WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships MITRE Releases ATT&CKTM for ICS as Common Lexicon for Industrial Cyber Defense Strategy
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

MITRE Releases ATT&CKTM for ICS as Common Lexicon for Industrial Cyber Defense Strategy

Author: Jennifer Walker

Created: Thursday, January 9, 2020 - 18:53

Categories: Cybersecurity, General Security and Resilience

The MITRE Corporation, publisher of the widely revered ATT&CKTM Framework, has just released a new knowledge base, ATT&CKTM for Industrial Control Systems. Developed in collaboration with experts from ICS cybersecurity firm Dragos, ATT&CKTM for ICS categorizes public behaviors of malicious activity targeting critical OT infrastructure. ATT&CKTM for ICS was created to provide a common view and lexicon for ICS threat behavior mapping so defenders can better validate or develop their defenses. ATT&CKTM for ICS differs from its ATT&CKTM for Enterprise counterpart, in that it is based on adversary goals specific to ICS, such as disrupting an industrial control process, destroying property or causing temporary or permanent harm or death to humans. Additional ICS-specific considerations have also incorporated the Purdue Model and OT network assets. This new knowledge base identifies unique ICS-based tactics, such as inhibit response functions and impair process control. The ICS-specific tactics are further refined to discuss over eighty behavioral techniques, including alarm suppression and modify control logic. Read more about the new ATT&CKTM for ICS Overview at MITRE and Dragos.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar