tap placement, and the telemetry available from historians, jump hosts and engineering workstations.
Industrial protocols as signal
Reading Modbus, DNP3, OPC and their relatives well enough to tell a normal engineering change from an intrusion.
Detection content for ICS
Writing, tuning and versioning detections against ATT&CK for ICS, with coverage tracked rather than assumed.
SIEM and architecture
Where OT telemetry should land, what to keep, and how to integrate with the enterprise SOC without collapsing the boundary.
Triage and escalation
Joint IT and OT workflows, and the standing agreement on who may authorise a process-affecting action.
Threat hunting in OT
Hypothesis-led hunting using process knowledge that no enterprise analyst has by default.
Who it is for: OT SOC analysts and detection engineers, ICS and control engineers supporting monitoring, MSSP teams taking on industrial clients, and security leaders funding OT visibility.
In OT the alert is the easy part. Knowing who may act on it is the control.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.