OT Security Resilience: Before, During and After the Incident
A practical resilience framework for industrial environments — organised across three phases: anticipation, response, and recovery.
avg. industrial data breach cost (2024)
of all cyberattacks hit manufacturing (2025)
avg. time to identify an industrial breach
cost of manufacturing unplanned downtime
Executive Summary
Industrial organisations have spent years building stronger perimeter defences. Yet the threat landscape keeps outpacing those efforts. Manufacturing is the single most targeted sector for ransomware, now for the fifth consecutive year, according to IBM X-Force. The consequences are severe:
avg. industrial data breach cost (2024)
The highest year-on-year increase across all industries — source: IBM Cost of a Data Breach Report
cost of unplanned manufacturing downtime
Production lines that stop, supply chains that fracture, and revenue that evaporates
These are not abstract numbers. They represent production lines that stop, supply chains that fracture, and revenue that evaporates.
Against this backdrop, boardroom conversations are shifting. Gartner's 2026 cybersecurity trends report identifies cyber resilience as a strategic imperative driven by regulatory volatility, geopolitical tensions, and an accelerating threat landscape. The message is clear: prevention alone is no longer sufficient.
Organisations must build the capacity to:
Anticipate
Harden access controls, segment networks, build complete audit trails.
Withstand
Reduce attack surface so intrusions stay contained, not catastrophic.
Respond
Instant containment — kill switches, isolated mode, real-time monitoring.
Recover
Forensic analysis, credential rotation, controlled validated recovery.
— whilst keeping production running.
The European regulatory environment reinforces this shift. The NIS2 Directive, now entering active enforcement across EU member states, explicitly requires business continuity planning, crisis management, incident handling, and supply chain security as core compliance obligations. For industrial operators, NIS2 compliance is not just about protecting IT systems. It demands operational resilience across the entire organisation, including OT environments.
This expert opinion presents a resilience framework for OT environments, organised into three phases:
For each phase, we examine the challenge from both a cybersecurity and production perspective, and demonstrate how WALLIX PAM delivers practical resilience capabilities that satisfy regulatory requirements whilst keeping operations alive.
The Case for OT Resilience
—
Why Prevention Is Necessary but Not Sufficient
Manufacturing is firmly established as the most targeted sector for cyberattacks. Attackers exploit sprawling networks, complex legacy systems, and inadequate segmentation between IT and OT environments. These gaps persist even in well-defended organisations that exploit zero-day vulnerabilities, compromised supply chains, and social engineering.
of all cyberattacks hit manufacturing (2025)
The highest share on record — source: IBM X-Force Threat Intelligence Index 2026
consecutive #1 most attacked industry
Manufacturing has topped the ranking every year since 2021
IBM X-Force Threat Intelligence Index
Manufacturing: #1 Most Attacked Industry — 2021–2025
Most targeted sector globally
Most extorted industry; ~half of Asia attacks
Enters IBM CODB top 5 costliest industries
70% of attacks targeted critical infrastructure
27.7% of all global cyberattacks — highest share on record
This is why Gartner now frames cybersecurity through the lens of resilience rather than prevention. Their 2026 trends report notes that "shifting geopolitical landscapes and evolving global mandates have made cybersecurity a critical business risk with direct implications for organisational resilience." In OT environments, this means accepting that an attacker may gain access. The organisations that fare best are those that can contain the damage, maintain critical operations, and recover quickly.
The organisations that fare best are those that can contain the damage, maintain critical operations, and recover quickly.
—
The Dual Impact: Cybersecurity and Production
What makes OT resilience fundamentally different from IT resilience is the dual impact of every incident. A ransomware attack on a corporate file server causes inconvenience and data loss. The same attack reaching a SCADA system or PLC can halt a production line, create safety hazards, and cascade through an entire supply chain.
Manufacturing downtime costs vary by sector, but the numbers are consistently brutal:
automotive unplanned stoppage cost
Manufacturing downtime costs vary by sector — but the numbers are consistently brutal
avg. industrial unplanned downtime cost
Source: IBM Cost of a Data Breach Report 2024
avg. time to identify an industrial breach
Source: IBM Cost of a Data Breach Report 2024
additional days to contain it
Combined: nearly 9 months of exposure before full resolution
IBM Cost of a Data Breach — 2023–2025
Industrial Sector: Average Data Breach Cost (USD M)
That is nearly nine months of exposure before an incident is fully resolved — an outcome no operations director can accept. Effective OT resilience must therefore serve two masters simultaneously: the CISO, who needs to contain threats and maintain the security posture, and the Production Head, who needs the line to keep running. Any solution that addresses one at the expense of the other will fail in practice.
