OT Security Professional
Four days remote on a running plant: how it is built and how it talks, the routes in, standards and regulation, detection and response.
A plant is no longer a world of its own
For decades industrial plants stood apart: their own network, their own protocols, no way out. That no longer holds. Remote maintenance by the manufacturer, production data in the ERP system, radio links to outlying sites, a service laptop in the cabinet. A plant hangs off the IT network today, usually in several places at once.
Attackers use it. Stuxnet, the Ukrainian power grid, Triton, Colonial Pipeline and FrostyGoop show the same development: it began with states and years of preparation, and by now ransomware that never aimed at production is enough to stop it.
The protocols in between know no authentication, because the network counted as closed when they were designed. And a plant still cannot be treated like a server room: availability comes before confidentiality, a patch is a matter of months, a restart costs production.
Foundations
What an industrial plant is, and why it resists an IT mindset.
- OT against IT. Protection goals, life cycles, operating philosophy
- Safety and security. How they interact, and where measures fail
- Roles. Asset owner, integrator, manufacturer, security officer, and the gaps between
- Components. PLC, RTU, HMI, SCADA, DCS, historian, SIS
- Purdue model. Levels 0 to 4 and the transitions
- Exercise. Explore the lab plant and place its components
Protocols and threats
How industrial systems talk to one another, and what can be attacked in that.
- Modbus, S7comm, OPC UA. Structure, address spaces, missing authentication
- Profinet, IEC 104, IEC 61850, fieldbus. Where each belongs
- Threat actors and routes in. From the supply chain to the insider
- Case studies. Stuxnet, Ukraine, Triton, Colonial Pipeline, FrostyGoop
- MITRE ATT&CK for ICS. The shared vocabulary
- Two exercises. Work through a capture; shift a process value over Modbus
Standards, regulation and architecture
What is required, and how a plant ought to be cut.
- IEC 62443. Zones, conduits, security levels
- Other frameworks. ISO 27019, NIST SP 800-82, the BSI ICS compendium, and which is good for what
- Regulation. NIS2, the KRITIS umbrella act, the CRA, with reporting routes and deadlines
- Network architecture. Segmentation along the Purdue levels, the industrial DMZ
- Remote access. VPN, jump hosts, vendor remote maintenance
- Exercise. A zone and conduit concept for the course plant
Protection, detection and response
What an operator actually does.
- Asset management. Passive against active discovery, data quality in the inventory
- Hardening and backup. Patch management, whitelisting, PLC program states
- Detection. OT IDS, SPAN and TAP, signature against anomaly, selection criteria
- SIEM and use cases. What the SIEM is for, and use cases along MITRE ATT&CK for ICS
- Incident response. Safety first, containment without stopping production, the BSI contact point
- Reporting duties. NIS2 and KRITIS applied
- Incident drill. 90 minutes with assigned roles on the YekCity simulator
Who the training is aimed at
- OT managers and plant management who have to place security requirements against their installations
- Automation engineers for whom security has been a side issue
- IT and cybersecurity people new to OT
- Auditors and consultants assessing OT environments
- Decision makers who justify investment or read test reports
Basic IT, networking and IT security are assumed. An automation background is not: the course starts with the question of what separates a controller from a server. Anyone already deep in OT security and after craft belongs in the Expert.
The exercises run on a plant that is live
The lab plant covers several Purdue levels, from the field up to the operator interface, and speaks the same protocols the lectures deal with. Four guided exercises run across the first three days.
The manipulation on day two is the turning point: it succeeds with a single command and no authentication, and the display in the control room stays plausible. The incident drill on day four runs on the YekCity simulator, a model city built with real Siemens and Schneider controllers.
Format, length, assessment
Format
Remote, in-house or as an open course.
Length
Four days, 32 teaching units.
Hands-on
Around 40 per cent. Four exercises and an incident drill.
Assessment
An exam of 40 questions and the incident drill.
Prerequisites
IT, networking and IT security at a basic level.
Language
German.
Common questions about the Professional
Both depend on whether you book in-house or places on an open course. Tell us the number of people as well. Ask us and you get dates and a price with a named contact.
No. Basic IT, networking and IT security are enough. If you want to brush up beforehand, a two-hour e-learning module on IT basics and the Purdue model is available.
A laptop with internet access. The lab runs in the browser or through accounts we provide, and nothing needs installing.
The certificate states scope, content, exam result and the drill, and is usable as evidence of regular training. Whether it suffices in your case is for your regulator to decide.
Ask for dates and terms.
Tell us whether you are after an in-house course or places on an open one, and for how many people. You get dates, a price and a named contact.