Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

OT & ICS Security

Everything that makes an office network manageable is unavailable on a plant floor. You cannot reboot to apply a patch, the controller has been running since before the vendor stopped supporting it, and the protocol carrying the commands was designed on the assumption that anyone on the wire was authorised. This programme is written for the engineers and IT staff who now share responsibility for those systems, and it works from availability and safety outward rather than importing enterprise security practice wholesale.

Programme Agenda

Why OT Security Is Not IT Security

Availability and safety over confidentiality, decade-long equipment lifecycles, vendor support constraints, and change windows measured in hours per year. The practices that transfer from IT, and the ones that cause outages when they are imported unchanged.

Knowing What Is On the Network

Passive asset discovery in environments where an active scan can knock a controller offline. Building and maintaining an inventory of PLCs, HMIs, historians, engineering workstations and the forgotten devices that appear during the exercise.

The Purdue Model and Practical Segmentation

Levels 0 to 5 explained against real plant architecture. Where the boundaries should sit, what a demilitarised zone between enterprise and control networks does, and the flat network problem most sites start from.

Legacy Protocols and Their Exposure

Modbus, DNP3, PROFINET and the rest: what they do not authenticate, what an attacker on the same segment can therefore do, and the compensating controls available when replacing the protocol is not an option.

Secure Remote Access for Vendors and Engineers

The most common way outsiders reach a control network. Jump hosts, session brokering, time-bound access, multi-factor authentication and recording, without blocking the support contract you depend on.

Patching and Change in Production

Risk-based patching when the outage window is annual. Virtual patching, compensating controls, vendor validation requirements and the documented decision to accept a vulnerability rather than fix it.

Monitoring and Detection Without Disruption

Network taps and span ports, protocol-aware monitoring, baselining normal process traffic, and alert thresholds that survive a shift change without producing noise nobody reads.

Incident Response Where Downtime Is Not an Option

Response playbooks that account for safety systems, manual fallback operation, and the decision authority between plant management and IT during an event. Tabletop run against a compromise of an engineering workstation.

Learning Outcomes:
Explain why enterprise security practice fails when applied unchanged to OT
Build an OT asset inventory using methods safe for production equipment
Apply the Purdue model to design segmentation for a real plant network
Assess the exposure created by legacy industrial protocols and select compensating controls
Design secure remote access for vendors without breaking support arrangements
Make and document risk-based patching decisions in constrained change windows
Deploy monitoring that detects abnormal process traffic without disrupting it
Run an OT incident response that keeps safety and availability first

Duration: 2 Days (16 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

Control and automation engineers, plant and maintenance managers, IT and network staff who have inherited OT responsibility, and security teams extending coverage from the enterprise network into production.

Either side of the IT and OT divide works. Engineers get the security concepts built up from first principles; IT participants get the process and safety context. Mixed groups from the same site tend to get the most from it, because the exercises expose where the two teams have different assumptions.

The standard's structure, zones and conduits model, and security levels are covered and used as a reference throughout. This is not a certification course against IEC 62443.

Yes, and it is the better option. For in-house delivery we work from your network diagrams and asset list, so the segmentation and remote access exercises produce a design you can actually take forward.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.

More in Cybersecurity