Executive Brief
OT/ICS ransomware resilience is the ability to sustain or safely stop a critical operation when digital services, identities, engineering tools, data, or connected systems can no longer be trusted. It is not a product feature and it is not the same as having a backup. It is an operating capability that joins business ownership, safety, architecture, identity, monitoring, response, recovery, suppliers, and executive decisions.
NIST CSF 2.0 provides an enterprise risk structure across Govern, Identify, Protect, Detect, Respond, and Recover. NIST SP 800-61 Revision 3 places incident response inside cybersecurity risk management and continuous improvement. Together, they support a program that begins before the incident and ends only when evidence-backed improvements are complete. [1] [2]
Central Argument
A resilient OT organization can explain which operations are essential, which dependencies must remain trusted, which containment actions are safe, how minimum operations will continue, and what evidence is required before a full return to service.
Define the Operational Mission and Safe State
Begin with the service delivered by the physical process. Identify the critical product, utility, treatment, transportation, storage, laboratory, or building function; the people and communities that depend on it; the safety and environmental boundaries; and the contractual or regulatory consequences of interruption.
For each priority process, define maximum tolerable interruption, minimum viable operation, safe-state criteria, manual alternatives, required staffing, essential communications, and the sequence for a controlled stop and restart. This business context determines whether a cybersecurity action reduces risk or introduces new operational harm.
Build an Authoritative OT Asset and Dependency Model
An asset list should describe more than device name and address. The inventory should capture function, process relationship, owner, model, software, configuration, communication path, support status, criticality, safety dependency, data handled, external service, recovery source, and known operating constraints.
The joint 2025 OT asset inventory guidance recommends an inventory supported by a taxonomy that organizes assets by function and criticality. This structure supports vulnerability management, incident response, and mission continuity. [9]
Dependency mapping should include enterprise identity, domain services, virtualization, databases, file shares, engineering repositories, historians, time sources, remote-access systems, cloud platforms, telecommunications, utilities, vendors, and physical prerequisites. A process can be operationally dependent on a service that is not located in the OT network.
Create Controlled Connectivity Patterns
Every connection into or out of OT should have a documented purpose, accountable owner, initiating identity, permitted protocol or service, approved destination, monitoring, review date, and isolation method. Standard patterns should cover enterprise data exchange, remote support, engineering transfer, cloud analytics, supplier maintenance, and emergency access.
The control should fail predictably. If a vendor portal is unavailable, the fallback must not be an unmanaged remote desktop tool. If an engineering workstation cannot run a modern agent, transfer should occur through a controlled gateway with inspection and audit. If external connectivity is removed, the site should know which functions continue and which must transition to manual operation.
Govern Identity, Privilege, and Remote Access
Named and attributable access is the foundation. Shared accounts, persistent vendor credentials, unmanaged jump hosts, long-lived service secrets, and emergency accounts without review create uncertainty at the exact moment rapid containment is required.
Use strong authentication where technically feasible, privileged access workflows, time-bound approval, device requirements, session recording or equivalent evidence, command or service restrictions, and rapid revocation. Machine identities need named owners, constrained permissions, rotation, and monitoring just as human identities do.
Prioritize Vulnerabilities as Operational Pathways
Do not rank OT vulnerabilities by severity score alone. Combine exploitation evidence, exposure, accessibility, privilege gained, path to a critical process, available detection, vendor support, maintenance window, rollback, compensating controls, and the consequence of failure.
CISA's Cross-Sector Cybersecurity Performance Goals provide a voluntary high-impact baseline, while DOE's C2M2 supports progressive capability development and institutionalization. [7] [8] These resources can help leaders distinguish minimum practices from longer-term maturity.
Detect the Sequence, Not Only the Encryption
Detection should cover the sequence that precedes disruption. Watch for exposed-service exploitation, credential abuse, new remote tools, privilege changes, discovery, and movement across zones. Also monitor access to virtualization or backup management, security-control disablement, unusual engineering transfer, rapid file modification, configuration change, and loss of process visibility.
Useful alerts include operational context. A network event becomes more meaningful when the case also shows the affected process, active maintenance window, responsible engineer, normal communication pattern, safe containment options, and available recovery state.
