Skip to content

available

Practical OT Cyber Security Training for Engineers

A structured, self-paced introduction to operational technology and industrial control system cyber security. The course is written for electrical, control, automation and systems engineers working in industrial environments and uses practical engineering examples throughout.

Modules
15
Estimated duration
9 hr 40 min
Level
Foundation to intermediate
Format
Self-paced

What you will be able to do

  • Explain why OT cyber risk is different from ordinary enterprise IT risk.
  • Identify the IEC 62443 roles that apply to a project and navigate the main parts of the series.
  • Define a system under consideration, its essential functions, zones and conduits.
  • Explain target, achieved and capability security levels without treating them as product grades.
  • Turn a risk assessment into a cybersecurity requirements specification and verification plan.
  • Review an OT network architecture, remote-access path and patching process.
  • Ask product suppliers and service providers for meaningful, scope-specific security evidence.
  • Distinguish a secure development process under IEC 62443-4-1 from component capability under IEC 62443-4-2.
How to use this course

Complete the modules in order on a first pass. Each lesson combines technical explanation, the Riverside case study, an engineering activity and a formative knowledge check. On later visits, use the syllabus to return directly to the topic needed for a project.

The written modules are complete without the planned videos and diagrams. Knowledge checks support learning and are not examinations or evidence of competence.

Riverside Water Transfer Station

The course uses one fictional unmanned station throughout so that every activity contributes to a coherent design. Its essential function is to transfer water within defined pressure and level limits while preventing equipment damage, loss of containment and unsafe operation.

  • Two duty/standby pumps controlled by a PLC
  • A local HMI and engineering workstation
  • Flow, pressure, level and motor-condition instruments
  • A protective shutdown function independent of normal control
  • A managed industrial Ethernet switch
  • A telemetry RTU connected to a central SCADA system
  • A historian connection used for business reporting
  • A vendor remote-support requirement and controlled removable media
  • A twenty-year expected operational life
Course progress0%

Loading progress…

Start Module 01

Progress is stored only in this browser and is not a certificate or formal training record.

Intended audience

  • Electrical engineers
  • Control and automation engineers
  • Systems integrators
  • OT and industrial cyber security practitioners
  • Commissioning and maintenance engineers
  • Technical managers responsible for industrial systems

Prerequisites

  • Basic awareness of industrial control systems
  • No previous cyber security qualification required
  • Familiarity with engineering systems is helpful

What you will cover

  • Industrial control system security
  • IEC 62443
  • OT network security
  • Cybersecurity lifecycle
  • Risk assessment
  • Service providers
  • Secure products

Course syllabus

Part 1: Foundations

  1. Module 01

    Introduction to Control Systems Security

    Not complete

    An introduction to industrial control systems, their security needs and the consequences of cyber incidents in operational environments.

    30 minutes

  2. Module 02

    Security Awareness in Industrial Environments

    Locked

    Practical security awareness for people who design, operate, maintain and support industrial systems.

    25 minutes

  3. Module 03

    Regulations and Standards Landscape

    Locked

    An orientation to the regulations, standards and guidance commonly encountered in industrial cyber security.

    30 minutes

  4. Module 04

    Overview of the ISA/IEC 62443 Standards Series

    Locked

    A practical map of the ISA/IEC 62443 series and the roles addressed across its parts.

    35 minutes

  5. Module 05

    Fundamental Models and Security Levels

    Locked

    An introduction to foundational IACS security models, zones, conduits and security-level concepts.

    40 minutes

Part 2: Lifecycle and Governance

  1. Module 06

    Introduction to the IACS Cybersecurity Lifecycle

    Locked

    A practical introduction to managing industrial cyber security through the system lifecycle.

    30 minutes

  2. Module 07

    Establishing an Industrial Cybersecurity Management System

    Locked

    The purpose, scope and practical building blocks of an industrial cybersecurity management system.

    35 minutes

  3. Module 08

    Evolving Security Standards and Best Practices

    Locked

    How engineers can monitor, assess and adopt evolving industrial security standards and good practice.

    25 minutes

Part 3: Networks and Operations

  1. Module 09

    Networking Basics for Industrial Control Systems

    Locked

    Essential networking concepts for understanding communications within industrial control systems.

    45 minutes

  2. Module 10

    Network Security Basics in OT Environments

    Locked

    Core defensive principles for segmenting, controlling and monitoring industrial networks.

    45 minutes

  3. Module 11

    Industrial Network Protocols and Their Security Implications

    Locked

    Security implications of common industrial protocols and the assumptions behind their use.

    40 minutes

  4. Module 12

    Patch Management and Malware Protection in IACS

    Locked

    Risk-based patching and malware protection that respects industrial availability and safety constraints.

    40 minutes

Part 4: Risk and Supply Chain

  1. Module 13

    Risk Assessment and Secure System Design

    Locked

    Applying risk assessment to define proportionate security requirements and system architecture.

    60 minutes

  2. Module 14

    Cybersecurity Requirements for IACS Service Providers

    Locked

    Security responsibilities and evidence for integrators, maintainers and other IACS service providers.

    40 minutes

  3. Module 15

    Developing Secure Products and Components

    Locked

    Secure product-development principles for components used within industrial automation and control systems.

    60 minutes

Final practical exercise

Produce a concise cyber design basis for Riverside. A second engineer should be able to trace every important requirement back to an unacceptable consequence and forward to a test or review record.

  1. Essential-function and system-under-consideration statement
  2. Applicability register and role/responsibility matrix
  3. Asset, dependency and data-flow records
  4. Zone-and-conduit diagram with three detailed threat scenarios
  5. Proposed target security-level vector for important zones and conduits
  6. Ten verifiable cybersecurity requirements
  7. Remote-access design and patch/vulnerability decision workflow
  8. FAT, SAT and restoration tests
  9. Service-provider evidence schedule and product security evaluation
  10. Residual-risk and lifecycle review record

Course limitations

  • The course does not reproduce the normative text of IEC 62443.
  • It does not assign a valid security level to a real system.
  • It does not replace an asset-owner risk assessment or competent review.
  • It does not prove conformity, certification or competence.
  • It does not authorise testing on a live IACS.
  • Current contractual editions, law, regulator guidance and product instructions always take precedence.