Threat Hunting & Incident Response
Waiting for an alert assumes the alert will fire. Threat hunting starts from the assumption that something is already present and unproven — and builds the response plan for when that's true.
An IT incident response plan doesn't automatically work in an OT environment
Threat hunting starts from a different premise than monitoring does: rather than waiting for a tool to raise an alert, an analyst works a hypothesis about how an adversary could be present in the environment right now, undetected, and looks for the evidence that would confirm or rule it out. In a converged IT/OT environment, that hunt has to account for both sides — an indicator on the IT network and an anomaly in control-system behavior can be the same event seen from two different vantage points.
Incident response planning for these environments carries a constraint that a standard IT playbook doesn't: isolating or taking a system offline to contain an incident can itself have safety or operational consequences. A response plan that doesn't account for that isn't a plan operations can actually execute when it matters — it's a document that gets set aside in favor of improvisation.
GSS builds both capabilities together: hunting that treats IT and OT as one environment, and response plans built jointly with operations so that containment decisions are made with full knowledge of what's downstream of them, before an incident forces that decision under pressure.