Design at least four detection scenarios for each priority process: loss of enterprise identity, misuse of remote access, change to an engineering or control asset, and loss of a recovery dependency. For each scenario, record the evidence source, responsible analyst, operational contact, maximum decision time, safe first action, and proof needed to close the event. This turns detection coverage into a testable operating agreement rather than a list of alerts.
Preauthorize Safe Response
Response decisions should be written before pressure is high. Define who may revoke enterprise sessions, suspend vendor access, block a gateway, isolate an engineering workstation, or disable a service. Separately authorize process-mode changes, controlled stops, law-enforcement engagement, customer communications, and phased recovery.
CISA's incident and vulnerability response playbooks illustrate the value of repeatable roles and action sequences. NIST SP 800-184 adds recovery planning, execution, and improvement. [6] [3] OT-specific playbooks must add process safety, operational alternatives, vendor support, evidence requirements, and restart authority.
Protect Recovery as a Production Capability
Recovery assets include more than backup media. Protect identity, virtualization, management consoles, software installers, licenses, controller logic, recipes, golden configurations, firmware, engineering files, historian data, network configurations, certificates, time services, communications, and contact information.
NCCoE practice guides address identifying and protecting assets and recovering data integrity after ransomware and destructive events. [4] [5] NCSC backup principles emphasize isolation, access control, retention, alerting, and the ability to restore. [10]
Every restore should answer three questions: Is the source trusted? Is the restored state technically correct? Is the process operationally safe? The third question requires operations and engineering evidence, not only an IT success message.
A recovery runbook should also define the order in which dependencies return. Identity, time services, name resolution, virtualization, remote support, engineering workstations, data services, communications, and control applications may have sequencing requirements that are not visible in an ordinary backup catalog. Record who validates each stage, which process checks are required, what causes a rollback, and how the organization operates while restoration remains incomplete.
A Practical Implementation Roadmap
- Select two or three critical processes and name executive, operations, engineering, IT, security, safety, and recovery owners.
- Document safe states, minimum viable operations, maximum tolerable interruption, manual alternatives, and critical dependencies.
- Create an authoritative asset, connectivity, identity, vendor, and recovery inventory for those processes.
- Remove unmanaged exposure, shared access, and unnecessary persistent connections; establish controlled patterns and isolation tests.
- Build detection around realistic ransomware sequences and connect alerts to process and business context.
- Exercise safe containment, evidence preservation, manual operation, restoration, integrity validation, and phased restart.
- Measure completion evidence, unresolved exceptions, recovery test results, user effort, and operational risk reduction before expanding scope.
Use the first 90 days to prove the model on a bounded operating scope. In the first month, establish ownership, safe-state definitions, dependency maps, and minimum evidence. In the second month, remove the most exposed pathways, test identity and isolation actions, and validate backup and configuration sources. In the third month, run a cross-functional exercise from initial alert through minimum operation, restoration, process validation, and executive closure. Expansion should be based on completed evidence and reusable patterns, not on the number of tools deployed.
Standards and Threat Mapping
NIST SP 800-82 Rev. 3 anchors OT-specific performance, reliability, safety, architecture, threat, and safeguard considerations. [11] The ISA/IEC 62443 series provides lifecycle, role, security-program, risk-assessment, zones-and-conduits, and product requirements. [12] MITRE ATT&CK for ICS supports behavior-based scenario design without implying that a specific technique occurred locally. [13] ENISA Threat Landscape 2025 adds independently scoped threat and dependency context and identifies ransomware as the most impactful threat within its report scope. [14] NIST IR 8374 Rev. 1 supplies current CSF 2.0 ransomware outcomes; NIST SP 1339 adds current OT backup practices; and NIST SP 1800-45 provides a current remote-access architecture example. [15] [16] [17]
These authorities serve different purposes. Standards and guidance inform control design; behavior matrices inform scenarios; threat landscapes provide scoped context; and CyberTech Intelligence supplies the proprietary operating synthesis, score, and decision models.
Visual Decision Architecture
The following visuals convert the campaign thesis into a repeatable sequence for executive review, incident command, recovery, and governance.
