Skip to main content

YekCity: OT security training platform for critical infrastructure

What we do not understand, we cannot protect.

The training dilemma in OT security

OT security teams in critical infrastructure have to be able to respond to attacks like Industroyer, BlackEnergy or Triton. But classic IT cyber ranges model neither industrial communication protocols such as IEC 104, IEC 61850 or Modbus, nor the physical consequences of attacks on process control.

Training on production SCADA systems, control technology or rail infrastructure is out of the question for obvious reasons. The result: SOC teams and incident response staff have theoretical knowledge of OT attacks and no practical experience of detecting or stopping them.

The central problem: the correlation between digital anomalies in network traffic and physical effects on controlled processes cannot be followed in existing training environments.

YekCity: realistic OT attack scenarios without operational risk

YekCity is a physical training environment for OT security that combines real industrial protocols, realistic network architecture and physically visible process effects.

YekCity, OT security training and awareness

Built out of practical OT penetration testing

The platform rests on what we learned in OT penetration tests in critical infrastructure. Our team has carried out security assessments in power plants, substations, rail infrastructure and manufacturing, from power plant control systems with IEC 61850 through interlocking control to DCS and MES systems with PROFINET and Modbus.

That practical experience lets us reproduce weaknesses we actually found. Every training scenario rests on real attack patterns from documented APT campaigns (Industroyer, Triton, BlackEnergy, Stuxnet) and on our own OT tests, anonymised and prepared for training use. The work follows standards such as MITRE ATT&CK for ICS, IEC 62443, the NIST Cybersecurity Framework and the BSI ICS Security Compendium.

Technical basis

YekCity supports the main industrial protocols: IEC 60870-5-104 for telecontrol, IEC 61850 (including GOOSE, MMS, SV) for energy automation, Modbus TCP/RTU for process automation, DNP3 for energy and water utilities, PROFINET and PROFIBUS for Siemens automation, the S7 protocol for PLC communication, EtherNet/IP for Rockwell systems, and OPC UA for Industry 4.0 integration.

The network infrastructure follows the Purdue model with segmented OT networks (DMZ, process network, control network, office IT), firewalls and IDS systems to IEC 62443-3-3, realistic IP addressing, and jump hosts and engineering workstations. That architecture mirrors real critical infrastructure environments.

A 3D-printed smart city model serves as the physical interface, visualising switching states, power failures and emergency shutdowns in real time. Teams see directly how manipulated GOOSE packets or IEC 104 commands have physical effects, and that correlation is not possible in a classic cyber range.

YekCity works with the common SIEM platforms such as Splunk, Elastic, Microsoft Sentinel and Graylog. Predefined detection rules based on MITRE ATT&CK for ICS come with it. Integration with network security monitoring tools such as Zeek, Suricata and Snort allows forensic analysis through PCAP exports.

Red and blue team exercises

A realistic simulation of complete attack chains against OT infrastructure. The red team operates like an APT group and carries out attacks from reconnaissance through lateral movement to the impact scenario. The blue team has to detect, analyse and stop the attacks in real time. The analysts have to work from detecting manipulated industrial protocols through SIEM analysis to incident response, under time pressure. The exercises are followed by a forensic review that identifies gaps in monitoring and in processes.

Who it is for: SOC teams, CERT and CSIRT, and those responsible for OT security.

Where it applies: critical infrastructure sectors

YekCity covers energy supply above all, from power plant control systems and substations through distribution networks to SCADA control rooms. Scenarios that can be trained include Industroyer-like multi-protocol attacks, GOOSE manipulation and IEC 104 man-in-the-middle.

Further sectors are rail infrastructure (interlockings, traction power, signalling), manufacturing (DCS, Siemens and Rockwell PLC systems, safety systems with Triton-like attacks) and water supply (SCADA with DNP3 and Modbus). All scenarios rest on our practical experience from OT tests in those areas.

NIS2 and KRITIS compliance

YekCity supports affected entities in meeting NIS2 requirements through regular documented security exercises, measurable improvement in response capability, and audit trails for compliance documentation. For the German KRITIS regulation the platform offers practical training of staff with OT responsibility, testing of contingency plans under realistic conditions, and evidence towards the BSI.

Next step

Talk to us.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139