OT cyber incident reports

Identifies substantive operational-technology, ICS, SCADA, and industrial-control cyber incident reports. Topic phrases are retained for discovery; enforcement requires case facts such as affected assets, timelines, initial access, containment, indicators, root cause, recovery, or operational impact, and high confidence also requires a concrete indicator, vulnerability, address, or control asset identifier.

Type
regex
Engine
boost_regex
Confidence
medium
Confidence justification
Medium confidence requires incident-specific case facts. High confidence adds a concrete technical indicator or affected control asset, reducing matches on policy and generic threat reporting.
Detection quality
Topic false positive
Jurisdictions
global
Regulations
GDPR
Data categories
security
Scope
wide
Risk rating
8
Platform compatibility
Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported

Pattern

(?is)\b(?:OT\s+cyber\s+incident\s+report|ICS\s+cyber\s+incident\s+report|SCADA\s+compromise\s+report|industrial\s+control\s+system\s+cyber\s+incident|operational\s+technology\s+security\s+incident\s+report)\b

Corroborative evidence keywords

ot cyber incident reports, cyber, incident, reports, critical, infrastructure, systems, SCADA, [object Object], [object Object], [object Object], Modbus, Modbus TCP, Modbus RTU, DNP3, OPC-UA, OPC Classic, IEC 61850, IEC 60870, IEC 60870-5-104 (+9 more)

Proximity: 300 characters

Should match

Should not match

Known false positives

References