Industrial Ransomware Attack Chain
Figure 1. Industrial Ransomware Attack Chain - From Access to Verified Recovery
|
Stage |
Operational Meaning |
|
1. Gain Access |
Exploit an exposed service, misuse credentials, compromise a supplier, or enter through a trusted remote pathway. |
|
2. Establish Control |
Create persistence, increase privilege, access management planes, or disable protective services. |
|
3. Cross Dependencies |
Reach identity, virtualization, engineering, file, backup, communications, or OT-adjacent services. |
|
4. Create Leverage |
Encrypt, steal data, deny recovery, disrupt supporting services, or force a precautionary shutdown. |
|
5. Contain Safely |
Revoke trust, restrict pathways, isolate affected services, preserve evidence, and protect minimum safe operation. |
|
6. Restore and Verify |
Recover from known-good sources, validate integrity and process safety, restart in phases, and close corrective actions. |
Recovery Decision Workflow
Figure 2. Recovery Decision Workflow - From Incident Command to Closed Improvement
|
Decision Step |
Required Outcome |
|
1. Establish Command |
Confirm process owner, incident authority, safety boundaries, communications, and evidence custody. |
|
2. Preserve Minimum Operation |
Continue reduced service, transition to local or manual control, or execute a controlled safe stop. |
|
3. Rebuild Trust |
Restore identity, management planes, engineering tools, configurations, logic, data, and communications from trusted sources. |
|
4. Validate Integrity |
Verify technical state, process behavior, safety, product quality, monitoring, and residual risk. |
|
5. Return in Phases |
Reconnect dependencies and expand from minimum operation to normal service with explicit approval and rollback criteria. |
|
6. Improve the System |
Close root causes, exceptions, supplier actions, architecture changes, and exercise findings with completion evidence. |
Industrial Ransomware Risk Maturity Model
Figure 3. Industrial Ransomware Risk Maturity Model
|
Maturity |
Operating Pattern |
Leadership Priority |
|
Reactive |
Dependencies, authority, and recovery evidence are reconstructed during the incident. |
Name critical operations, define safe first actions, protect logs, and test basic restoration. |
|
Defined |
Asset, access, segmentation, response, backup, and continuity procedures exist but remain separate. |
Standardize operational impact, pathways, decision rights, recovery evidence, and exceptions. |
|
Connected |
Operations, engineering, IT, security, safety, and suppliers share selected context and workflows. |
Create one operational trust chain and remove handoff gaps. |
|
Measured |
Exposure, detection, containment, recovery, exceptions, and exercises are measured by process. |
Use operational consequence and test evidence to prioritize investment. |
|
Adaptive |
Controls and operating modes adjust through current context, governed automation, and validated scenarios. |
Scale trusted patterns and continuously validate disruption and recovery assumptions. |
Governance and Decision Rights
Figure 4. Industrial Ransomware Governance Framework
|
Decision Stage |
Accountable Owner |
Required Evidence |
Exit Criteria |
|
Operational Scope |
COO / Business Owner |
Critical process, safe state, minimum operation, disruption tolerance, customer and safety impact. |
Scope and priorities approved. |
|
Architecture and Access |
OT Engineering / IT |
Asset and dependency map, segmentation, identities, remote pathways, vendor access, recovery sources. |
Every material path has an owner and isolation method. |
|
Detection and Response |
CISO / Incident Commander |
Cyber and process evidence, safe containment options, legal and communications triggers. |
Response authority and evidence requirements tested. |
|
Recovery and Restart |
Operations / Engineering / Safety |
Trusted source, integrity checks, process validation, residual risk, rollback, phased restart. |
Return-to-service approval recorded. |
|
Improvement and Investment |
Executive Risk Committee |
Exercise results, exception aging, corrective actions, supplier obligations, investment decisions. |
Actions closed with evidence and next review date. |
CyberTech Intelligence Industrial Ransomware Resilience Framework™
Eight operating layers connecting critical operations to controlled connectivity, safe response, trusted recovery, and evidence-led governance
|
01 |
Prepare Define critical operations, safe states, minimum service, disruption tolerance, dependencies, recovery priorities, decision owners, and exercise scenarios before an incident. |
|
02 |
Protect Reduce avoidable exposure through controlled connectivity, secure configurations, strong identity, protected engineering workstations, governed vendor access, and isolated recovery administration. |
|
03 |
Detect Correlate identity, endpoint, network, engineering, historian, remote-access, and process evidence so teams can recognize loss of trust before uncertainty becomes disruption. |
|
04 |
Contain Preauthorize process-aware actions such as token revocation, vendor suspension, gateway restriction, workstation isolation, reduced operation, local control, or a controlled stop. |
|
05 |
Recover Restore identity, configurations, logic, recipes, data, engineering services, communications, and supporting platforms from known-good sources with integrity and safety checks. |
|
06 |
