Skip to content
Part 1 Β· Module 2 of 15Course syllabus
Course progress0%
Module 2 of 15Part 1: Foundations

Security Awareness in Industrial Environments

Practical security awareness for people who design, operate, maintain and support industrial systems.

25 minutesFoundationReviewed 15 July 2026
Course progress0%

Learning objectives

  • Explain why awareness is a risk control rather than a yearly presentation.
  • Tailor training for operators, engineers, managers and third parties.
  • Identify behaviours that commonly introduce OT risk.
  • Define simple evidence that an awareness programme is working.

Introduction

This module considers security awareness in the context of practical industrial engineering work.

Planned video lesson

Module 02 video lesson

Video lesson coming soon. The written module can be completed without the video.

Planned recording: 5-7 minutes showing how the same cyber event requires different actions from an operator, controls engineer and manager.

Transcript will be added with the video.

Main lesson

People, process and technology

IEC 62443 treats security as a combination of people, processes and technology. Technology is applied through procedures, and procedures are carried out by people with assigned responsibilities. A technically strong design can therefore be defeated by an unapproved laptop, a shared administrator account or a contractor who does not know how to report an anomaly.

Awareness should teach people what a secure action looks like in their role.

RoleTraining emphasisPractical behaviour
OperatorsRecognising abnormal plant and interface behaviourReport unexpected alarms, screens, restarts and control changes promptly
Control engineersSecure configuration and change controlUse approved tools, named accounts and traceable backups
MaintainersMedia, portable devices and remote supportScan and authorise equipment before connection
ManagersRisk ownership and resourcingProtect maintenance windows, competence and lifecycle support budgets
IT supportOT constraints and escalationDo not scan, isolate, patch or reboot OT without an agreed method
VendorsSite rules and evidenceUse the approved access route and record every change

High-value awareness topics

Generic phishing training is useful but insufficient. OT-specific awareness should include:

  • Default and shared credentials.
  • Removable media and portable engineering devices.
  • Temporary modems, wireless access points and unmanaged switches.
  • Remote-support approval and session supervision.
  • Unexpected controller, HMI or network behaviour.
  • Secure handling of logic, configuration and backup files.
  • Social engineering aimed at operations and maintenance staff.
  • The difference between reporting a concern and diagnosing it alone.
  • Emergency routes when normal communications are unavailable.

Training should be short, repeated and connected to real tasks. A five-minute pre-job briefing before a shutdown may prevent more risk than an annual hour-long slide deck.

Exercises reveal more than attendance records

Useful activities include:

  • A tabletop exercise for a loss-of-view event.
  • A controlled demonstration of an unauthorised USB device.
  • A walk-through of the approved remote-access route.
  • A red-team / blue-team exercise in an isolated training environment.
  • A restoration drill using a verified controller backup.
  • A short scenario asking staff who must be contacted and what evidence must be preserved.

Never demonstrate malware or active attack techniques on a live control system.

Measure behaviour and readiness

Completion rates show attendance, not competence. Better indicators include:

  • Percentage of privileged accounts assigned to named people.
  • Number of unapproved connection paths found during inspection.
  • Time taken to report and escalate an abnormal event.
  • Percentage of contractors briefed before access.
  • Restoration exercises completed successfully.
  • Repeated causes found in change and incident reviews.

The purpose is improvement, not punishment. People will hide small anomalies if the reporting culture blames the reporter.

Planned original figure β€” M02-F01

Create a role-to-risk matrix showing operator, engineer, IT, manager and vendor responsibilities across normal operation, maintenance and incident response.

Planned asset: /static/training/ot-cyber-security/module-02/figure-01.svg

Engineering example

Riverside application

At Riverside, operators, engineers, IT support, managers and vendors each see different warning signs and control different sources of risk.

Practical activity

Apply what you learned

Create a one-page briefing for a vendor engineer connecting to Riverside. It should state:

  • The approved connection route.
  • The named person authorising the session.
  • Prohibited devices and connections.
  • How changes will be recorded.
  • How unexpected behaviour will be reported.
  • How the session will be closed and checked.

Record your reasoning and project notes here. Your response stays in this browser and is not submitted to the website.

Loading saved response…

0 / 10,000

Do not enter real credentials, confidential network details, sensitive asset information or security-sensitive project data.

Knowledge check

Answer every question correctly to complete this module. If an answer is incorrect, review the explanation and try again. This is not a formal examination.

1. Every maintainer completed annual awareness training, but two unapproved USB devices were found connected during a shutdown. What does this show?
2. Which pre-job briefing gives a vendor engineer the most useful OT security direction?
3. An operator notices an unexpected HMI restart immediately after a remote-support session. What is the best first action?
0 of 3 questions answered correctly.

Key takeaways

Remember these points

  • Awareness is effective when it changes role-specific behaviour, not when it records attendance alone.

  • Engineering laptops, removable media, remote support and temporary connections require OT-specific instruction.

  • A constructive reporting culture helps weak signals reach the right people early.

Relevant standards and guidance

This module uses original explanatory language. Consult the applicable editions and project requirements rather than treating this lesson as normative text.

  • ISA/IEC 62443-2-1
  • NIST SP 800-82 Rev. 3

Further reading

Last reviewed

15 July 2026.

Complete the knowledge check above and answer every question correctly to unlock module completion.

Progress is stored only in this browser and is not a certificate or formal training record.