MITRE ATT&CK for ICS
The 12 ICS tactics
The ICS matrix organises adversary behaviour into 12 tactics. The ‘why’ behind each stage of an attack. These differ from the Enterprise matrix because they reflect the specific objectives and constraints of attacking industrial environments.
Initial Access – how the adversary gains a foothold in the ICS environment. Common techniques include exploiting internet-facing OT devices, spear-phishing engineering staff, compromising remote access services, or pivoting from the IT network through a poorly segmented DMZ.
Execution – running adversary-controlled code on ICS devices. This includes scripting on engineering workstations, modifying PLC programs, or executing commands through native ICS protocols like Modbus or OPC UA.
Persistence – maintaining access across system restarts and network changes. Techniques include modifying PLC firmware, implanting backdoors in engineering workstations, and creating rogue accounts on SCADA systems.
Evasion – avoiding detection by security tools and operators. Adversaries may spoof sensor readings to hide their activity, masquerade as legitimate ICS traffic, or modify logs on servers.
Discovery – mapping the ICS environment. Adversaries enumerate network topology, identify PLCs and their configurations, locate safety systems, and determine the relationship between control systems and physical processes.
Lateral Movement – moving between systems within the OT network. This includes exploiting trust relationships between engineering workstations and PLCs, using default credentials on industrial devices, and traversing network segments that lack proper access controls.
Collection – gathering data from ICS environments, including process parameters, control logic, engineering drawings, and network configurations. This intelligence informs subsequent attack stages.
Command and Control – establishing communication channels between compromised ICS devices and adversary infrastructure. Techniques include using standard ICS protocols to blend with legitimate traffic.
Inhibit Response Function – disabling or degrading the ability of operators and safety systems to respond to the attack. This is the tactic that makes ICS attacks uniquely dangerous. Techniques include disabling safety instrumented systems (SIS), blocking operator access to HMIs, suppressing alarms, and modifying control logic so that manual overrides fail.
Impair Process Control – modifying process control parameters to disrupt operations. Adversaries may change setpoints, alter control logic, or send unauthorised commands to actuators and valves.
Impact – the final objective. In ICS environments, impact tactics include damage to equipment (driving machinery beyond safe operating parameters), denial of control (locking operators out of their own systems), denial of view (blinding operators to what is actually happening), loss of availability (shutting down processes), loss of safety (disabling protective systems), and in extreme cases, physical destruction.
The last three tactics – Inhibit Response Function, Impair Process Control, and Impact are unique to the ICS matrix. They describe attack outcomes that do not exist in IT environments, where the worst case is typically data loss or system downtime rather than physical damage or safety incidents.
How it differs from Enterprise ATT&CK
The Enterprise ATT&CK matrix covers IT environments, servers, workstations, cloud infrastructure, mobile devices, and network equipment. The ICS matrix covers OT environments including PLCs, RTUs, SCADA systems, DCS, HMIs, safety systems, and the physical processes they control.
Key differences:
- Attack objectives – Enterprise ATT&CK ends with data exfiltration or system disruption. ICS ATT&CK ends with physical consequences: equipment damage, process disruption, safety system failure
- Techniques – ICS techniques include modifying PLC ladder logic, spoofing sensor data, and manipulating industrial protocols. These do not appear in the Enterprise matrix
- Threat actors – ICS-focused groups documented by MITRE include Sandworm (Russian GRU, responsible for Ukraine power grid attacks), XENOTIME/TRITON (targeted Saudi petrochemical safety systems), and Volt Typhoon (Chinese state actor targeting US critical infrastructure)
- Detection challenges – many ICS devices lack logging capabilities, cannot run endpoint detection agents, and use protocols with no built-in authentication. Detection in ICS environments requires network-based monitoring and protocol-aware analysis
For organisations with converged IT/OT environments, both matrices apply. An attacker may use Enterprise techniques to compromise the IT network, then pivot to ICS techniques once they reach the OT environment. Threat modelling exercises should map attack paths across both matrices.
Using MITRE ATT&CK for ICS
The ICS matrix supports several practical security activities:
Threat modelling – mapping known adversary groups and their documented TTPs to the organisation’s specific ICS environment. This identifies which techniques are most relevant and which controls are missing.
