Skip to content
Part 1 Β· Module 1 of 15Course syllabus
Course progress0%
Module 1 of 15Part 1: Foundations

Introduction to Control Systems Security

An introduction to industrial control systems, their security needs and the consequences of cyber incidents in operational environments.

30 minutesFoundationReviewed 15 July 2026
Course progress0%

Learning objectives

  • Define OT and IACS in practical terms.
  • Explain how a cyber event can produce a physical consequence.
  • Compare common IT and OT design priorities.
  • Challenge common myths about isolated and legacy systems.
  • Describe defence-in-depth and detection-in-depth.

Introduction

This module introduces the purpose and scope of practical cyber security for industrial control systems.

Planned video lesson

Module 01 video lesson

Video lesson coming soon. The written module can be completed without the video.

Planned recording: 6-8 minutes explaining why an OT cyber incident is an engineering and physical-process problem, using Riverside as the example.

Transcript will be added with the video.

Main lesson

What is being protected?

Operational technology includes programmable systems and devices that monitor, control or influence a physical process. An industrial automation and control system is wider than the PLC cabinet. It includes people, hardware, software, networks, procedures, maintenance tools, configuration files, supporting services and external dependencies.

The security boundary therefore may include:

  • Controllers, RTUs, DCS nodes and safety-related systems.
  • HMIs, engineering workstations, historians and application servers.
  • Network switches, routers, firewalls, wireless infrastructure and serial gateways.
  • Vendor laptops, removable media and portable test equipment.
  • Identity, time, backup, logging and remote-access services.
  • Procedures, competent people and approved ways of working.

A weakness in any one of these can create a route to the process.

Think in consequences, not only data

In enterprise IT, a cyber incident often centres on confidentiality, financial loss or interruption to office services. Those remain relevant in OT, but the final consequence can be physical:

  • Loss of process view or control.
  • Unauthorised logic, setpoint or configuration changes.
  • Suppressed alarms or falsified measurements.
  • Equipment damage or premature wear.
  • Environmental release.
  • Unsafe plant conditions.
  • Loss of production or essential service.
  • Extended recovery because specialist equipment is obsolete.

The correct starting question is not β€œWhich cyber product should we buy?” It is β€œWhich cyber events could prevent the process from remaining safe, controlled and recoverable?”

IT and OT require different engineering decisions

ConsiderationTypical enterprise ITTypical industrial OT
Main purposeProcess and protect informationMonitor or control a physical process
Typical lifetimeSeveral yearsOften 10-25 years or more
RestartUsually routineMay interrupt production or create process risk
PatchingFrequent and centrally managedCompatibility testing and an approved outage may be required
Network trafficDiverse and frequently changingOften limited, predictable and process-dependent
Main consequenceData or business impactPhysical, safety, environmental and service impact
RecoveryRebuild or replace may be acceptableRestore known logic, configuration and process state

This does not mean availability always overrides security. It means every control must be assessed against the actual process. Automatically isolating a compromised workstation may be sensible. Automatically isolating a controller during a critical process state may create a larger hazard.

Five myths to remove early

  1. β€œThe system is air-gapped.” Verify every route: laptops, USB media, cellular modems, wireless links, historian transfers, vendor support and temporary commissioning connections.
  2. β€œNobody would target us.” Malware, ransomware, mistakes and supply-chain compromise do not require an attacker to know the site exists.
  3. β€œIt uses a proprietary protocol.” Obscurity does not provide authentication, authorisation or integrity.
  4. β€œA firewall makes the system secure.” A firewall controls some communications. It does not correct weak accounts, unsafe maintenance, unsupported products or poor recovery.
  5. β€œSafety and security are separate.” A cyber event can challenge the basic process control system, alarms, operator response and protective layers at the same time.

Defence and detection in depth

Defence-in-depth uses independent and mutually supporting controls. Typical layers include physical security, controlled identities, hardened devices, segmented networks, protected applications, secure engineering processes and independent safety functions.

Detection-in-depth asks how abnormal activity will be noticed at each layer. Logs, network monitoring, configuration comparison, alarm review, access records and operator reporting should provide several opportunities to detect a problem before it becomes a major consequence.

Planned original figure β€” M01-F01

Create an original consequence chain: cyber entry point to loss of view or control, physical process deviation, and business, safety or environmental outcome.

Planned asset: /static/training/ot-cyber-security/module-01/figure-01.svg

Engineering example

Riverside application

Riverside shows why the security boundary extends beyond the PLC to the people, tools, services and connections that can influence the process.

Practical activity

Apply what you learned

Write three unacceptable outcomes before listing threats:

  1. Pumps run outside safe hydraulic limits.
  2. Operators lose trustworthy indication during a developing fault.
  3. The station cannot be restored within the agreed recovery time.

Then identify at least two cyber paths to each outcome. This consequence-first method stops the assessment becoming a generic list of malware names.

Record your reasoning and project notes here. Your response stays in this browser and is not submitted to the website.

Loading saved response…

0 / 10,000

Do not enter real credentials, confidential network details, sensitive asset information or security-sensitive project data.

Knowledge check

Answer every question correctly to complete this module. If an answer is incorrect, review the explanation and try again. This is not a formal examination.

1. A PLC has no default gateway, but it is programmed from a laptop and sends data through a historian. Which conclusion is best?
2. An engineering workstation is suspected of compromise while the process is stable. What should determine the containment action?
3. Which statement correctly relates defence-in-depth and detection-in-depth?
0 of 3 questions answered correctly.

Key takeaways

Remember these points

  • OT cyber incidents can create physical, safety, environmental and service consequences.

  • The IACS boundary includes people, procedures, support tools and external dependencies as well as controllers.

  • Defence-in-depth needs corresponding opportunities to detect abnormal behaviour.

Relevant standards and guidance

This module uses original explanatory language. Consult the applicable editions and project requirements rather than treating this lesson as normative text.

  • ISA/IEC 62443 series
  • NIST SP 800-82 Rev. 3

Further reading

Last reviewed

15 July 2026.

Complete the knowledge check above and answer every question correctly to unlock module completion.

Progress is stored only in this browser and is not a certificate or formal training record.