OT Security Training: Professional and Expert
Two stages, one building on the other. The Professional runs remotely on a live lab plant and closes with an examination. The Expert stands in front of real controllers, on site.
Why OT security needs its own training
A plant controls a physical process. It stays largely in the same configuration across its life cycle. Restarts and patches depend on planned shutdowns, and how often those come is decided by the process. Some of its protocols date from the era of closed networks and still transmit without authentication, Modbus TCP or classic S7comm among them. OPC UA does provide for authentication and encryption. Whether they are switched on in a given case is a question to be checked. On top of that, the plant now hangs off remote maintenance, ERP and service laptops.
Our OT training starts exactly there. Both stages end at a plant communicating over IEC 60870-5-104, IEC 61850, Modbus TCP and OPC UA.
Which stage suits whom
Which stage fits depends less on a job title than on what is to be done afterwards.
OT Security Professional, four days remote, 32 teaching units. For everyone who has to place security requirements against a plant. It covers the components and protocols of a plant, the requirements of IEC 62443 and NIS2, and network architecture and incident response. Work runs on a live lab plant, with around 40 per cent of the time spent on exercises. It closes with an exam of forty questions and an incident drill with assigned roles.
OT Security Expert, three days on site, 24 teaching units. For everyone who has to produce and substantiate findings. Protocols byte by byte, attacks run under control, detection rules written on your own recordings and checked against them to see whether they fire. Around 80 per cent of the course is hands-on exercises. The Professional is the prerequisite where there is no comparable practice.
Who takes which route. Managers and newcomers are served by the Professional. SOC and control room staff need both, an understanding of the process and the ability to write and test a rule. Security staff with an OT remit start at the Expert once the foundations are in place. That stage is about reading protocols yourself, running attacks under control and writing detection rules.
The full syllabus sits on each page, so that it is maintained in one place rather than two.
Tabletop exercise
Knowledge is one thing; making the right decision under pressure is another.
A tabletop exercise is a facilitated simulation of a security incident. No code, no tools. A scenario, a room, and the people who would have to work together on the day. New information arrives in real time, and decisions get made without the full picture. Typical scenarios:
- Ransomware spreading towards the OT
- A suspicious firmware change on a PLC
- An unknown remote access at night
- Anomalous process values with no recognisable cause
What gets practised is escalation and communication, decisions under uncertainty, cooperation between IT, OT, production and management, and the judgement between safety, security and availability. The scenarios are built together with you, so that they fit your plant, your sector and your risks.
Duration: 2 to 4 hours. Result: documented lessons learned, identified gaps in the processes, a plan of measures.
Red and blue team exercise on YekCity
YekCity is our model city with power supply and industrial plant. Real controllers from Siemens and Schneider, real protocols with Modbus, S7comm, OPC UA, IEC 60870-5-104 and IEC 61850, real attacks. The scenarios come from documented incidents, among them the Industroyer attack on a Ukrainian substation, which used IEC 60870-5-104 and IEC 61850.
In the red and blue format our red team attacks and your blue team detects and stops. The lights go out, processes stop, under control and by agreement. In the purple variant both work together and review after each phase: what was detected, what was not, and why? Which use cases are missing from the SIEM, where does the playbook not hold? The format is iterative and produces improvements rather than a snapshot.
What gets examined is coverage against MITRE ATT&CK for ICS, alert quality and triage capability, response time and the effectiveness of the playbooks, and coordination between the IT SOC and OT engineering.
The format suits the close of a SOC build particularly well: it shows whether the capabilities built hold on the day. Basic detection with an OT IDS and a SIEM connection should be in place for it.
For rail and vehicles
For security staff in the rail industry we have developed a course of its own that works on YekTrain: MVB and CANopen, forged telegrams, intrusion detection on the vehicle bus, and building a rail SOC.
For the vehicle environment the equivalent format runs on YekCar, with CAN, diagnostics over UDS and keyless entry systems. Crisis exercises for utilities and municipalities run on YekCity. All three rigs come out of our research and work with real technology.
Common questions about OT training
For the Professional we assume basics in IT, networking and IT security, but no automation background. For the Expert, the Professional or equivalent hands-on experience comes on top.
Professional closes with an examination of forty questions, plus the incident exercise. Both are certified and can be used as evidence of regular training under NIS2.
Train yes, attack no. The exercises run on the lab plant or on our rigs. In a production plant we work passively and in an agreed window.
For the Expert, eight to twelve, in teams of two or three, so that everyone gets to the controllers and the measuring equipment. Professional runs remotely and takes more.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.