Operate Sustain minimum safe service through local control, manual procedures, alternate communications, prioritized staffing, and clearly defined duration and escalation limits. |
|
07 |
Improve Use exercises, incident evidence, exception aging, restore results, user effort, and corrective-action closure to strengthen architecture, procedures, and investment priorities. |
|
08 |
Govern Align executives, operations, engineering, IT, security, safety, legal, communications, procurement, suppliers, and insurers through decision rights, risk thresholds, metrics, and accountable closure. |
Figure 5. CyberTech Intelligence Industrial Ransomware Resilience Framework™ - Eight-Layer Architecture
Industrial Ransomware Readiness Score™
Table. Industrial Ransomware Readiness Score™
|
Domain |
Executive Assessment Question |
Ready-State Evidence |
|
Asset Visibility |
Can leaders verify the OT assets, software, configurations, owners, and dependencies that support each critical operation? |
Authoritative inventory, process relationship, software and firmware records, configuration baseline, unsupported assets, ownership, and review evidence. |
|
Network Segmentation |
Can every authorized path between enterprise, plant, engineering, cloud, remote, and third-party environments be explained and safely isolated? |
Zone-and-conduit model, permitted services, gateway policy, firewall evidence, data-flow diagrams, isolation tests, exceptions, and rollback procedures. |
|
Identity |
Is every human and machine connection attributable, purpose-bound, time-limited, strongly authenticated where feasible, and rapidly revocable? |
Identity inventory, MFA and PAM coverage, service-account owners, break-glass governance, token controls, session evidence, access reviews, and revocation tests. |
|
Backups |
Are OT backups protected, current, integrated with change management, and tested during recovery exercises? |
Isolated copies, backup schedules, configuration and logic coverage, access controls, alerting, retention, restore tests, and change-management linkage. |
|
Recovery |
Can critical services return from a trusted source through a sequenced, integrity-checked, and operationally approved restoration process? |
Recovery sequence, trusted sources, golden configurations, identity recovery, technical checks, safety and quality validation, rollback, approval, and time evidence. |
|
Incident Response |
Are safe containment, evidence preservation, communications, legal escalation, and return-to-service decisions preauthorized for industrial scenarios? |
Scenario playbooks, incident command, decision authority, safety review, forensic steps, communications, fallback operations, exercises, and after-action closure. |
|
Vendor Access |
Are vendors, integrators, managed services, product support, and emergency pathways governed throughout their lifecycle? |
Named sponsors and accounts, approved purpose, device requirements, access windows, monitoring, incident obligations, support commitments, revocation, and assurance. |
|
Remote Connectivity |
Does every remote connection use an approved pattern with monitoring, expiry, an isolation method, and a tested operational alternative? |
Gateway inventory, approved protocols, session logging, connection owners, time limits, isolation results, emergency alternatives, and exception evidence. |
|
Engineering Workstations |
Are engineering workstations and project repositories protected as high-impact control and recovery assets? |
Managed images, application allowlisting, privileged separation, project integrity, secure transfer, removable-media controls, logging, recovery copies, and validation tests. |
|
OT Monitoring |
Can defenders connect abnormal cyber activity with process, maintenance, production, and safety context early enough to act? |
Telemetry map, OT-aware detections, time synchronization, protected logs, process context, alert thresholds, investigation records, tuning results, and coverage tests. |
|
Executive Governance |
Do business, operations, engineering, IT, security, safety, legal, communications, procurement, and suppliers review resilience through one decision cadence? |
Executive dashboard, risk appetite, decision rights, exception register, exercise calendar, investment priorities, action owners, due dates, and completion evidence. |
How to Calculate the Score
|
Control Rating |
Definition |
Evidence Test |
|
0 - Not Established |
No defined control or accountable owner. |
No current evidence. |
|
1 - Initial |
Control exists informally or only in isolated teams. |
Evidence is partial, outdated, or untested. |
|
2 - Defined |
Control and ownership are documented. |
Evidence exists but testing is incomplete. |
|
3 - Tested |
Control operates and has passed a recent scenario or restore test. |
Results, exceptions, and corrective actions are recorded. |
|
4 - Evidence-Backed |
Control is measured, repeatable, and improved through current evidence. |
Completion evidence, decision records, and recurring validation are available. |
Score each of the 11 domains from 0 to 4. Divide the total by 44 and multiply by 100. Readiness bands: 0-39 High Exposure; 40-59 Developing; 60-79 Operational; 80-94 Resilient; 95-100 Evidence-Backed
Request an OT/ICS Ransomware Resilience Assessment
Map operational dependencies, exposed pathways, remote access, recovery assumptions, safe containment actions, and evidence gaps. The assessment produces prioritized controls, accountable owners, and completion evidence rather than a generic risk list.
