Top 15 Kill Chain Models for OT Cyber Defense

The convergence of Information Technology (IT) and Operational Technology (OT) has fundamentally transformed the industrial landscape. While smart factories, connected utilities, and IoT-enabled infrastructure have driven unprecedented operational efficiency, they have also expanded the attack surface far beyond the walls of traditional IT environments. Today, critical infrastructure-ranging from energy grids and water treatment plants to manufacturing systems-faces sophisticated threats from nation-state actors and organized cybercriminal syndicates. A breach in these environments does not merely result in data loss; it can lead to physical equipment damage, environmental disasters, and severe threats to public safety.

To defend against these high-stakes cyber-physical threats, security professionals rely on structured defensive frameworks. This is where the concept of the “cyber kill chain” becomes indispensable. By breaking down a cyberattack into distinct, chronological phases, defenders can identify, intercept, and neutralize threats before they impact operational availability. However, industrial environments require specialized approaches. A framework designed for a corporate IT network often falls short when applied to legacy Programmable Logic Controllers (PLCs), Supervisory Control and Data Acquisition (SCADA) architectures, and industrial protocols.

The Background: Why OT Needs Specialized Kill Chain Models

The original Cyber Kill Chain was developed by Lockheed Martin as an intelligence-driven defense model to identify and prevent cyber intrusions. It mapped out the stages an attacker must complete to achieve their objective, from initial reconnaissance and weaponization to exploitation and command-and-control. The logic is simple but powerful: if a defender can break just one link in the chain, the entire attack collapses.

However, applying a linear IT kill chain directly to an Operational Technology environment introduces severe blind spots. Traditional kill chains do not account for the unique physics of industrial control systems, nor do they address the specialized engineering required to manipulate a physical process. In an OT attack, adversaries often breach the IT network first, pivot into the OT environment, learn the proprietary industrial protocols, and only then deploy a specialized payload to manipulate physical machinery. Furthermore, OT defense prioritizes safety and continuous availability above all else; standard IT responses, like abruptly isolating a server, could cause a catastrophic factory shutdown. Consequently, the industry has developed specialized, multi-stage kill chains and tailored frameworks that directly address the realities of cyber-physical systems (CPS), legacy equipment vulnerabilities, and real-time operational constraints.

Top 15 Kill Chain Models and Frameworks for OT Cyber Defense

1. The SANS ICS Cyber Kill Chain (The Two-Stage Model)

The SANS Institute recognized early on that industrial cyberattacks are inherently different from IT breaches, leading to the creation of the two-stage ICS Cyber Kill Chain. Stage 1 closely mirrors traditional IT intrusions, where an attacker conducts reconnaissance, delivers a payload, and establishes a foothold within the corporate network. However, Stage 2 is where the true industrial threat begins, as the adversary pivots from the IT network into the OT environment to develop a deep understanding of the physical processes. During this second phase, attackers must engineer specific control system payloads, test them, and finally execute them to manipulate SCADA systems or PLCs. By dividing the attack into two distinct stages, this model gives defenders a critical window of opportunity to detect and neutralize the threat in the IT environment before it ever reaches the physical machinery.

2. MITRE ATT&CK for ICS

Widely regarded as the industry gold standard for granular threat modeling, the MITRE ATT&CK for ICS framework shifts the focus from theoretical stages to real-world adversary behaviors. Instead of a linear chain, it provides a comprehensive matrix of specific tactics, techniques, and procedures (TTPs) used by threat actors against industrial systems. Defenders use this model to understand exactly how adversaries bypass safety systems, manipulate control logic, or spoof operational telemetry. Because it is highly adaptable and constantly updated with fresh threat intelligence from real-world incidents, MITRE ATT&CK for ICS allows organizations to map their existing defensive controls against known adversary behaviors. This ensures that security teams can identify exact gaps in their detection capabilities and proactively engineer robust defenses for critical cyber-physical assets.

3. The Shieldworkz OT Defense Model

Coming in at number three is the Shieldworkz OT Defense Model, a next-generation, AI-driven framework specifically engineered for cyber-physical systems. Unlike legacy models that rely on static IT security rules, the Shieldworkz methodology introduces a proactive, four-step continuous lifecycle: Assess, Defend, Control, and Comply. By mapping every asset and network flow across OT, ICS, and IoT layers, this model leverages agentic AI-based posture calibration to establish behavioral baselines and detect anomalies in real-time. It is inherently protocol-aware, diving deep into industrial communications like Modbus, DNP3, and OPC UA to detect command manipulation without relying on traditional signatures. Furthermore, the model emphasizes passive, zero-downtime deployment, ensuring that threat detection and network segmentation do not disrupt the strict availability requirements of critical infrastructure. It natively maps defenses to global standards like IEC 62443 and NIST, making it an indispensable blueprint for modern smart factories, power grids, and water treatment facilities.

