What MITRE ATT&CK ICS T0809: Data Destruction (Inhibit Response Function) requires
MITRE ATT&CK ICS T0809 covers adversary destruction of data and historian records on industrial control systems to inhibit operator response and forensic investigation. CRASHOVERRIDE/Industroyer (Ukraine 2016), Industroyer2 (Ukraine 2022), and FrostyGoop (Ukraine 2024) all included data-destruction components targeting OT historians and engineering workstations. Compliance obligations include NIST SP 800-82 Rev 3, NERC CIP-008 (Incident Response), NERC CIP-009 (Recovery Plans), IEC 62443-2-1 (Security Program), IEC 62443-3-3 SR 7.3 (Backup), ISO 27001 A.8.13, NIS2 Article 21(2)(c), and CISA OT Cybersecurity Performance Goals.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T0809/
SHA-256 integrity: c5071414bb7babaa21025c1112d1eda06210a3cf6c63d90d15cd985714cb7028
Primary Citations — 8 traced to source
- MITRE ATT&CK ICS Technique T0809: Data Destruction (https://attack.mitre.org/techniques/T0809/)
- NERC CIP-009-6: Recovery Plans for BES Cyber Systems
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-ics-t0809-data-destruction.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-ics-t0809-data-destruction.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-ics-t0809-data-destruction
- Back to registry: Browse all 10,085 compliance nodes