Ransomware in OT: Real Cases and Lessons Learned
Most ransomware that has caused OT operational impact did not directly encrypt PLCs or field controllers -- it encrypted IT systems, and the operator made the decision to shut down OT operations as a precaution because they could no longer trust or verify the integrity of systems connected to the affected IT environment. This distinction matters enormously for how an organization should prepare.
The well-known 2021 pipeline ransomware incident in the United States is a clear example: the ransomware hit corporate IT systems, including billing, and the operator proactively shut down pipeline operations because billing and operational systems were not confidently segmented enough to guarantee the OT side was unaffected -- resulting in days of fuel supply disruption from an attack that, technically, never touched the pipeline's control systems directly. The lesson is not 'segmentation failed' in a narrow technical sense -- it is that uncertainty about segmentation integrity was itself enough to force an operational shutdown, which is exactly why segmentation has to be provable, tested, and documented, not just assumed.
A second consistent lesson across OT ransomware cases: organizations that had a rehearsed, OT-specific incident response and business continuity plan recovered meaningfully faster than those improvising in real time, because they had already answered questions like 'how do we verify a system is clean before reconnecting it to the OT network' before they needed the answer under pressure.
The practical takeaway is that ransomware resilience for OT depends heavily on IT/OT segmentation that can be demonstrated and trusted under stress, offline and tested backups for both IT and OT-relevant systems, and a documented decision process for when and how to isolate OT from a compromised IT environment -- made in advance, not improvised during the incident.
Reading
6 minutes