Continue the OT/ICS Ransomware Resilience Journey
Move from executive education to operating assessment through one consistent evidence, control, recovery, and decision path.
Table. CyberTech Intelligence OT/ICS Ransomware Resilience Content and Action Journey
|
Stage |
Asset or Offer |
Purpose |
|
Top of Funnel |
Download the OT/ICS Ransomware Readiness Checklist |
Identify initial gaps across operational impact, assets, connectivity, access, detection, response, recovery, third parties, and governance. |
|
Middle of Funnel |
Download the OT/ICS Operational Resilience Playbook |
Apply the eight-layer operating model, control questions, implementation sequence, scenario tests, and executive scorecard. |
|
Decision Stage |
Access the OT/ICS Ransomware & Operational Disruption 2026 Research Report |
Review current evidence, disruption pathways, ecosystem dynamics, operating implications, maturity progression, and board-level measures. |
|
Commercial Stage |
Request an OT/ICS Ransomware Resilience Assessment |
Evaluate operational dependencies, exposed paths, recovery assumptions, response authority, third-party access, and evidence gaps. |
|
Activation Stage |
Schedule an Executive OT Resilience Workshop |
Align operations, engineering, IT, security, safety, legal, communications, procurement, and leadership on priorities, owners, and completion evidence. |
About CyberTech Intelligence
CyberTech Intelligence provides decision-ready cybersecurity intelligence, research-led executive content, and precision engagement programs for security leaders and technology providers. Its work connects threat evidence, operating-model analysis, and commercial relevance so complex cyber risks can be translated into practical decisions and measurable action.
Research and Citation Governance
Official government, standards-body, law-enforcement, national cyber authority, incident-response, vendor research, and clearly scoped industry sources are used for threat patterns, control guidance, and operating recommendations. Quantitative findings retain their date, geography, population, and methodological limits. CyberTech Intelligence frameworks, scorecards, maturity models, and recommendations are proprietary analysis and are not presented as independent survey findings. Every cited URL was reviewed as an accessible public source on the revision date. Authoritative baseline standards may recur across assets when cross-asset consistency requires them; all quantitative and incident-specific claims remain separately attributed and scoped.
References
[1] National Institute of Standards and Technology. The NIST Cybersecurity Framework 2.0. February 2024. https://www.nist.gov/publications/nist-cybersecurity-framework-csf-20. Accessed July 29, 2026. Risk-management framework used to structure Govern, Identify, Protect, Detect, Respond, and Recover outcomes.
[2] National Institute of Standards and Technology. Incident Response Recommendations and Considerations for Cybersecurity Risk Management, SP 800-61 Revision 3. April 2025. https://csrc.nist.gov/pubs/sp/800/61/r3/final. Accessed July 29, 2026. Current incident-response guidance used for preparation, response, recovery, and continuous improvement.
[3] National Institute of Standards and Technology. Guide for Cybersecurity Event Recovery, SP 800-184. December 2016. https://csrc.nist.gov/pubs/sp/800/184/final. Accessed July 29, 2026. Recovery guidance used for planning, playbooks, improvement, and restoration governance.
[4] National Cybersecurity Center of Excellence. Data Integrity: Recovering from Ransomware and Other Destructive Events, SP 1800-11. September 2020. https://www.nccoe.nist.gov/data-integrity-recovering-ransomware-and-other-destructive-events. Accessed July 29, 2026. Practice guide used for trusted recovery, integrity verification, and restoration of affected data and services.
