Security Awareness in Industrial Environments
Practical security awareness for people who design, operate, maintain and support industrial systems.
Learning objectives
- Explain why awareness is a risk control rather than a yearly presentation.
- Tailor training for operators, engineers, managers and third parties.
- Identify behaviours that commonly introduce OT risk.
- Define simple evidence that an awareness programme is working.
Introduction
This module considers security awareness in the context of practical industrial engineering work.
Planned video lesson
Video lesson coming soon. The written module can be completed without the video.
Planned recording: 5-7 minutes showing how the same cyber event requires different actions from an operator, controls engineer and manager.
Transcript will be added with the video.
Main lesson
People, process and technology
IEC 62443 treats security as a combination of people, processes and technology. Technology is applied through procedures, and procedures are carried out by people with assigned responsibilities. A technically strong design can therefore be defeated by an unapproved laptop, a shared administrator account or a contractor who does not know how to report an anomaly.
Awareness should teach people what a secure action looks like in their role.
| Role | Training emphasis | Practical behaviour |
|---|---|---|
| Operators | Recognising abnormal plant and interface behaviour | Report unexpected alarms, screens, restarts and control changes promptly |
| Control engineers | Secure configuration and change control | Use approved tools, named accounts and traceable backups |
| Maintainers | Media, portable devices and remote support | Scan and authorise equipment before connection |
| Managers | Risk ownership and resourcing | Protect maintenance windows, competence and lifecycle support budgets |
| IT support | OT constraints and escalation | Do not scan, isolate, patch or reboot OT without an agreed method |
| Vendors | Site rules and evidence | Use the approved access route and record every change |
High-value awareness topics
Generic phishing training is useful but insufficient. OT-specific awareness should include:
- Default and shared credentials.
- Removable media and portable engineering devices.
- Temporary modems, wireless access points and unmanaged switches.
- Remote-support approval and session supervision.
- Unexpected controller, HMI or network behaviour.
- Secure handling of logic, configuration and backup files.
- Social engineering aimed at operations and maintenance staff.
- The difference between reporting a concern and diagnosing it alone.
- Emergency routes when normal communications are unavailable.
Training should be short, repeated and connected to real tasks. A five-minute pre-job briefing before a shutdown may prevent more risk than an annual hour-long slide deck.
Exercises reveal more than attendance records
Useful activities include:
- A tabletop exercise for a loss-of-view event.
- A controlled demonstration of an unauthorised USB device.
- A walk-through of the approved remote-access route.
- A red-team / blue-team exercise in an isolated training environment.
- A restoration drill using a verified controller backup.
- A short scenario asking staff who must be contacted and what evidence must be preserved.
Never demonstrate malware or active attack techniques on a live control system.
Measure behaviour and readiness
Completion rates show attendance, not competence. Better indicators include:
- Percentage of privileged accounts assigned to named people.
- Number of unapproved connection paths found during inspection.
- Time taken to report and escalate an abnormal event.
- Percentage of contractors briefed before access.
- Restoration exercises completed successfully.
- Repeated causes found in change and incident reviews.
The purpose is improvement, not punishment. People will hide small anomalies if the reporting culture blames the reporter.
Planned original figure β M02-F01
Create a role-to-risk matrix showing operator, engineer, IT, manager and vendor responsibilities across normal operation, maintenance and incident response.
Planned asset: /static/training/ot-cyber-security/module-02/figure-01.svg
Engineering example
Riverside application
At Riverside, operators, engineers, IT support, managers and vendors each see different warning signs and control different sources of risk.
Practical activity
Apply what you learned
Create a one-page briefing for a vendor engineer connecting to Riverside. It should state:
- The approved connection route.
- The named person authorising the session.
- Prohibited devices and connections.
- How changes will be recorded.
- How unexpected behaviour will be reported.
- How the session will be closed and checked.
Record your reasoning and project notes here. Your response stays in this browser and is not submitted to the website.
Loading saved responseβ¦
0 / 10,000Do not enter real credentials, confidential network details, sensitive asset information or security-sensitive project data.
Knowledge check
Answer every question correctly to complete this module. If an answer is incorrect, review the explanation and try again. This is not a formal examination.
Key takeaways
Remember these points
Awareness is effective when it changes role-specific behaviour, not when it records attendance alone.
Engineering laptops, removable media, remote support and temporary connections require OT-specific instruction.
A constructive reporting culture helps weak signals reach the right people early.
Relevant standards and guidance
This module uses original explanatory language. Consult the applicable editions and project requirements rather than treating this lesson as normative text.
- ISA/IEC 62443-2-1
- NIST SP 800-82 Rev. 3
Further reading
- NCSC CAF Objective B β Protecting against cyber attacks, including staff awareness and training
- NCSC β Creating and maintaining a definitive view of your OT architecture
- NIST SP 800-82 Rev. 3 β OT roles, training and awareness guidance
- CISA β Cross-Sector Cybersecurity Performance Goals 2.0
Last reviewed
15 July 2026.
Complete the knowledge check above and answer every question correctly to unlock module completion.
Progress is stored only in this browser and is not a certificate or formal training record.