OT environments overwrite the evidence you need faster than IT ones do. A disciplined evidence timeline captured in the first hours is worth more than any post incident forensic effort.
The hardest part of investigating an OT incident is not analysis. It is that the evidence you needed was overwritten before anyone thought to preserve it. Ring buffers on IEDs, short PLC diagnostic logs, historian retention windows measured in days, engineering workstations rebooted by well meaning technicians. The clock is not on the investigator side.
What to capture first
In the first few hours of a suspected OT incident, the priority is preservation, not analysis. A minimum capture list:
- HMI and engineering workstation memory and disk images where safe to acquire.
- Historian exports for the affected process variables covering a wide window before and after the suspected event.
- Firewall and switch logs from the ESP boundary and from any jump host segment.
- Vendor specific diagnostic bundles from PLCs, RTUs, and IEDs involved.
- Remote access session logs for the relevant time window, including contractor access.
- Any change management or work order records that touched the affected assets recently.
Capture first. Interpret later.
Build the timeline as you go
An evidence timeline is not a post incident artifact. It is a live document from the first hour. Each entry needs a timestamp, a source, an observation in plain language, and a confidence tag. Assessments belong in a separate column so they can be revised without losing the underlying evidence.
ThreatSpire structures evidence timelines this way by default. Each item carries its source, its collection time, and its confidence, and multiple analysts can contribute in parallel without stepping on each other.
Why this matters more in OT
In IT, you can often go back to endpoint logs weeks later. In OT, if you did not pull the IED diagnostic bundle in the first day, it is gone. If you did not export the historian window before someone rolled the retention, it is gone. If the engineering workstation was reimaged during recovery, it is gone.
A disciplined evidence timeline captured early is the single highest leverage habit an OT incident response team can build. It is also the artifact regulators and legal counsel will ask for first.

