A 12-Step Process for IIoT (Industrial Internet of Things) Forensics (Kebande, IT Professional, 2026)
A solid framework and a great challenges table — but a checklist, not a field manual. Here’s what’s actually in it.
Author: Berend Watchus. Independent AI & Cybersecurity Researcher. Trendwatcher. Publication for System Weakness, online magazine.


If you work in OT (Operational Technology) / ICS (Industrial Control Systems) security or run investigations touching industrial environments, this paper is worth a skim — but go in with the right expectations. It’s a framework/checklist paper, not a how-to and not a research result.
What you’ll actually find: a clean, twelve-step map of the forensic lifecycle applied to Industrial IoT — from forensic readiness and initial assessment through acquisition, imaging/hashing, protocol analysis, cross-device correlation, legal handling, and closure. It’s explicitly aligned to ISO/IEC 27043 (the international standard for incident investigation principles and processes), so if you already live in that standard, none of the skeleton will surprise you. The single most useful artifact is Table 1, a well-referenced rundown of what actually makes IIoT forensics hard: device heterogeneity, proprietary protocols (Modbus, OPC-UA (Open Platform Communications Unified Architecture), DNP3 (Distributed Network Protocol 3), MQTT (Message Queuing Telemetry Transport)), real-time evidence that gets overwritten, devices with no logging or secure storage, and cross-jurisdiction legal mess. That table alone is a good briefing slide.
Be honest with yourselves about the limits: the paper tells you what to do at each stage but not how. It names the genuinely hard problems — imaging a PLC (Programmable Logic Controller) with no storage, capturing volatile telemetry without disrupting a live safety-critical process, dealing with vendor protocols that have no tooling — and then leaves them as open challenges.
Disclosure: the technical/forensics parts here were drafted with AI help — not my area. OT/ICS experts, please correct me in the comments.
There’s no case study, no proof-of-concept, no tool guidance, and no validation (the author defers all of that to future work). Several steps are the standard DF (Digital Forensics) process with industrial vocabulary layered on top, and a fair amount overlaps the author’s own earlier work.
Bottom line for this audience: treat it as a shared vocabulary and a planning scaffold — a way to structure an IIoT engagement, brief a non-technical stakeholder, or sanity-check that your readiness posture covers the pre-incident steps most orgs skip. Don’t expect acquisition techniques, protocol-parsing tradecraft, or anything you can run in the field. Read it for the framework and the challenges table; get your actual tradecraft elsewhere.
A 12-Step Process for IIoT (Industrial Internet of Things) Forensics (Kebande, IT Professional… was originally published in System Weakness on Medium, where people are continuing the conversation by highlighting and responding to this story.