OT ransomware: when they take production and the data
Ransomware crews have learned that a stopped production line pays faster than encrypted files. What the double-extortion play looks like against OT, and how to blunt it.
The play
Intrusion comes through IT: stolen credentials, exposed remote access, or a compromised supplier. Then quiet reconnaissance, data exfiltration to create leverage, and finally encryption timed for maximum disruption — increasingly reaching toward the systems that run operations, where the pressure to pay is greatest.
Why OT raises the stakes
You cannot simply reimage a PLC or take a safety system offline to clean it. The threat of stopped production, or the fear of an unsafe state, is itself the leverage. That is why extortion against manufacturers, utilities and logistics operators has climbed — the cost of downtime dwarfs the ransom.
Blunting it
Enforce IT/OT segmentation so an IT compromise cannot walk into the plant. Monitor OT passively for the reconnaissance and lateral movement that precede encryption. Keep offline, tested backups. And rehearse the incident with operations in the room, so containment decisions respect safety and uptime rather than fighting them.
Questions, answered
Should we ever pay?
Can you monitor OT without risking it?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.