Detection engineering – developing detection rules and monitoring use cases aligned to specific ICS techniques. For example, monitoring for unauthorised changes to PLC logic or unexpected commands on industrial protocols.
Red teaming and purple teaming – structuring offensive security exercises around realistic ICS attack scenarios, using documented adversary techniques as the basis for test cases.
Gap analysis – assessing existing security controls against the ICS matrix to identify where the organisation has detection and prevention coverage and where blind spots exist. This is particularly valuable when mapped alongside IEC 62443 requirements.
Cyberfort and MITRE ATT&CK for ICS
We use the ICS ATT&CK matrix to structure threat assessments for clients in manufacturing, energy, utilities, and defence through our OT/IoT security review service. Our assessments map adversary TTPs to the client’s specific industrial environment, identifying attack paths and control gaps aligned to the ICS matrix. Our penetration testing and incident response services include ICS-specific capabilities for organisations that need to validate or defend their operational technology environments.
Related glossary terms
- MITRE ATT&CK – the parent framework covering Enterprise, Mobile, Cloud, and ICS matrices
- IEC 62443 – the international standard for industrial control system cybersecurity, complementing MITRE’s threat intelligence with prescriptive controls
- Threat Modelling – the discipline of identifying and analysing adversary attack paths, using frameworks such as ATT&CK for ICS
- Red Teaming – offensive security exercises that can be structured around ICS ATT&CK techniques
- NCSC CAF – the UK framework for assessing cyber resilience in critical national infrastructure, including OT environments
External references
- Wikipedia: MITRE ATT&CK — overview of the parent framework
- Wikidata: Q100047419 — canonical entity identifier for MITRE ATT&CK
- MITRE ATT&CK for ICS — the official ICS matrix with all tactics, techniques, and documented adversary groups
- CISA: ICS Advisories — US government advisories on vulnerabilities and threats specific to industrial control systems
Frequently asked questions
What is MITRE ATT&CK for ICS?
MITRE ATT&CK for ICS is a knowledge base that catalogues the tactics, techniques, and procedures used by adversaries to attack industrial control systems. It covers 12 tactics specific to OT environments, including techniques for disrupting physical processes, disabling safety systems, and damaging equipment. It is maintained by the MITRE Corporation and updated as new adversary behaviour is documented from real-world incidents.
How does the ICS matrix differ from Enterprise ATT&CK?
The Enterprise matrix covers attacks on IT systems where the objectives are typically data theft, espionage, or ransomware. The ICS matrix covers attacks on operational technology where the objectives include physical damage, process disruption, and safety system compromise. The ICS matrix includes three unique tactics. These are: Inhibit Response Function, Impair Process Control, and Impact that describe outcomes specific to industrial environments. It also covers ICS-specific techniques such as modifying PLC logic and manipulating industrial protocols.
Who are the main threat actors targeting ICS?
MITRE documents several groups targeting industrial control systems, and activity has intensified over the past two years. Volt Typhoon, attributed to Chinese state actors, has been pre-positioning inside US water, energy and communications infrastructure, with CISA warning in February 2024 that it had held covert access to some OT environments for up to a year. The Iran-linked CyberAv3ngers group compromised internet-exposed Unitronics PLCs at several US water utilities in late 2023, including the Municipal Water Authority of Aliquippa in Pennsylvania. And in January 2024, malware known as FrostyGoop cut heating to more than 600 buildings in Lviv, Ukraine, by manipulating ICS devices over the Modbus protocol. These build on the foundational cases behind the ICS matrix, Sandworm’s attacks on Ukraine’s power grid (2015-2016) and the TRITON attack on a Saudi petrochemical plant’s safety systems (2017), and show that ICS attacks remain largely the preserve of state-sponsored actors with the resources to disrupt physical infrastructure.
Awards and Accreditations




















Contact Us
Cyberfort Ltd
Venture West,
Greenham Business Park, Thatcham,
Berkshire,
RG19 6HX
