Halil, I’d run this as a safety incident with cyber causes, not as a pure IT outage. The sourced pattern is edge-access failure: Polish CHP reporting points to Fortinet/private connectivity into OT, the water-system reporting points to suspected Iran-linked OT targeting, and CISA says Gunra affiliates exploited FortiGate firewall/SSL-VPN appliances and targeted critical infrastructure. In Purdue terms, assume Level 3.5/3 is compromised until proven otherwise, and prevent uncontrolled movement toward Level 2/1 PLCs. The physical concern is not “data loss”; it is wrong process visibility, unsafe command paths, false trips, missed trips, cargo/port safety delays, or operators being forced into blind manual mode.
First 24 hours: establish an OT incident commander beside plant operations; verify physical truth from field instruments, manual rounds, and independent alarms before trusting HMIs. Put PLC/HMI logic under change freeze, preserve FortiGate/Teltonika/VPN/APN/jump-host logs, revoke active VPN sessions, disable nonessential vendor access, and block direct routes from remote access paths to controllers. Do not power-cycle firewalls, APN routers, or PLCs casually; in OT, that can remove visibility or trip a process. For WAGO/Siemens/Unitronics-style environments, compare controller projects/checksums to known-good offline backups before touching logic.
24–72 hours: move from containment to controlled recovery. Build temporary allow-lists between Level 3 and Level 2, watch for PLC write functions, engineering workstation activity, RDP lateral movement, new admin sessions, alarm suppression, and unexplained setpoint changes. Patch Fortinet/edge devices only through a tested maintenance plan or redundant failover; if you cannot patch safely, use virtual patching, ACLs, VPN shutdown, MFA/session reset, and supervised vendor access. For the port-style IT disruption, keep manual cargo processing separated from OT/yard systems until identity, endpoints, and network trust are cleaned; don’t reconnect “because business is waiting.”
The leadership mistakes to avoid are predictable: demanding “patch everything in 24 hours,” believing the site is “air-gapped,” chasing attribution before stabilizing the process, trusting HMI screens without field verification, letting vendors back in through emergency remote access, and making segmentation changes without testing whether they break safety or control traffic. Also, I would not invent exact Dragos Q2 numbers here; the useful operational takeaway is that industrial ransomware must be planned as an availability and safety-continuity problem, not just backup restoration.