Table of Contents
Fetching ...

Everyone Needs AIR: An Agnostic Incident Reporting Framework for Cybersecurity in Operational Technology

Nubio Vidal, Naghmeh Moradpoor, Leandros Maglaras

TL;DR

This paper tackles the lack of structured, live incident reporting in OT environments by introducing AIR, a modular 25-element framework organized into seven groups that abstracts IT incident-reporting guidance for OT constraints. AIR is agnostic to specific OT architectures and can be layered onto existing OT frameworks to standardize fields, terminology, and timing across multi-stakeholder contexts, enabling better situational awareness and regulatory alignment. The authors map AIR to OT standards (ISA/IEC 62443, NERC CIP) and IT standards (ISO/IEC 27035, NIST SP 800-61r3), show how AIR activates during incident escalation, and demonstrate its utility with a retrospective application to the 2015 Ukrainian oblenergos attack. Overall, AIR offers a practical baseline for cross-organizational, regulator-ready live OT incident reporting, with potential for future practitioner validation and real-time implementation.

Abstract

Operational technology (OT) networks are increasingly coupled with information technology (IT), expanding the attack surface and complicating incident response. Although OT standards emphasise incident reporting and evidence preservation, they do not specify what data to capture during an incident, which hinders coordination across stakeholders. In contrast, IT guidance defines reporting content but does not address OT constraints. This paper presents the Agnostic Incident Reporting (AIR) framework for live OT incident reporting. AIR comprises 25 elements organised into seven groups to capture incident context, chronology, impacts, and actions, tailored to technical, managerial, and regulatory needs. We evaluate AIR by mapping it to major OT standards, defining activation points for integration and triggering established OT frameworks, and then retrospectively applying it to the 2015 Ukrainian distribution grid incident. The evaluation indicates that AIR translates high-level requirements into concrete fields, overlays existing frameworks without vendor dependence, and can support situational awareness and communication during response. AIR offers a basis for standardising live OT incident reporting while supporting technical coordination and regulatory alignment.

Everyone Needs AIR: An Agnostic Incident Reporting Framework for Cybersecurity in Operational Technology

TL;DR

This paper tackles the lack of structured, live incident reporting in OT environments by introducing AIR, a modular 25-element framework organized into seven groups that abstracts IT incident-reporting guidance for OT constraints. AIR is agnostic to specific OT architectures and can be layered onto existing OT frameworks to standardize fields, terminology, and timing across multi-stakeholder contexts, enabling better situational awareness and regulatory alignment. The authors map AIR to OT standards (ISA/IEC 62443, NERC CIP) and IT standards (ISO/IEC 27035, NIST SP 800-61r3), show how AIR activates during incident escalation, and demonstrate its utility with a retrospective application to the 2015 Ukrainian oblenergos attack. Overall, AIR offers a practical baseline for cross-organizational, regulator-ready live OT incident reporting, with potential for future practitioner validation and real-time implementation.

Abstract

Operational technology (OT) networks are increasingly coupled with information technology (IT), expanding the attack surface and complicating incident response. Although OT standards emphasise incident reporting and evidence preservation, they do not specify what data to capture during an incident, which hinders coordination across stakeholders. In contrast, IT guidance defines reporting content but does not address OT constraints. This paper presents the Agnostic Incident Reporting (AIR) framework for live OT incident reporting. AIR comprises 25 elements organised into seven groups to capture incident context, chronology, impacts, and actions, tailored to technical, managerial, and regulatory needs. We evaluate AIR by mapping it to major OT standards, defining activation points for integration and triggering established OT frameworks, and then retrospectively applying it to the 2015 Ukrainian distribution grid incident. The evaluation indicates that AIR translates high-level requirements into concrete fields, overlays existing frameworks without vendor dependence, and can support situational awareness and communication during response. AIR offers a basis for standardising live OT incident reporting while supporting technical coordination and regulatory alignment.
Paper Structure (16 sections, 4 figures, 4 tables)

This paper contains 16 sections, 4 figures, 4 tables.

Figures (4)

  • Figure 1: OT standards: responsibilities, reporting and coordination
  • Figure 2: IT standards: responsibilities, reporting and coordination
  • Figure 3: AIR in the ISO 5-phase model incident management lifecycle
  • Figure 4: AIR layer added to (a) PREATORIAN and (b) CROF