Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK ICS T0809: Data Destruction (Inhibit Response Function)

MITRE ATT&CK ICS T0809 covers adversary destruction of data and historian records on industrial control systems to inhibit operator response and forensic…

What MITRE ATT&CK ICS T0809: Data Destruction (Inhibit Response Function) requires

MITRE ATT&CK ICS T0809 covers adversary destruction of data and historian records on industrial control systems to inhibit operator response and forensic investigation. CRASHOVERRIDE/Industroyer (Ukraine 2016), Industroyer2 (Ukraine 2022), and FrostyGoop (Ukraine 2024) all included data-destruction components targeting OT historians and engineering workstations. Compliance obligations include NIST SP 800-82 Rev 3, NERC CIP-008 (Incident Response), NERC CIP-009 (Recovery Plans), IEC 62443-2-1 (Security Program), IEC 62443-3-3 SR 7.3 (Backup), ISO 27001 A.8.13, NIS2 Article 21(2)(c), and CISA OT Cybersecurity Performance Goals.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T0809/

SHA-256 integrity: c5071414bb7babaa21025c1112d1eda06210a3cf6c63d90d15cd985714cb7028

Primary Citations — 8 traced to source

  • MITRE ATT&CK ICS Technique T0809: Data Destruction (https://attack.mitre.org/techniques/T0809/)
  • NERC CIP-009-6: Recovery Plans for BES Cyber Systems

+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.