OT & ICS Security
Everything that makes an office network manageable is unavailable on a plant floor. You cannot reboot to apply a patch, the controller has been running since before the vendor stopped supporting it, and the protocol carrying the commands was designed on the assumption that anyone on the wire was authorised. This programme is written for the engineers and IT staff who now share responsibility for those systems, and it works from availability and safety outward rather than importing enterprise security practice wholesale.
Programme Agenda
Why OT Security Is Not IT Security
Availability and safety over confidentiality, decade-long equipment lifecycles, vendor support constraints, and change windows measured in hours per year. The practices that transfer from IT, and the ones that cause outages when they are imported unchanged.
Knowing What Is On the Network
Passive asset discovery in environments where an active scan can knock a controller offline. Building and maintaining an inventory of PLCs, HMIs, historians, engineering workstations and the forgotten devices that appear during the exercise.
The Purdue Model and Practical Segmentation
Levels 0 to 5 explained against real plant architecture. Where the boundaries should sit, what a demilitarised zone between enterprise and control networks does, and the flat network problem most sites start from.
Legacy Protocols and Their Exposure
Modbus, DNP3, PROFINET and the rest: what they do not authenticate, what an attacker on the same segment can therefore do, and the compensating controls available when replacing the protocol is not an option.
Secure Remote Access for Vendors and Engineers
The most common way outsiders reach a control network. Jump hosts, session brokering, time-bound access, multi-factor authentication and recording, without blocking the support contract you depend on.
Patching and Change in Production
Risk-based patching when the outage window is annual. Virtual patching, compensating controls, vendor validation requirements and the documented decision to accept a vulnerability rather than fix it.
Monitoring and Detection Without Disruption
Network taps and span ports, protocol-aware monitoring, baselining normal process traffic, and alert thresholds that survive a shift change without producing noise nobody reads.
Incident Response Where Downtime Is Not an Option
Response playbooks that account for safety systems, manual fallback operation, and the decision authority between plant management and IT during an event. Tabletop run against a compromise of an engineering workstation.
Learning Outcomes:
Explain why enterprise security practice fails when applied unchanged to OT
Build an OT asset inventory using methods safe for production equipment
Apply the Purdue model to design segmentation for a real plant network
Assess the exposure created by legacy industrial protocols and select compensating controls
Design secure remote access for vendors without breaking support arrangements
Make and document risk-based patching decisions in constrained change windows
Deploy monitoring that detects abnormal process traffic without disrupting it
Run an OT incident response that keeps safety and availability first
Duration: 2 Days (16 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Cybersecurity
- CompTIA Security+ Certification · Intermediate, 5 days
- CompTIA CySA+ Certification · Intermediate to Advanced, 5 days
- ISC2 Certified in Cybersecurity (CC) · Beginner, 3 days
- CEH Certified Ethical Hacker · Intermediate, 5 days
- CyberSafe for Schools · Beginner, 4 days
- Cybersecurity Awareness for Employees · All staff, 1 day
- Cybersecurity for Non-IT Staff · Beginner, 1 day
- Phishing and Social Engineering Awareness · Beginner, 1 day