—
Regulatory Drivers: NIS2 and Business Continuity
The NIS2 Directive makes this dual mandate a regulatory requirement. Article 21 explicitly requires covered entities to implement risk management measures encompassing incident handling, business continuity, crisis management, and supply chain security. In January 2026, the European Commission proposed targeted amendments to simplify compliance further while maintaining stringent resilience requirements.
For industrial operators, NIS2 compliance means going beyond IT disaster recovery. It requires continuity of the organisation's business processes as a whole, including OT environments where physical production depends on the availability and integrity of control systems. Management bodies are personally accountable for compliance failures, and essential entities face significant fines:
max NIS2 fine per violation
of global turnover (alternative penalty)
For essential entities, regulators apply whichever threshold is higher, and management bodies can be held personally accountable. These are statutory maximums; actual enforcement timelines and levels vary by member state. With resilience-oriented investments driving much of the growth, Gartner's global information security spending forecast confirms the market is responding:
projected global infosec spending in 2026
Source: Gartner Forecast, 4Q25 Update
year-on-year increase in security spending
Resilience-oriented investments driving the growth
The alignment between regulatory pressure, market spending, and operational reality creates a clear mandate: invest in resilience now, or face compounding risk.
Phase 1
Before the Incident: Anticipation & Preparation
The strongest form of resilience is never being tested. Whilst no defence is impenetrable, the measures organisations put in place before an incident determine whether an intrusion becomes a nuisance or a catastrophe.
WALLIX PAM delivers a set of anticipatory controls that serve both cybersecurity and operational objectives.
Cybersecurity Perspective
The goal is clear: reduce the attack surface, harden identity controls, and ensure complete visibility over who accesses what. WALLIX achieves this through several reinforcing mechanisms.
Production Benefit
These same controls translate into resilience advantages that directly strengthen the organisation's ability to anticipate threats, limit their impact, and recover cleanly.
Strong authentication & MFA
Cybersecurity Perspective
Multi-factor authentication, privileged account management, and a dedicated third-party identity provider block identity-based intrusions before they start. Even if attackers steal credentials, they still cannot get in. IBM X-Force 2026 data shows that nearly a third of manufacturing attackers used compromised credentials to access administrative and operational systems once inside, making controlled identity management an essential first line of defence.
Production Benefit
Strong authentication eliminates the credential habits that create silent liability: shared passwords, generic contractor accounts, and credential reuse that destroy accountability when something goes wrong. Every action is traceable to a named individual from the moment they connect. When an incident occurs, you have the evidence to understand it.
Granular access control (RBAC)
Cybersecurity Perspective
Role-based, time-based, and asset-based access restrictions ensure users can access only the systems they are authorised for, nothing more. This limits lateral movement and prevents both accidental and deliberate access to sensitive OT assets.
Production Benefit
There is no risk of third parties exceeding their privileges, which could otherwise lead to misconfigurations or production incidents that are impossible to trace. Access is strictly bound to what each role requires; lateral movement and privilege overreach are blocked at the source.
SRA Bastion (IT/OT segmentation)
Cybersecurity Perspective
The WALLIX Secure Remote Access bastion sits at the IT/OT boundary, creating a clean, enforceable separation with trust zones and conduits aligned to IEC 62443. Attackers struggle to reach the industrial network, and you stay compliant without redesigning your entire infrastructure.
Production Benefit
The WALLIX PAM acts as a proxy in the iDMZ layer, offering a shield approach that preserves OT production: no more shadow VPNs or uncontrolled IT-to-OT access paths. One controlled gateway means fewer unmanaged connections to trace when something goes wrong, and complete traceability across all vendor activity from the moment of connection.
Full session recording & audit
Cybersecurity Perspective
Every remote connection. Every privileged operation. No blind spots, no assumptions. You can prove who did what, when, and why. This is a requirement under both NIS2 and IEC 62443.
Production Benefit
When something goes wrong on the line, you know exactly who was connected and what they did. No more guessing which remote session or recent change caused the issue.
Third-party access governance
Cybersecurity Perspective
Remote vendors connect only through the secure gateway, with no direct PLC/SCADA VPN access. In the event of an incident, there are no unmanaged connections to trace; everything runs through a centralised access platform with full traceability.
Production Benefit
Vendors and contractors reach the systems they need through a controlled, governed pathway rather than an open VPN that bypasses every security control. Every external party is authenticated, their access is scoped to specific assets, and their session is approved before it opens.
Session approval workflows
Cybersecurity Perspective
No external party connects to your operational environment without explicit approval. OT teams review and authorise remote sessions before they are activated. OT teams can approve, deny, and monitor in real time. This closes a critical gap: unknown or forgotten remote sessions that have historically provided attackers with an open door into industrial networks.
Production Benefit
Session approval gives OT teams direct control over who gets in and when. Remote access requests come to you for approval before any connection is established, and only authorised persons can perform maintenance on critical equipment. No more discovering after the fact that someone was inside a control system you did not know about.
SOC/SIEM integration
Cybersecurity Perspective
Detailed access logs feed directly into your SOC. Unusual activity gets spotted earlier, dots get connected faster, and your team responds before an intrusion becomes a production-threatening incident.
Production Benefit
Unusual access patterns are flagged early, before they lead to unplanned downtime or unexpected configuration changes. SOC/SIEM integration means your security team sees the same picture your OT team does, and both can act on it before an anomaly becomes an incident.
Legacy asset protection
Cybersecurity Perspective
Older PLCs, HMIs, and controllers without modern security features need not remain the weakest link. Encrypted, authenticated, supervised access protects these assets without touching the equipment itself, reducing attack surface and buying time before costly upgrades.
Production Benefit
Crucially, legacy equipment stays in production. Older PLCs, HMIs, and controllers can be protected with access controls without requiring costly upgrades or replacements. They remain defensible under governance, bought time before any forced replacement decision.
Credential Governance
Cybersecurity Perspective
Credentials are the keys to your OT environment. A vault stores them securely, rotates them automatically, and revokes them instantly when an incident breaks out or a vendor contract ends. Some legacy assets (field devices, protection relays, certain PLCs) rely on fixed credentials and cannot rotate. For those, controlled access takes over: every request is known, every session recorded, accountability never in question.
Production Benefit
Credentials vaulted and governed. Rotation where assets support it; controlled access and full session recording, where they don't.
Phase 2
During the Incident: Response & Containment
When an intrusion is detected, every second counts. The difference between a contained incident and a full-scale production shutdown often comes down to how quickly and decisively an organisation can respond.
WALLIX PAM provides the tools to limit propagation and maintain operational control without forcing a complete shutdown.
Cybersecurity Perspective
The priority is containment: cut off attacker access, preserve forensic evidence, and maintain full visibility over every active session while the threat is neutralised.
Production Benefit
The priority during an incident is to keep the line running, or at a minimum, to control the degradation. WALLIX's response capabilities are designed with this reality in mind.
Centralised kill switch
Cybersecurity Perspective
One control point terminates all remote connections across the entire operational environment. When an intrusion is detected, attacker access is cut in seconds, before they reach critical systems. This is the kind of capability that turns a potential catastrophe into a manageable event.
Production Benefit
Remote access shuts down instantly when needed. You are not waiting on IT to act. Critical systems are protected in seconds, minimising exposure and potential downtime.
Immediate account suspension
Cybersecurity Perspective
Compromised user accounts and third-party credentials get disabled the moment a threat is identified, with no waiting for manual password resets or policy updates. The threat is immediately locked out while your audit trail remains intact.
Production Benefit
Compromised or suspected accounts are locked out without disrupting the rest of the team; the rest of the team keeps working while the threat is contained.
Real-time session monitoring
Cybersecurity Perspective
Suspicious behaviour shows up as it happens: unexpected commands, unusual lateral movement, multiple sessions from the same account, and connections outside standard patterns. Dedicated security team members are alerted and can step in before damage occurs.
Production Benefit
Flags anomalies before they impact the production line. If a remote change caused an issue, you can trace exactly what happened, with no guesswork or finger-pointing, just clear answers.
