02:07. Change request 0412 has been open for nineteen minutes. Type: emergency. Summary: install the responder's collection agent on two engineering workstations and the historian. Status: awaiting approval. The approver's phone goes to voicemail. The next change board meets Tuesday at 10:00.
On the floor, the process runs normally. The responder sits on the bridge call with a laptop open and nothing to point it at. Every minute the ticket waits, whoever is inside the network keeps the initiative.
That plant is invented. The ticket is not, or not quite. A version of it slowed a real response in 2024, at an organisation with a plan, endpoint detection and a change board.
This piece is for whoever owns an OT incident response plan that has never been run against a clock. If you ran an injects-based exercise this year and the plan held, you can stop here.
The case file: a federal agency, three weeks, one change board
Be clear about the source before anything is built on it. CISA advisory AA25-266A, published September 23, 2025, describes an incident response engagement at a U.S. federal civilian executive branch agency. An office network, not a plant. No controllers, no safety systems, no process.
The attackers got in on July 11, 2024 through CVE-2024-36401, a flaw in a public-facing GeoServer, and came back through a second GeoServer on July 24. The agency's EDR flagged one of their tools on July 15. Nobody acted on that alert. The activity, in CISA's words, "remained undetected for three weeks."
Detection is not the subject here. What happened after the agency called for help is. Read these four sentences slowly:
"Their IRP did not have procedures for bringing in third parties for assistance, which hampered CISA's efforts to respond to the incident quickly and efficiently. The agency could not provide CISA remote access to their security information and event management (SIEM) tool, which initially kept CISA from reviewing all available logs, hindering CISA's analysis. The agency had to go through their change control board process before CISA could deploy their EDR agents. The agency could have proactively identified these roadblocks by testing their IRP, such as via a tabletop exercise, but had not tested their plan for a long period."
Three roadblocks. None of them technical, all of them in place long before the attacker arrived. The advisory does not say how many hours they cost, so this article will not guess.
Why a plant has it worse
Now move the same three roadblocks onto an industrial site. Each one gets heavier.
Plants route control-system changes through management of change because a bad change can hurt someone, and the people who sign them are rightly slow to sign at night. Remote access to the plant network is hard to grant by design. And the outside help you need is often the controller vendor, whose support contract procurement negotiated on a weekday and nobody on the response team has read.
So the lesson transfers with one adjustment. At a plant, the roadblocks sit on top of safety rules that should not be bypassed. That makes settling them in daylight more urgent, not less.
One check before going further: can you name, right now, the person who approves an emergency change on your OT network at 02:00, and their number? If yes, this section is not your problem, and inject 3 below probably is.
The change manager: "Pre-approval is a blank cheque"
"The board exists so that nobody installs unknown software on production systems at two in the morning. You are asking me to sign off changes nobody has seen yet. That is exactly what an attacker would want me to do."
Fair, and inject 1 does not ask you to drop control. It asks you to move the decision. CISA does not recommend bypassing the board. It recommends writing "processes for expediating deployment of EDR and other security tools through change control boards" (CISA's spelling) into the plan before an incident.
In practice the board meets once and approves a short list: which tools, which versions, which hosts may take them, who may install them, and a review of every emergency change within a set number of days. The board still decides. It decides on a Tuesday instead of at 02:07.
The OT engineer: "Nobody touches my HMIs at night"
"I have watched endpoint software lock up an operator station. You are not putting an agent on my HMIs in the middle of an incident because a consultant asked for it. On my side of the fence, the change board is a safety feature."
Agreed, and the inject should record that position, not overrule it. The useful answer to inject 1 at a plant is often a no with detail: agents allowed on the engineering workstations and the historian, never on operator stations or controllers, and passive network capture everywhere else. That is a decision. Written down, it turns a 02:00 argument into a 02:00 lookup.
The engineer should also own inject 2. They know which systems have shared accounts and which have exactly one person who can log in. The agency could not get CISA into its log platform. A plant that cannot get its own engineer into the historian at night has the same problem, closer to the process.
The site director: "The vendor will never sit in a tabletop"
"I can barely get my own shift supervisors into a room. The controller vendor will not come, legal will not come, and none of them will be awake at two in the morning in a real incident either. So what exactly does the exercise prove?"
It proves what happens when they are absent, which is the situation you will face. Injects 3 and 4 need no vendor and no lawyer in the room. They need someone to dial the out-of-hours number during the exercise, then pull the contract and read the response clause aloud. If the number rings out or the clause says next business day, you have the roadblock in fifteen minutes.
CISA's own advice goes further than this: it recommends including "engagement with third party incident responders and external EDR agents and other tools" during the test. Start with the dial test. Invite the vendor once you know what you need from them.
Back to the ticket
Look again at change request 0412. Every field was correct and the process was followed. The approver field held a real name: someone who moved to another site in March. Nobody had updated the plan, because nobody had ever run it.
The CISA case has the same shape. The agency had a plan. It lacked a test of it, so the roadblocks waited for the worst hour to show themselves. An hour in a meeting room would have shown them on a weekday.
Sources: CISA, AA25-266A: CISA Shares Lessons Learned from an Incident Response Engagement, September 23, 2025 | NIST NVD, CVE-2024-36401


