OTSecurity

OT-ISAC, NCSA, TXOne conduct Predictive Resilience exercise, focus on evidence-driven OT cybersecurity decisions


The OT Information Sharing and Analysis Center (OT-ISAC), Thailand’s National Cyber Security Agency (NCSA), and TXOne Networks conducted a Predictive Resilience Exercise in Bangkok on Aug. 18, 2026, bringing participants together to work through a realistic, evolving operational scenario. The exercise focused on identifying critical signals, validating information, engaging appropriate stakeholders and determining actions that support both cybersecurity and safe operations, rather than identifying a specific attacker or malware. 

The exercise centered on ‘Predictive Resilience,’ which OT-ISAC described as the ability to anticipate possibilities, recognize weak signals, challenge assumptions and make informed decisions before a complete picture of an incident is available. Participants were encouraged to work from evidence and continuously validate information as new signals emerged from security monitoring, engineering systems, vendor activity, operational observations and physical processes. 

Participant feedback highlighted five areas of value: decision-making under uncertainty, realistic evidence-driven scenarios, stronger understanding between IT and OT teams, facilitator expertise and shared best practices, and recognition that OT cyber incidents can create operational and physical challenges beyond the digital environment. The exercise also identified practical resilience measures, including greater visibility into vendor access and OT system changes, stronger logging and monitoring, controls around shared accounts, configuration comparison capabilities and clearer escalation pathways across teams and sectors. 

Real operational incidents rarely arrive with a complete explanation of what is happening. Information may emerge from security monitoring, engineering systems, vendor activity, operational observations, or changes in physical processes. Individually, these signals may appear insignificant. Together, they can tell a very different story.

​The exercise encouraged participants to work from evidence rather than assumptions, continuously validating what they knew and reconsidering what they thought they knew as new information emerged.

It also demonstrated the value of bringing IT, OT, cybersecurity and operational perspectives together.

One participant observed: “This exercise can build knowledge between OT and IT people to focus more on security. It helps them understand each other in ways they might not have considered before.”

Another highlighted the value of seeing suspicious activity develop across sectors without relying on a traditional malware signature, providing insight into why detection and response increasingly need to bridge IT and OT boundaries.

Participant feedback consistently centred around five themes: decision-making under uncertainty; realistic, evidence-driven scenarios; stronger IT and OT understanding; facilitator expertise and shared best practices; and recognising that an OT cyber incident is ultimately an operational and physical challenge, not simply a digital one.

Rather than testing whether participants could find one predetermined “correct” answer, the exercise explored how teams arrived at their decisions.

What evidence should be prioritised? What requires further validation? Who needs to be involved? Which assumptions are influencing the response? And what could be the operational consequences of acting — or waiting?

These conversations are particularly important in OT environments, where cybersecurity decisions must also account for safety, availability and continuity of operations.

The exercise also surfaced practical opportunities for strengthening organisational resilience. Participants highlighted the importance of greater visibility and traceability of vendor access and OT system changes, stronger logging and monitoring, better controls around shared accounts, configuration comparison capabilities, and clear escalation pathways across teams and sectors.

One participant captured an important lesson: “Organizations often confuse an approved login with a legitimate action — authentication is not the same as intent.”

A successful login may confirm that an authorised account has accessed a system. It does not necessarily confirm that the actions that follow are expected, appropriate or safe. Understanding that distinction requires more than technology. It requires context, communication and collaboration between cybersecurity, engineering and operations.

Perhaps the greatest value of an exercise like this comes from bringing people with different responsibilities, experiences and sector perspectives into the same conversation.

​An engineer may recognise an operational anomaly. A cybersecurity practitioner may identify unusual access behaviour. Another participant may challenge an assumption others have accepted. Someone from another sector may have encountered a similar problem and approached it differently.

​Each perspective contributes another piece of the picture.

​This is where collective learning becomes a resilience capability.

By sharing how different teams interpret evidence, validate information and make decisions, participants learn not only from the scenario but also from one another. That collective experience can then be brought back into individual organisations, strengthening processes, conversations and readiness before a real incident occurs.

​Predictive Resilience is not about predicting exactly when, where or how the next cyberattack will happen.

​It is about preparing organisations for the reality that the next incident may not resemble the last one. Threat actors change. Technology changes. Operational dependencies change. But the ability to recognise weak signals, validate evidence, challenge assumptions, collaborate across disciplines and make informed decisions remains fundamental.

​Exercises provide a safe environment to practise those capabilities before they are needed in a real operational situation. And, when those experiences are shared across a community, the value extends beyond a single organisation.

​Predictive Resilience creates an opportunity to practise decision-making, share perspectives, and strengthen readiness across the community.



Source link