How a threat assessment uses MITRE ATT&CK for ICS

Updated 15 September 2026 · 6 minute read

Most security assessments start from a standard and ask what is missing. A threat assessment starts from the adversary and asks what they would actually do to your plant. MITRE ATT&CK for ICS is the shared language for that conversation.

What ATT&CK for ICS is

ATT&CK is a knowledge base of adversary tactics and techniques built from observed intrusions. The ICS matrix describes behaviour against control systems specifically: how attackers get in, move, find the controllers, and then disrupt the process.

Its twelve tactics run from initial access, execution, persistence, privilege escalation and evasion, through discovery, lateral movement, collection and command and control, to the three that only exist in OT: inhibit response function, impair process control, and impact.

Why the last three matter most

In IT the damage is usually data. In OT the damage is physical. Inhibit response function covers techniques that stop operators and safety systems from reacting: blocking alarms, denying the HMI, disabling a safety controller. Impair process control covers techniques that change what the process does: modifying a parameter, sending an unauthorised command, spoofing a reported value. Impact is the consequence: loss of view, loss of control, loss of safety, damage to property.

A threat assessment that stops at the corporate perimeter never reaches these. One that starts with them, and works backwards to how an adversary would get there, produces priorities the plant recognises.

How the assessment runs

  • Understand the process: what the plant does, which functions would hurt if lost, and which systems perform them.
  • Map the estate against the matrix: for each realistic technique, is there a path to it in this environment? A vendor VPN into the engineering network, a flat network between the historian and the controllers, a default credential on a relay.
  • Weigh by consequence: a technique that could reach a safety system outranks one that could reach a reporting server.
  • Choose the controls that break the most paths: segmentation that removes lateral movement, monitoring that detects discovery and unauthorised commands, access control that removes the easy initial access.
  • Write it down as a plan the operations team can run, sequenced by risk and by outage window.

What it is not

It is not a penetration test. We work from architecture, configuration and interviews, and add on-network evidence only where it is safe to collect. It is not a substitute for a standards-based risk assessment either; the two are complementary, and many clients scope them together.

Sources
  • MITRE ATT&CK for ICS

Want this applied to your plant?

Tell us the site, the systems and the regulator. A consultant will reply, not a sales queue.