Quick Breakdown of CyOTE: What 27 OT Incidents Tell Us

Analysis | | Control Systems Security

Attack Vectors Credentials OT Incident Analysis MITRE ATT&CK ICS

Executive Summary

Idaho National Laboratory's CyOTE Insights database catalogues 27 real-world operational technology (OT) cyber incidents from 2000 through 2022. Each incident is mapped to the MITRE ATT&CK for ICS framework with technique-level detail.

We pulled the full technique frequency data. The result is simple: the same five attack vectors dominate every breach.

The Top 5 OT Attack Vectors

78% Valid Accounts — the #1 vector
63% Service Stop — stopping incident response
63% Scripting — execution mechanism
59% Data Destruction — wiping systems
56% Masquerading — hiding in plain sight

Source: CyOTE Insights v1.0.0, Idaho National Laboratory, 27 case studies

Initial Access: How They Get In

Of the 12 distinct initial access techniques in the MITRE ATT&CK ICS matrix, three dominate:

Initial Access techniques across 27 OT incidents

Valid Accounts appears in 21 of 27 incidents (78%). It's used both for initial access and lateral movement — the same credential set that gets the attacker in lets them move through the network.

Remote Services is second at 14 incidents (52%). VPNs, RDP, GoToMyPC — any remote access tool is a potential entry point. The Kansas water utility attack (2019) used a former employee's unrevoked GoToMyPC credentials. Colonial Pipeline (2021) used an expired VPN account linked to leaked dark web passwords.

Spearphishing accounts for 11 incidents (41%). Norsk Hydro (2019), Conti on the Irish HSE (2021), and Industroyer in Ukraine (2016) all started with a malicious email attachment.

The pattern: 78% of OT breaches start with stolen, shared, or unrevoked credentials. The other 22% start with phishing, supply chain compromise, or physical media. If you have credential hygiene and email filtering, you've addressed the vast majority of initial access risk.

Impact: What They Do When They're In

The impact taxonomy tells a different story. Most OT attacks aren't about data theft — they're about operational disruption:

Impact techniques across 27 OT incidents

Loss of Productivity and Revenue is the most common impact (19/27, 70%). This isn't surprising — every ransomware attack falls here. But Loss of Availability at 16/27 (59%) is more significant: systems are rendered inoperable, not just encrypted.

Manipulation of Control appears in only 8 incidents, but it's the one that matters most for OT. This is the category where attackers actually changed industrial processes — Ukraine's grid breakers (2015, 2016), Oldsmar water treatment (2021), BTC pipeline (2008). Low frequency, maximum severity.

The Five-Vector Attack Chain

Looking at technique co-occurrence across all 27 incidents, a consistent attack chain emerges:

Step 1: Valid Accounts → Initial access via compromised credentials │ ▼ Step 2: Remote Services → Lateral movement through network │ ▼ Step 3: Scripting → Execute payloads and tools │ ▼ Step 4: Masquerading → Hide activity from defenders │ ▼ Step 5: Service Stop → Disable incident response capability │ ▼ Step 6: Data Destruction → Wipe systems, encrypt files │ ▼ Result: Loss of Productivity / Availability

This chain appears — with variations — in 17 of the 27 incidents. The most complete implementations: Industroyer (2016, 29 techniques), INCONTROLLER (2022, 36 techniques), JBS Foods (2021, 22 techniques), and Conti on the Irish HSE (2021, 21 techniques).

Complexity Is Trending Up

Attack technique count has increased steadily over the 22-year span:

Technique count per incident, 2000–2022

Maroochy Shire (2000) used 16 techniques. INCONTROLLER (2022) used 36 — more than double. The trend is clear: attacks are getting more sophisticated, not less.

What Defenders Should Do

Priority 1: Credential Hygiene (addresses 78% of initial access)

Priority 2: Email Filtering + User Training (addresses 41% of initial access)

Priority 3: Service Continuity Controls (addresses 63% of defense inhibition)

Priority 4: Masquerading Detection (addresses 56% of evasion)

Data Source

All analysis based on Idaho National Laboratory's CyOTE Insights v1.0.0 — a curated database of 27 OT cyber incidents with MITRE ATT&CK ICS technique mappings. The tool is available at github.com/idaholab/Insights.

← Home Articles Products

AOT Framework — Adaptive Operational Technology

AI-centric OT defense that moves from passive visibility to machine-speed, closed-loop cyber resilience. Discover the maturity model and cornerstone defense architecture.

Explore the AOT Framework