MITRE ATT&CK ICS
T0826

Loss of Availability

Description

Adversaries may attempt to disrupt essential components or systems to prevent owner and operator from delivering products or services. (Citation: Corero) (Citation: Michael J. Assante and Robert M. Lee) (Citation: Tyson Macaulay) Adversaries may leverage malware to delete or encrypt critical data on HMIs, workstations, or databases. In the 2021 Colonial Pipeline ransomware incident, pipeline operations were temporally halted on May 7th and were not fully restarted until May 12th. (Citation: Colonial Pipeline Company May 2021)

Mapped SPARTA techniques

2 techniques

  • EX-0010.01RansomwareST0004
    addresses
    moderate

    T0826 'Loss of Availability' addresses adversary actions causing unavailability of system/process resources; ransomware encrypts data to deny availability — same impact concept. Cross-tactic moderate (impact vs execution) and concept-adjacent (ICS has no specific ransomware technique; T0826 captures the availability-denial outcome).

  • IMP-0003DenialST0009
    addresses
    high

    T0826 'Loss of Availability' is in MITRE ICS impact tactic and addresses adversary actions causing unavailability of system/process resources; SPARTA IMP-0003 'Denial' (deny access entirely) is the parent-level spacecraft equivalent. Tactic and activity align directly; T0826 is the broadest availability-loss impact technique applicable.

Cite as SafeMode Space, mitre-attack-ics T0826.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.