Skip to main content

OT Security Professional

Four days remote on a running plant: how it is built and how it talks, the routes in, standards and regulation, detection and response.

Training rack with a VIPA controller, a SIMATIC S7-1500 and Siemens input and output modules.
Trusted by
Introduction

A plant is no longer a world of its own

For decades industrial plants stood apart: their own network, their own protocols, no way out. That no longer holds. Remote maintenance by the manufacturer, production data in the ERP system, radio links to outlying sites, a service laptop in the cabinet. A plant hangs off the IT network today, usually in several places at once.

Attackers use it. Stuxnet, the Ukrainian power grid, Triton, Colonial Pipeline and FrostyGoop show the same development: it began with states and years of preparation, and by now ransomware that never aimed at production is enough to stop it.

The protocols in between know no authentication, because the network counted as closed when they were designed. And a plant still cannot be treated like a server room: availability comes before confidentiality, a patch is a matter of months, a restart costs production.

Day 1

Foundations

What an industrial plant is, and why it resists an IT mindset.

  • OT against IT. Protection goals, life cycles, operating philosophy
  • Safety and security. How they interact, and where measures fail
  • Roles. Asset owner, integrator, manufacturer, security officer, and the gaps between
  • Components. PLC, RTU, HMI, SCADA, DCS, historian, SIS
  • Purdue model. Levels 0 to 4 and the transitions
  • Exercise. Explore the lab plant and place its components
Day 2

Protocols and threats

How industrial systems talk to one another, and what can be attacked in that.

  • Modbus, S7comm, OPC UA. Structure, address spaces, missing authentication
  • Profinet, IEC 104, IEC 61850, fieldbus. Where each belongs
  • Threat actors and routes in. From the supply chain to the insider
  • Case studies. Stuxnet, Ukraine, Triton, Colonial Pipeline, FrostyGoop
  • MITRE ATT&CK for ICS. The shared vocabulary
  • Two exercises. Work through a capture; shift a process value over Modbus
Day 3

Standards, regulation and architecture

What is required, and how a plant ought to be cut.

  • IEC 62443. Zones, conduits, security levels
  • Other frameworks. ISO 27019, NIST SP 800-82, the BSI ICS compendium, and which is good for what
  • Regulation. NIS2, the KRITIS umbrella act, the CRA, with reporting routes and deadlines
  • Network architecture. Segmentation along the Purdue levels, the industrial DMZ
  • Remote access. VPN, jump hosts, vendor remote maintenance
  • Exercise. A zone and conduit concept for the course plant
Day 4

Protection, detection and response

What an operator actually does.

  • Asset management. Passive against active discovery, data quality in the inventory
  • Hardening and backup. Patch management, whitelisting, PLC program states
  • Detection. OT IDS, SPAN and TAP, signature against anomaly, selection criteria
  • SIEM and use cases. What the SIEM is for, and use cases along MITRE ATT&CK for ICS
  • Incident response. Safety first, containment without stopping production, the BSI contact point
  • Reporting duties. NIS2 and KRITIS applied
  • Incident drill. 90 minutes with assigned roles on the YekCity simulator
Audience

Who the training is aimed at

  • OT managers and plant management who have to place security requirements against their installations
  • Automation engineers for whom security has been a side issue
  • IT and cybersecurity people new to OT
  • Auditors and consultants assessing OT environments
  • Decision makers who justify investment or read test reports

Basic IT, networking and IT security are assumed. An automation background is not: the course starts with the question of what separates a controller from a server. Anyone already deep in OT security and after craft belongs in the Expert.

The lab

The exercises run on a plant that is live

The lab plant covers several Purdue levels, from the field up to the operator interface, and speaks the same protocols the lectures deal with. Four guided exercises run across the first three days.

The manipulation on day two is the turning point: it succeeds with a single command and no authentication, and the display in the control room stays plausible. The incident drill on day four runs on the YekCity simulator, a model city built with real Siemens and Schneider controllers.

Key facts

Format, length, assessment

Format

Remote, in-house or as an open course.

Length

Four days, 32 teaching units.

Hands-on

Around 40 per cent. Four exercises and an incident drill.

Assessment

An exam of 40 questions and the incident drill.

Prerequisites

IT, networking and IT security at a basic level.

Language

German.

Common questions

Common questions about the Professional

Both depend on whether you book in-house or places on an open course. Tell us the number of people as well. Ask us and you get dates and a price with a named contact.

No. Basic IT, networking and IT security are enough. If you want to brush up beforehand, a two-hour e-learning module on IT basics and the Purdue model is available.

A laptop with internet access. The lab runs in the browser or through accounts we provide, and nothing needs installing.

The certificate states scope, content, exam result and the drill, and is usable as evidence of regular training. Whether it suffices in your case is for your regulator to decide.

Certifications held in the team
Memberships
Next step

Ask for dates and terms.

Tell us whether you are after an in-house course or places on an open one, and for how many people. You get dates, a price and a named contact.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Location
Dortmund
Ruhrallee 9 · 44139