Most ransomware playbooks are written for IT and assume systems can be isolated and rebuilt with no physical consequence. In an OT environment, several of those assumptions do not hold, and the plan needs to account for that in advance.

Pre-approve the isolation decision

Decide now, not during the incident, who has the authority to isolate OT from a compromised IT environment, and under what conditions. This decision should be jointly owned by security and operations.

Assume segmentation until you can prove otherwise

If IT is compromised, the operational question is not just 'is OT infected' -- it is 'can we prove OT was never reachable.' If you cannot answer that quickly and confidently, plan for a precautionary shutdown decision path in advance.

Keep OT-relevant backups offline and tested

Configuration backups, engineering project files, and historian data all need offline, tested backups -- not just IT server backups. Test restoration regularly, not only when you need it.

Define your safe reconnection criteria

Before reconnecting any system to the OT network after an incident, know in advance what 'clean' means for that system class and who signs off on it.

Rehearse it

Run a tabletop exercise against this exact scenario at least annually. The gaps it reveals are far cheaper to find in a rehearsal than during a real event.