Introduction to Control Systems Security
An introduction to industrial control systems, their security needs and the consequences of cyber incidents in operational environments.
Learning objectives
- Define OT and IACS in practical terms.
- Explain how a cyber event can produce a physical consequence.
- Compare common IT and OT design priorities.
- Challenge common myths about isolated and legacy systems.
- Describe defence-in-depth and detection-in-depth.
Introduction
This module introduces the purpose and scope of practical cyber security for industrial control systems.
Planned video lesson
Video lesson coming soon. The written module can be completed without the video.
Planned recording: 6-8 minutes explaining why an OT cyber incident is an engineering and physical-process problem, using Riverside as the example.
Transcript will be added with the video.
Main lesson
What is being protected?
Operational technology includes programmable systems and devices that monitor, control or influence a physical process. An industrial automation and control system is wider than the PLC cabinet. It includes people, hardware, software, networks, procedures, maintenance tools, configuration files, supporting services and external dependencies.
The security boundary therefore may include:
- Controllers, RTUs, DCS nodes and safety-related systems.
- HMIs, engineering workstations, historians and application servers.
- Network switches, routers, firewalls, wireless infrastructure and serial gateways.
- Vendor laptops, removable media and portable test equipment.
- Identity, time, backup, logging and remote-access services.
- Procedures, competent people and approved ways of working.
A weakness in any one of these can create a route to the process.
Think in consequences, not only data
In enterprise IT, a cyber incident often centres on confidentiality, financial loss or interruption to office services. Those remain relevant in OT, but the final consequence can be physical:
- Loss of process view or control.
- Unauthorised logic, setpoint or configuration changes.
- Suppressed alarms or falsified measurements.
- Equipment damage or premature wear.
- Environmental release.
- Unsafe plant conditions.
- Loss of production or essential service.
- Extended recovery because specialist equipment is obsolete.
The correct starting question is not βWhich cyber product should we buy?β It is βWhich cyber events could prevent the process from remaining safe, controlled and recoverable?β
IT and OT require different engineering decisions
| Consideration | Typical enterprise IT | Typical industrial OT |
|---|---|---|
| Main purpose | Process and protect information | Monitor or control a physical process |
| Typical lifetime | Several years | Often 10-25 years or more |
| Restart | Usually routine | May interrupt production or create process risk |
| Patching | Frequent and centrally managed | Compatibility testing and an approved outage may be required |
| Network traffic | Diverse and frequently changing | Often limited, predictable and process-dependent |
| Main consequence | Data or business impact | Physical, safety, environmental and service impact |
| Recovery | Rebuild or replace may be acceptable | Restore known logic, configuration and process state |
This does not mean availability always overrides security. It means every control must be assessed against the actual process. Automatically isolating a compromised workstation may be sensible. Automatically isolating a controller during a critical process state may create a larger hazard.
Five myths to remove early
- βThe system is air-gapped.β Verify every route: laptops, USB media, cellular modems, wireless links, historian transfers, vendor support and temporary commissioning connections.
- βNobody would target us.β Malware, ransomware, mistakes and supply-chain compromise do not require an attacker to know the site exists.
- βIt uses a proprietary protocol.β Obscurity does not provide authentication, authorisation or integrity.
- βA firewall makes the system secure.β A firewall controls some communications. It does not correct weak accounts, unsafe maintenance, unsupported products or poor recovery.
- βSafety and security are separate.β A cyber event can challenge the basic process control system, alarms, operator response and protective layers at the same time.
Defence and detection in depth
Defence-in-depth uses independent and mutually supporting controls. Typical layers include physical security, controlled identities, hardened devices, segmented networks, protected applications, secure engineering processes and independent safety functions.
Detection-in-depth asks how abnormal activity will be noticed at each layer. Logs, network monitoring, configuration comparison, alarm review, access records and operator reporting should provide several opportunities to detect a problem before it becomes a major consequence.
Planned original figure β M01-F01
Create an original consequence chain: cyber entry point to loss of view or control, physical process deviation, and business, safety or environmental outcome.
Planned asset: /static/training/ot-cyber-security/module-01/figure-01.svg
Engineering example
Riverside application
Riverside shows why the security boundary extends beyond the PLC to the people, tools, services and connections that can influence the process.
Practical activity
Apply what you learned
Write three unacceptable outcomes before listing threats:
- Pumps run outside safe hydraulic limits.
- Operators lose trustworthy indication during a developing fault.
- The station cannot be restored within the agreed recovery time.
Then identify at least two cyber paths to each outcome. This consequence-first method stops the assessment becoming a generic list of malware names.
Record your reasoning and project notes here. Your response stays in this browser and is not submitted to the website.
Loading saved responseβ¦
0 / 10,000Do not enter real credentials, confidential network details, sensitive asset information or security-sensitive project data.
Knowledge check
Answer every question correctly to complete this module. If an answer is incorrect, review the explanation and try again. This is not a formal examination.
Key takeaways
Remember these points
OT cyber incidents can create physical, safety, environmental and service consequences.
The IACS boundary includes people, procedures, support tools and external dependencies as well as controllers.
Defence-in-depth needs corresponding opportunities to detect abnormal behaviour.
Relevant standards and guidance
This module uses original explanatory language. Consult the applicable editions and project requirements rather than treating this lesson as normative text.
- ISA/IEC 62443 series
- NIST SP 800-82 Rev. 3
Further reading
- NCSC β Operational Technology guidance collection
- NCSC β Cyber Assessment Framework
- NIST SP 800-82 Rev. 3 β Guide to Operational Technology Security
- CISA β Industrial Control Systems recommended practices
Last reviewed
15 July 2026.
Complete the knowledge check above and answer every question correctly to unlock module completion.
Progress is stored only in this browser and is not a certificate or formal training record.