[5] National Cybersecurity Center of Excellence. Data Integrity: Identifying and Protecting Assets Against Ransomware and Other Destructive Events, SP 1800-25. December 2020. https://www.nccoe.nist.gov/data-integrity-identifying-and-protecting-assets-against-ransomware-and-other-destructive-events. Accessed July 29, 2026. Practice guide used for asset identification, protection, integrity, and ransomware preparation.
[6] Cybersecurity and Infrastructure Security Agency. Federal Government Cybersecurity Incident and Vulnerability Response Playbooks. Updated resource. https://www.cisa.gov/topics/cybersecurity-best-practices/executive-order-improving-nations-cybersecurity. Accessed July 29, 2026. Repeatable incident and vulnerability response playbooks used as a basis for role clarity and action sequencing.
[7] Cybersecurity and Infrastructure Security Agency. Cross-Sector Cybersecurity Performance Goals. Updated 2025. https://www.cisa.gov/cybersecurity-performance-goals. Accessed July 29, 2026. Voluntary baseline used to frame high-impact practices and completion evidence across critical infrastructure.
[8] U.S. Department of Energy. Cybersecurity Capability Maturity Model, Version 2.1. June 2022. https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2. Accessed July 29, 2026. Maturity model used to structure capability development, institutionalization, and measurement.
[9] Australian Signals Directorate and International Partners. Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators. August 14, 2025. https://www.cyber.gov.au/business-government/secure-design/operational-technology-environments/foundations-for-ot-cybersecurity-asset-inventory-guidance-for-owners-and-operators. Accessed July 29, 2026. Joint guidance used for OT asset inventory, taxonomy, criticality, and operational dependency mapping.
[10] UK National Cyber Security Centre. Principles for Ransomware-Resistant Backups. November 22, 2024. https://www.ncsc.gov.uk/collection/ransomware-resistant-backups. Accessed July 29, 2026. Official guidance used for backup isolation, access control, retention, alerting, and recovery design.
[11] National Institute of Standards and Technology (NIST). NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security. September 2023. https://csrc.nist.gov/pubs/sp/800/82/r3/final. Accessed July 30, 2026. Relevance: OT performance, reliability, safety, architectures, threats, vulnerabilities, and safeguards.
[12] International Society of Automation (ISA). ISA/IEC 62443 Series of Standards. Current series page; accessed July 30, 2026. https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards. Accessed July 30, 2026. Relevance: Lifecycle, roles, security programs, risk assessment, zones and conduits, product and component requirements.
[13] MITRE. MITRE ATT&CK for ICS Matrix. Live matrix; accessed July 30, 2026. https://attack.mitre.org/matrices/ics/. Accessed July 30, 2026. Relevance: Behavior-based scenario design across initial access, movement, inhibit response, impair process control, and impact.
[14] European Union Agency for Cybersecurity (ENISA). ENISA Threat Landscape 2025. October 2025. https://www.enisa.europa.eu/news/etl-2025-eu-consistently-targeted-by-diverse-yet-convergent-threat-groups. Accessed July 30, 2026. Relevance: Threat and dependency context; ransomware identified as the most impactful threat in the report scope.
[15] National Institute of Standards and Technology (NIST). NIST IR 8374 Rev. 1, Ransomware Risk Management: A CSF 2.0 Community Profile. June 2026. https://csrc.nist.gov/pubs/ir/8374/r1/final. Accessed July 30, 2026. Relevance: Current Govern, Identify, Protect, Detect, Respond, and Recover outcomes for ransomware risk management.
[16] National Institute of Standards and Technology (NIST). NIST SP 1339, OT Backup Quick Start Guide. June 2026. https://csrc.nist.gov/pubs/sp/1339/final. Accessed July 30, 2026. Relevance: OT backup integration with change management, regular creation, testing, and recovery exercises.
[17] National Institute of Standards and Technology (NIST). NIST SP 1800-45, Operational Technology Remote Access Build Architecture. June 2026. https://www.nccoe.nist.gov/publications/practice-guide/cybersecurity-water-and-wastewater-sector-build-architecture-nist-sp. Accessed July 30, 2026. Relevance: Current practice architecture for secure OT remote access in a critical-infrastructure context.