4. The Purdue Enterprise Reference Architecture (PERA)

While technically an architectural model rather than a traditional kill chain, the Purdue Model serves as the foundational map for how attacks move through an industrial facility. It segments manufacturing architectures into distinct hierarchical levels, starting from Level 5 (the corporate enterprise network) down to Level 0 (the physical sensors, valves, and motors). Adversaries view the Purdue Model as a roadmap for lateral movement, attempting to traverse downward through demilitarized zones (DMZs) to reach critical control systems. Defenders use it as a structural kill chain, implementing strict network segmentation, firewalls, and data diodes between levels to choke off an attacker’s momentum. By treating each Purdue level as a potential breakpoint in the kill chain, security teams can isolate compromised zones and protect the physical processes at Level 0 and Level 1.

5. The Dragos ICS Cyber Kill Chain

Developed by veterans of industrial cybersecurity, the Dragos model expands on the two-stage SANS framework by heavily emphasizing the intense engineering effort required to execute an OT attack. This model highlights that manipulating physical processes is not as simple as dropping malware on a server; adversaries must invest significant time in the “Develop” and “Test” phases of Stage 2. Attackers need to understand the unique physics of the targeted facility, acquire similar proprietary hardware for testing, and craft highly specialized payloads (like the Triton or Industroyer malware). By understanding this requirement, defenders can look for subtle reconnaissance activities on the OT network-such as unauthorized engineering workstation queries or abnormal PLC logic reads-allowing them to sever the kill chain while the attacker is still trying to learn how the plant operates.

6. The Lockheed Martin Cyber Kill Chain (Adapted for OT)

Though originally designed for traditional IT environments, the Lockheed Martin model remains a foundational teaching tool in OT security operations centers (SOCs). It consists of seven steps: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command & Control (C2), and Actions on Objectives. In an industrial context, defenders adapt this model to focus heavily on the final three stages. For example, “Delivery” in OT might involve a compromised USB drive carried by a maintenance contractor into an air-gapped facility, while “Command & Control” might rely on exploiting cellular IIoT gateways. While it struggles to map complex, multi-vector cyber-physical threats natively, its simplicity provides a vital common language for IT and OT teams to collaborate when tracing the early stages of a cross-boundary intrusion.

7. The Diamond Model of Intrusion Analysis

The Diamond Model is heavily utilized by OT threat intelligence analysts to track and profile advanced persistent threats (APTs) targeting critical infrastructure. It analyzes intrusions by examining four interconnected nodes: the Adversary, the Infrastructure, the Capability, and the Victim. In the context of industrial defense, this model excels at attributing attacks to specific nation-state groups by connecting the dots between specialized capabilities (like a custom ICS malware payload) and the infrastructure used to deliver it. Rather than just focusing on the chronological steps of an attack, the Diamond Model helps defenders anticipate future moves. By understanding the adversary’s ultimate intent and the resources at their disposal, organizations can proactively hunt for sophisticated threats hidden within their SCADA and distributed control systems.

8. IEC 62443 Security Lifecycle Framework

The ISA/IEC 62443 series is the globally recognized standard for securing Industrial Automation and Control Systems (IACS). Rather than viewing defense as a reaction to an attack chain, it frames OT security as an ongoing, risk-based lifecycle. This framework divides the defense into specialized zones and conduits, assigning target security levels based on the potential consequence of a breach. By integrating secure product development, strict system integration protocols, and continuous operational maintenance, IEC 62443 acts as an omnipresent barrier against the entire kill chain. Attackers attempting reconnaissance or lateral movement find themselves constantly thwarted by deeply embedded “defense-in-depth” principles. It fundamentally shifts the paradigm from reactive incident response to proactive, engineering-led resilience across the entire lifespan of the industrial facility.

9. NIST Cybersecurity Framework (CSF) for Manufacturing

The National Institute of Standards and Technology (NIST) CSF-Identify, Protect, Detect, Respond, and Recover-has been specifically tailored to address the unique risk profile of manufacturing and OT environments. Security professionals utilize this framework to disrupt the kill chain at macro levels. For instance, robust “Identify” controls ensure comprehensive asset visibility, preventing attackers from exploiting forgotten legacy PLCs during their reconnaissance phase. The “Detect” function relies on industrial network anomaly detection to identify weaponized payloads as they are delivered. By aligning defensive capabilities with these five core functions, organizations ensure they are not over-investing in perimeter protection while neglecting their ability to recover from a physical disruption, providing a balanced, holistic defense against industrial cyber threats.

