OT training: Professional and Expert
Two levels, each with a fixed shape. Professional runs remotely on a virtual waterworks and closes with an examination; Expert runs in person in front of real controllers.
IT knowledge carries only half the way in a plant
Whoever knows IT security knows attack patterns, tools and method. In automation the constraints change: there is no patching, there is no scanning, availability comes before confidentiality, and the protocols know neither authentication nor encryption.
Our OT training starts at that gap, and both levels end at a plant. What runs there runs with IEC 60870-5-104, IEC 61850, Modbus TCP and OPC UA, which is to say with what speaks in your plant too.
From understanding to doing it yourself
Professional runs over four days remotely, 32 teaching units, on a virtual waterworks across three levels: an HMI with OPC UA, the control level with Modbus TCP, and below it a pump and a tank. Attacking and detecting happen on that rig, not on examples. It closes with an examination of forty questions and an incident exercise with distributed roles.
Expert runs over three days in person, in front of real controllers and with measuring equipment. Here the participants write the detection rules themselves, up to a rule that fires on a write command, and check against a capture whether it holds.
Professional is the precondition for Expert, unless equivalent practice exists.
Three roles, two routes
Which level fits depends less on the job title than on what is to be done afterwards.
Decision-makers and newcomers
Professional. Afterwards you know how a plant is built, which attacks are documented and what they set off, and you have taken part in an incident exercise.
SOC and control room
Professional, then Expert. Whoever has to assess alerts from a plant needs both: an understanding of the process and the ability to write a rule and test it.
Security staff with an OT remit
Expert, once the foundations are there. The emphasis is on measuring equipment, captures and detection rules of your own.
What the first level covers
Whoever is responsible for OT security does not have to analyse protocols. What they have to understand is how industrial environments are built, which threats take hold there and what the regulator requires.
Foundations. What a PLC is and why it works differently from a server. HMI, SCADA system and historian. The layout of a typical OT architecture and the transitions between IT and OT.
Security concepts. Network segmentation in OT environments. What IEC 62443 concretely requires, which zones and security levels are relevant, and what follows from that for your own organisation. What part machine builders, integrators and maintenance providers play in the attack surface.
Real attacks. What actually worked in Stuxnet, Industroyer and Triton, and what follows from it.
Regulation. What NIS2, the German KRITIS regulation and the IT Security Act require, and what that means for decisions and budget.
What the second level covers
Protocols. Modbus, with no authentication and no encryption. S7comm, the Siemens protocol found in many production environments. OPC UA, with security mechanisms that are frequently misconfigured in practice. IEC 60870-5-104 and IEC 61850 from energy supply, both with attack surfaces of their own.
Attacks. How attackers get from IT into OT and what lateral movement through segmentation gaps concretely looks like. Industroyer manipulates protection relays over IEC 104 and IEC 61850. Triton attacks Triconex safety systems over proprietary protocols. Pipedream is modular and can be used against several controller platforms. The analysis is grounded in MITRE ATT&CK for ICS.
Detection. OT IDS technologies, use case development to MITRE ATT&CK for ICS, SIEM integration, and anomaly detection for industrial protocols.
Response. Containment without stopping production, forensics on the PLC, and coordination between IT security and OT engineering.
Tabletop exercise
Knowledge is one thing; making the right decision under pressure is another.
A tabletop exercise is a facilitated simulation of a security incident. No code, no tools. A scenario, a room, and the people who would have to work together on the day. New information arrives in real time, and decisions get made without the full picture. Typical scenarios:
- Ransomware spreading towards the OT
- A suspicious firmware change on a PLC
- An unknown remote access at night
- Anomalous process values with no recognisable cause
What gets practised is escalation and communication, decisions under uncertainty, cooperation between IT, OT, production and management, and the judgement between safety, security and availability. The scenarios are built together with you, so that they fit your plant, your sector and your risks.
Duration: 2 to 4 hours. Result: documented lessons learned, identified gaps in the processes, a plan of measures.
Red and blue team exercise on YekCity
YekCity is our model city with power supply, traffic control and industrial plant. Real controllers from Siemens and Schneider, real protocols with Modbus, S7comm, OPC UA, IEC 60870-5-104 and IEC 61850, real attacks. The scenarios come from documented incidents, among them the Industroyer attack on Ukrainian substations, which used exactly these protocols.
In the red and blue format our red team attacks and your blue team detects and stops. The lights go out, traffic signals fail, processes stop, under control and by agreement. In the purple variant both work together and review after each phase: what was detected, what was not, and why? Which use cases are missing from the SIEM, where does the playbook not hold? The format is iterative and produces improvements rather than a snapshot.
What gets examined is coverage against MITRE ATT&CK for ICS, alert quality and triage capability, response time and the effectiveness of the playbooks, and coordination between the IT SOC and OT engineering.
The format suits the close of a SOC build particularly well: it shows whether the capabilities built hold on the day. Basic detection with an OT IDS and a SIEM connection should be in place for it.
For rail and vehicles
For security staff in the rail industry we have developed a course of its own that works on YekTrain: MVB and CANopen, forged telegrams, intrusion detection on the vehicle bus, and building a rail SOC.
For the vehicle environment the equivalent format runs on YekCar, with CAN, diagnostics over UDS and keyless entry systems. Crisis exercises for utilities and municipalities run on YekCity. All three rigs come out of our research and work with real technology.
How the two levels run
Professional: four days remotely, 32 teaching units, with an examination. Expert: three days in person in front of real controllers. Professional is the precondition for Expert, unless equivalent practice exists.
Placement
Who is to take part, and what has to be done afterwards. For decision-makers Professional is enough; whoever has to assess alerts from a plant needs both.
Professional, four days remotely
Foundations, security concepts, real attacks and regulation, practised on a virtual waterworks across three levels. It closes with an examination of forty questions and an incident exercise with distributed roles.
Expert, three days in person
Protocols, attacks, detection and response in front of real controllers and with measuring equipment. Participants write their detection rules themselves and check against a capture whether they hold.
Certificate
The examination and the incident exercise are certified and can be used as evidence of regular training under NIS2.
Common questions about OT training
For Professional, no. Basic networking knowledge helps; the rest we bring. For Expert we assume Professional or equivalent practice.
Professional closes with an examination of forty questions, plus the incident exercise. Both are certified and can be used as evidence of regular training under NIS2.
Train yes, attack no. The exercises run on the virtual waterworks or on our rigs. In a production plant we work passively and in an agreed window.
For Expert, six to twelve, so that everyone gets to the controllers and the measuring equipment. Professional runs remotely and takes more.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.