Isolated mode (Unified Console)
Cybersecurity Perspective
External remote connections can be temporarily turned off via the WALLIX ONE Remote Access Unified Console, while internal monitoring and essential access remain active. Your operational environment is shielded during investigation without losing visibility or forcing a complete shutdown.
Production Benefit
External connections pause while internal operations continue. You investigate without forcing a full production shutdown, maintaining visibility throughout the process.
Encrypted session preservation
Cybersecurity Perspective
Every action taken during an incident is captured and preserved in tamper-proof, encrypted recordings. Evidence is ready for post-incident analysis, compliance reporting, and potential legal proceedings.
Production Benefit
If a remote change caused an issue, you can trace exactly what happened, with no guesswork or finger-pointing, just clear answers.
Automatic SOC alerting
Cybersecurity Perspective
Immediate alerts go to your SOC when suspicious remote activity is detected. No delays, no missed signals. Your response team mobilises the moment something looks wrong.
Production Benefit
Faster awareness means less time lost to escalation. Your response team mobilises the moment something looks wrong.
Break glass mechanism
Cybersecurity Perspective
Emergency access to critical systems remains available even when standard authentication pathways are compromised. Production teams can continue operating safely while the incident remains contained.
Production Benefit
Production is not blocked by its own equipment during an emergency incident, whether a cyber event, fire, or electrical failure. Access to critical systems remains available even when Secure Remote Access is down.
Local control fallback
Cybersecurity Perspective
When remote pathways are under attack, critical production continues only through secure on-site access. Operations do not stop; they revert to the most secure access method until the threat is neutralised.
Production Benefit
When remote access is compromised, operations shift to secure on-site access. The line keeps running while the threat is dealt with.
Phase 3
After the Incident: Recovery & Improvement
How an organisation recovers from an incident determines whether it comes back stronger or remains vulnerable to the next attack. The post-incident phase is where resilience is truly built, through forensic understanding, systematic remediation, and validated recovery.
WALLIX PAM ensures that recovery is thorough, controlled, and feeds directly into strengthened defences.
Cybersecurity Perspective
The goal shifts to hardening: trace the full attack path, eliminate every compromised credential, and ensure that restored access is tighter than what existed before the incident.
Production Benefit
The post-incident phase is about getting back to full operations on a stronger footing. WALLIX's recovery capabilities ensure this happens without the chaos that typically follows a security event.
Forensic log & video review
Cybersecurity Perspective
Detailed access logs and video recordings let you trace the complete attack timeline. You understand exactly which credentials were compromised, what systems were accessed, and how the attacker moved through your environment. This is the foundation for every improvement that follows.
Production Benefit
You understand exactly what happened without weeks of forensic investigation. Access logs and session recordings pinpoint which user, remote session, or credential was involved.
Credential & SSH key rotation
Cybersecurity Perspective
Passwords and access keys for all remote accounts get rotated systematically. Any credentials that may have been exposed are eliminated so attackers cannot use them to re-enter your environment.
For legacy OT assets that cannot be rotated, you still gain clean accountability: every credential mapped to a named person, every access right justified, nothing left open by default.
Production Benefit
Rotation where assets support it. For legacy OT assets, clean accountability steps in, credentials mapped, access justified, nothing left open.
Access rights reassessment
Cybersecurity Perspective
Outdated user accounts are removed. Third-party permissions are refined. Excessive privileges discovered during the incident are eliminated.
Every access right is validated against current operational needs and the principle of least privilege.
Production Benefit
Access rights reflect who actually needs access today. Outdated accounts, over-privileged vendors, and forgotten contractor credentials are cleaned out, which reduces future risk.
Controlled reactivation
Cybersecurity Perspective
Remote access is restored progressively, not rushed. Each connection pathway is tested and verified before going live, and only after security validation confirms that vulnerabilities are addressed and monitoring is enhanced.
Production Benefit
Production resumes on a stronger footing, with remote access coming back online progressively and each connection pathway validated before it goes live.
Sectors in scope
OT resilience is a cross-industry imperative

Pipelines, grid, generation
Energy & Utilities

Hospitals & medical devices
Healthcare

Factories & production lines
Manufacturing
PAM Resilience Measures
A unified view of WALLIX PAM capabilities across all three phases of incident resilience.
