OT cyber incident reports
Identifies substantive operational-technology, ICS, SCADA, and industrial-control cyber incident reports. Topic phrases are retained for discovery; enforcement requires case facts such as affected assets, timelines, initial access, containment, indicators, root cause, recovery, or operational impact, and high confidence also requires a concrete indicator, vulnerability, address, or control asset identifier.
- Type
- regex
- Engine
- boost_regex
- Confidence
- medium
- Confidence justification
- Medium confidence requires incident-specific case facts. High confidence adds a concrete technical indicator or affected control asset, reducing matches on policy and generic threat reporting.
- Detection quality
- Topic false positive
- Jurisdictions
- global
- Regulations
- GDPR
- Data categories
- security
- Scope
- wide
- Risk rating
- 8
- Platform compatibility
- Purview: Compatible, GCP DLP: Compatible, Macie: Compatible, Zscaler: Compatible, Palo Alto: Degraded, Netskope: Unsupported
Pattern
(?is)\b(?:OT\s+cyber\s+incident\s+report|ICS\s+cyber\s+incident\s+report|SCADA\s+compromise\s+report|industrial\s+control\s+system\s+cyber\s+incident|operational\s+technology\s+security\s+incident\s+report)\b
Corroborative evidence keywords
ot cyber incident reports, cyber, incident, reports, critical, infrastructure, systems, SCADA, [object Object], [object Object], [object Object], Modbus, Modbus TCP, Modbus RTU, DNP3, OPC-UA, OPC Classic, IEC 61850, IEC 60870, IEC 60870-5-104 (+9 more)
Proximity: 300 characters
Should match
OT cyber incident report— Low-tier probe - incident-report topic without case factsOT cyber incident report: affected asset, attack timeline, initial access, containment action, root cause, and recovery status— Medium-tier probe - substantive case facts without a concrete technical indicatorOT cyber incident report: affected PLC asset PLC-07, source IP 10.24.8.15, CVE-2025-12345, attack timeline, containment action, and recovery status— High-tier probe - case facts with control-asset, address, and vulnerability indicators
Should not match
unrelated generic text without domain phrases— No relevant topic phrases presentplaceholder value 12345— Random text should not match topic-specific regexot cyber incident report— Bare report title surfaces only in discoveryThe public advisory describes industrial-control malware trends.— Public threat overview without an organisation-specific incident reportTraining example: OT cyber incident report for PLC-07 at source IP 10.24.8.15, CVE-2025-12345— Explicit training content must not enforce
Known false positives
- Public advisories, vendor threat reports, news, and exercises discuss OT incidents, indicators, containment, and affected technologies without exposing an organisation's case report. Mitigation: Require incident-specific case facts and reject explicit public-advisory, vendor-report, news-report, and exercise framing from enforcing tiers.
- Training scenarios can contain realistic CVEs, IP addresses, hashes, PLC IDs, timelines, and containment actions. Mitigation: Reject explicit template, demo, tutorial, sample-data, and training-example framing from enforcing tiers.
References
- https://www.legislation.gov.au/C2018A00029/latest/text
- https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism
- https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/preventing-preparing-for-and-responding-to-data-breaches/data-breach-preparation-and-response