available
Practical OT Cyber Security Training for Engineers
A structured, self-paced introduction to operational technology and industrial control system cyber security. The course is written for electrical, control, automation and systems engineers working in industrial environments and uses practical engineering examples throughout.
- Modules
- 15
- Estimated duration
- 9 hr 40 min
- Level
- Foundation to intermediate
- Format
- Self-paced
What you will be able to do
- Explain why OT cyber risk is different from ordinary enterprise IT risk.
- Identify the IEC 62443 roles that apply to a project and navigate the main parts of the series.
- Define a system under consideration, its essential functions, zones and conduits.
- Explain target, achieved and capability security levels without treating them as product grades.
- Turn a risk assessment into a cybersecurity requirements specification and verification plan.
- Review an OT network architecture, remote-access path and patching process.
- Ask product suppliers and service providers for meaningful, scope-specific security evidence.
- Distinguish a secure development process under IEC 62443-4-1 from component capability under IEC 62443-4-2.
How to use this course
Complete the modules in order on a first pass. Each lesson combines technical explanation, the Riverside case study, an engineering activity and a formative knowledge check. On later visits, use the syllabus to return directly to the topic needed for a project.
The written modules are complete without the planned videos and diagrams. Knowledge checks support learning and are not examinations or evidence of competence.
Riverside Water Transfer Station
The course uses one fictional unmanned station throughout so that every activity contributes to a coherent design. Its essential function is to transfer water within defined pressure and level limits while preventing equipment damage, loss of containment and unsafe operation.
- Two duty/standby pumps controlled by a PLC
- A local HMI and engineering workstation
- Flow, pressure, level and motor-condition instruments
- A protective shutdown function independent of normal control
- A managed industrial Ethernet switch
- A telemetry RTU connected to a central SCADA system
- A historian connection used for business reporting
- A vendor remote-support requirement and controlled removable media
- A twenty-year expected operational life
Loading progress…
Start Module 01Progress is stored only in this browser and is not a certificate or formal training record.
Intended audience
- Electrical engineers
- Control and automation engineers
- Systems integrators
- OT and industrial cyber security practitioners
- Commissioning and maintenance engineers
- Technical managers responsible for industrial systems
Prerequisites
- Basic awareness of industrial control systems
- No previous cyber security qualification required
- Familiarity with engineering systems is helpful
What you will cover
- Industrial control system security
- IEC 62443
- OT network security
- Cybersecurity lifecycle
- Risk assessment
- Service providers
- Secure products
Course syllabus
Part 1: Foundations
- Not complete
Module 01
Introduction to Control Systems Security
An introduction to industrial control systems, their security needs and the consequences of cyber incidents in operational environments.
30 minutes
- Locked
Module 02
Security Awareness in Industrial Environments
Practical security awareness for people who design, operate, maintain and support industrial systems.
25 minutes
- Locked
Module 03
Regulations and Standards Landscape
An orientation to the regulations, standards and guidance commonly encountered in industrial cyber security.
30 minutes
- Locked
Module 04
Overview of the ISA/IEC 62443 Standards Series
A practical map of the ISA/IEC 62443 series and the roles addressed across its parts.
35 minutes
- Locked
Module 05
Fundamental Models and Security Levels
An introduction to foundational IACS security models, zones, conduits and security-level concepts.
40 minutes
Part 2: Lifecycle and Governance
- Locked
Module 06
Introduction to the IACS Cybersecurity Lifecycle
A practical introduction to managing industrial cyber security through the system lifecycle.
30 minutes
- Locked
Module 07
Establishing an Industrial Cybersecurity Management System
The purpose, scope and practical building blocks of an industrial cybersecurity management system.
35 minutes
- Locked
Module 08
Evolving Security Standards and Best Practices
How engineers can monitor, assess and adopt evolving industrial security standards and good practice.
25 minutes
Part 3: Networks and Operations
- Locked
Module 09
Networking Basics for Industrial Control Systems
Essential networking concepts for understanding communications within industrial control systems.
45 minutes
- Locked
Module 10
Network Security Basics in OT Environments
Core defensive principles for segmenting, controlling and monitoring industrial networks.
45 minutes
- Locked
Module 11
Industrial Network Protocols and Their Security Implications
Security implications of common industrial protocols and the assumptions behind their use.
40 minutes
- Locked
Module 12
Patch Management and Malware Protection in IACS
Risk-based patching and malware protection that respects industrial availability and safety constraints.
40 minutes
Part 4: Risk and Supply Chain
- Locked
Module 13
Risk Assessment and Secure System Design
Applying risk assessment to define proportionate security requirements and system architecture.
60 minutes
- Locked
Module 14
Cybersecurity Requirements for IACS Service Providers
Security responsibilities and evidence for integrators, maintainers and other IACS service providers.
40 minutes
- Locked
Module 15
Developing Secure Products and Components
Secure product-development principles for components used within industrial automation and control systems.
60 minutes
Final practical exercise
Produce a concise cyber design basis for Riverside. A second engineer should be able to trace every important requirement back to an unacceptable consequence and forward to a test or review record.
- Essential-function and system-under-consideration statement
- Applicability register and role/responsibility matrix
- Asset, dependency and data-flow records
- Zone-and-conduit diagram with three detailed threat scenarios
- Proposed target security-level vector for important zones and conduits
- Ten verifiable cybersecurity requirements
- Remote-access design and patch/vulnerability decision workflow
- FAT, SAT and restoration tests
- Service-provider evidence schedule and product security evaluation
- Residual-risk and lifecycle review record
Sources and further reading
Course limitations
- The course does not reproduce the normative text of IEC 62443.
- It does not assign a valid security level to a real system.
- It does not replace an asset-owner risk assessment or competent review.
- It does not prove conformity, certification or competence.
- It does not authorise testing on a live IACS.
- Current contractual editions, law, regulator guidance and product instructions always take precedence.