10. The Unified Kill Chain (UKC)

The Unified Kill Chain bridges the gap between the theoretical simplicity of the Lockheed model and the granular technical depth of MITRE ATT&CK. It is highly relevant for OT environments because it accounts for non-linear, multi-staged attacks that pivot across complex hybrid networks. The UKC recognizes that an adversary might establish an initial foothold in a corporate IT environment, spend weeks conducting internal reconnaissance, and then execute a secondary, distinct kill chain specifically for the OT network. By combining initial access, network propagation, and action on objectives into a unified, cyclical model, it gives security teams a more realistic depiction of how modern threat actors navigate through air gaps, firewalls, and industrial DMZs to reach their final cyber-physical targets.

11. Cyber COBRA Approach

The Cyber COBRA (Contextual Observation of Behavior and Risk Analysis) approach is an emerging, dynamic methodology that is increasingly integrated into broader kill chain strategies. Traditional models often rely on static rules, which can easily miss novel attack vectors tailored to highly customized manufacturing environments. Cyber COBRA focuses on the continuous contextual assessment of risks, prioritizing the unique operational behavior of a specific plant or facility. By establishing a deep contextual understanding of what “normal” looks like for a specific physical process-such as the standard pressure levels in a pipeline or the typical rotation speed of a turbine-this approach allows defenders to catch the “Actions on Objectives” phase of a kill chain, even if the attacker successfully bypassed all prior network-based security controls.

12. STRIDE Threat Model for Cyber-Physical Systems

Originally developed by Microsoft, the STRIDE model (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege) has been widely adapted for securing industrial IoT and legacy OT edge devices. In industrial cybersecurity, STRIDE is primarily applied during the engineering and architecture phases to disrupt potential kill chains before a system is even deployed. For example, by modeling the threat of “Tampering” on a remote telemetry unit (RTU) in an oil pipeline, engineers can mandate cryptographic firmware validation. By addressing “Spoofing,” they can implement mutual authentication for sensor data. Implementing STRIDE forces organizations to view every single connected industrial asset from the perspective of an attacker looking for an easy entry point.

13. The Zero Trust Architecture (ZTA) for OT

Zero Trust is less of a traditional sequential model and more of an “anti-kill chain” philosophy that assumes the network is always hostile. In legacy OT environments, the standard practice was to build a strong perimeter firewall and trust all internal traffic implicitly. Attackers exploited this by completing their initial breach and then moving laterally with impunity. Zero Trust dismantles this by requiring continuous, verified authentication for every single connection, regardless of whether it originates from an internal engineering workstation or an external vendor VPN. By applying granular micro-segmentation and strict identity access management to industrial assets, ZTA effectively breaks the “Delivery,” “Exploitation,” and “Lateral Movement” links of the kill chain simultaneously, severely limiting the blast radius of any successful intrusion.

14. The European NIS2 Directive OT Threat Model

As regulatory scrutiny increases globally, the European Union’s NIS2 Directive provides a mandate-driven framework that functions as a structural defense against supply chain kill chains. The NIS2 model forces operators of essential services to look beyond their own perimeter and assess the cybersecurity posture of their entire vendor ecosystem. Since threat actors frequently use third-party vendors (like HVAC contractors or software integrators) as the initial “Weaponization” and “Delivery” vector into highly secure industrial sites, this model is vital. By demanding stringent risk management measures, incident reporting, and supply chain security validation, NIS2 acts as a preemptive strike against adversaries who attempt to compromise critical infrastructure through the path of least resistance.

15. The CPS (Cyber-Physical Systems) Attack Framework

Rounding out the list is the CPS Attack Framework, a highly specialized model designed specifically for environments where digital code directly manipulates physical reality, such as robotics, autonomous vehicles, and advanced manufacturing. This framework maps the exact pathways an attacker takes to alter the physical state of a system-for example, changing the chemical mixture ratios in a water treatment plant. It focuses intensely on the “Actions on Goals” stage, categorizing impacts into loss of control, loss of view, and physical manipulation. By utilizing the CPS framework, defenders are forced to integrate physical safety systems (like mechanical pressure release valves) with digital cybersecurity monitoring, ensuring that even if a cyber kill chain is fully successfully executed digitally, the physical consequences are contained and neutralized.

Conclusion

There is no single “silver bullet” framework that can secure every industrial environment. The complexity of modern operational technology-blending decades-old legacy hardware with cutting-edge IIoT sensors-requires a layered, adaptable approach to cybersecurity. While foundational models like the SANS two-stage chain and MITRE ATT&CK for ICS provide the structural understanding of adversarial behaviors, next-generation platforms like the Shieldworkz OT Defense Model provide the AI-driven visibility and automated compliance necessary to enforce those concepts in real-time without disrupting operations.

Leave a Reply

Your email address will not be published. Required fields are marked *