Before the incident
Strong authentication & MFA
Granular access control (RBAC)
SRA Bastion (IT/OT segmentation)
Full session recording & audit
Third-party access governance
Session approval workflows
SOC/SIEM integration
Legacy asset protection
Credential Governance
During the incident
Centralised kill switch
Immediate account suspension
Real-time session monitoring
Isolated mode (Unified Console)
Encrypted session preservation
Automatic SOC alerting
Break glass mechanism
Local control fallback
After the incident
Forensic log & video review
Credential & SSH key rotation
Access rights reassessment
Controlled reactivation
Regulatory Alignment: NIS2 and IEC 62443
The three-phase resilience framework directly addresses specific regulatory requirements. NIS2 Article 21 mandates risk management measures covering incident handling, business continuity, and supply chain security. IEC 62443-3-3 requires specific capabilities for access control, network segmentation, and audit at each Security Level.
NIS2 Directive
Article 21 — Risk management measures
Art. 21(b) — Incident handling
Kill switch, real-time monitoring, SOC alerting, isolated mode
Art. 21(c) — Business continuity
Break glass, local fallback, controlled reactivation of remote access
Art. 21(d) — Supply chain security
Third-party governance, session approval workflows, dedicated IDP
Art. 21(g) — Access control & MFA
Strong authentication, RBAC, privileged account management
IEC 62443
Functional requirements for industrial security
FR1 — Identification & Authentication
MFA, dedicated OT identity provider, session approval workflows
FR5 — Network segmentation
SRA Bastion at IT/OT boundary — trust zones and conduits enforced
FR6 — Audit & accountability
Full session recording, forensic log review, encrypted preservation
Conclusion
The question for industrial organisations in 2026 is no longer whether they will face a cyber incident, but how well they will cope when it happens. With manufacturing firmly established as the most targeted sector for the fifth consecutive year, the average industrial breach taking over nine months to fully identify and contain, and regulators now holding executives personally accountable for resilience failures, the stakes could not be higher.
WALLIX PAM addresses this reality with a practical, three-phase resilience framework that works for both the CISO and the Production Head. Before an incident, it hardens access controls, segments networks, and creates complete audit trails. During an incident, it provides instant containment capabilities — from centralised kill switches to isolated mode — without forcing a full production shutdown. After an incident, it enables thorough forensic analysis, systematic credential rotation, and controlled, validated recovery.
What sets this approach apart is the refusal to treat security and operations as competing priorities. Every measure is designed to serve both: the kill switch cuts attacker access and shields production from further damage. Session recordings provide forensic evidence and answer production troubleshooting questions. Legacy asset protection reduces attack surface and keeps critical systems defensible without forcing premature replacement.
For OT environments, those new approaches must be purpose-built. A factory floor is not a server room. Production continuity is non-negotiable. And the best security is security that people actually use — because it does not get in the way of their work. Resilience is not a product feature. It is an operational philosophy. WALLIX PAM gives organisations the tools to make that philosophy real.
avg. time to fully resolve an industrial breach
199 days to identify + 73 days to contain — source: IBM Cost of a Data Breach Report 2024
manufacturing ranked #1 most attacked sector
The most targeted sector for ransomware for five consecutive years — source: IBM X-Force 2026
WALLIX
Resilience is an operational philosophy
A factory floor is not a server room. Production continuity is non-negotiable. The best security is security that people actually use — because it does not get in the way of their work. WALLIX PAM gives organisations the tools to make resilience real.
Yoann DELOMIER
OT Business Strategic Leader
References
- [1]IBM X-Force (2026). X-Force Threat Intelligence Index 2026. Published February 2026. https://www.ibm.com/reports/threat-intelligence
- [2]IBM Security (2024). Cost of a Data Breach Report 2024. Ponemon Institute / IBM. July 2024. https://www.ibm.com/reports/data-breach
- [3]Gartner (2026). Top Cybersecurity Trends for 2026. Press Release, 5 February 2026. https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026
- [4]European Commission (2022). Directive (EU) 2022/2555 — NIS2 Directive. https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
- [5]Gartner (2025). Forecast: Information Security, Worldwide, 2023–2029, 4Q25 Update. G00843183, 18 December 2025.
Get started
Ready to get started?
Our experts will assess your current OT environment and recommend a tailored PAM resilience roadmap.
Talk to an OT security expert
