Environment
An industrial operator with a central security operations function had built detection capability around IT-focused tooling -- endpoint detection, firewall logs, and identity telemetry -- and extended it to OT sites mostly by pointing the same tools at whatever OT logs were reachable.
Challenge
Analysts were flooded with alerts that made sense in an IT context but meant little operationally: generic "unusual traffic" alerts on protocols like Modbus that don't carry the identity or behavioral context IT tooling expects, with no way to tell a benign engineering change from a meaningful anomaly. Analysts began routinely dismissing OT-origin alerts, which meant a real event risked being lost in the noise.
Approach
Instead of tuning existing IT rules, the team built a small number of detection use cases starting from MITRE ATT&CK; for ICS tactics relevant to their environment -- unauthorized engineering workstation connections outside change windows, unexpected write commands to controllers, and use of default protocol functions with no authentication from unfamiliar hosts. Each use case specified exactly what telemetry source fed it, what normal looked like, and what operational action followed a true positive, closing the loop between the SOC and site engineering rather than leaving alerts to sit in a queue no one owned.
Outcome
Total alert volume from OT sources dropped as generic noise was retired, while the operator gained a small set of use cases analysts trusted enough to act on quickly, with site engineering teams involved in validating each one before it went live.