
Bridge control engineering, information technology security, and operational technology risk to protect industrial control systems, networks, and safety-critical processes across real facilities, using Purdue model concepts and open-book certification prep.
Define industrial control systems and their role in safety, availability, and process integrity across critical infrastructure, and explain why security in operational technology differs from information technology, emphasizing real-time control.
Compare information technology and operational technology to show availability and safety override confidentiality in industrial control systems. Explore legacy systems, compensating controls, and governance under IEC 62443 for safety-critical processes.
Define key ICS terminology and map each term to physical equipment and real-time processes across SCADA, DCS, PLC, RTU, HMI, SIS, and historian.
Define explicit ownership and cross-functional governance for industrial control systems, aligning control engineers, OT and IT security, plant managers, and integrators through IEC 62443 and joint change management.
Protect the last automated line of defense: the safety instrumented system in industrial control. Learn how security preserves safety through segmentation, access controls, and cross-functional collaboration.
Apply layered physical defenses from the perimeter to the cabinet in OT to prevent tailgating, rogue devices, and unauthorized access, within a unified program with threat intelligence and incident response.
Understand industrial control system architecture and why segmentation and the Purdue model, zones and conduits, and the industrial demilitarized zone protect safety, availability, and resilience.
The Purdue reference model defines six levels, from the physical process to the enterprise, guiding segmentation, boundaries, and defense in depth with the industrial demilitarized zone.
Define level 0 of the Purdue model and explore how sensors, actuators, valves, and 4-20 mA signals physically control industrial processes, underscoring cyber security's defensive emphasis and risk to safety.
Level 1 basic control uses programmable logic controllers, remote terminal units, and safety controllers to translate decisions into physical actions, requiring defense in depth and segmentation to mitigate cyber risk.
Explore level 2 area supervisory control, where the human-machine interface, scada server, and engineering workstation protect process safety through defense in depth and layered cyber defenses.
Explore the level 3 site operations layer, including historians, manufacturing execution systems, and batch management, and learn ISA 95/88, IEC 62443, data segmentation, and defense and depth posture.
Describe the industrial demilitarized zone as a controlled intermediary between IT and OT, enforced by dual firewalls, jump servers, and data diodes to secure data exchange.
Explore levels 4 and 5 of the Purdue model, detailing enterprise and internet exposure, segmentation, and governance to prevent enterprise compromise from cascading into operations.
Define zones and conduits using the IEC 62443 framework to segment operational technology networks and protect safety, reliability, and process integrity.
Design secure industrial control system architectures by layering defense in depth, least privilege, and fail-safe defaults across zones and conduits, ensuring independent protections and long-term life-cycle resilience.
Explore how sensors and transmitters for pressure, temperature, flow, and level drive control via 4-20 mA loops and live zero principle, with Hart diagnostics. Security risks from physical access.
Learn how final control elements translate controller signals into physical action, including valves, motors, and dampers, and how their failure modes, reliability, and safety features influence secure industrial control.
Explore how programmable logic controllers read inputs from sensors, execute real-time logic, and drive outputs. Analyze ladder diagram and function block diagram languages, scan cycles, and fieldbus interfaces for control.
Remote terminal units are rugged autonomous controllers that collect data and relay it to a supervisory control and data acquisition master station, addressing security challenges in unmanned, dispersed sites.
Explore how safety instrumented systems provide an independent automated layer of defense from the basic process control system, detecting hazards and triggering automatic shutdown to protect lives and facilities.
Explore intelligent electronic devices in power systems, their protection, metering, and signaling roles, and essential cyber security mitigations like segmentation, access control, and monitoring of goose messages.
Discover why field devices at level 0 and 1 lack authentication, encryption, and integrity, and learn mitigations such as segmentation, protocol-aware firewalls, physical access controls, and secure-by-design standards.
Explore how human-machine interfaces provide real-time process visibility, alarms, and operator commands, and how alarm management lifecycle and security hardening enhance safety.
Explore how SCADA systems provide centralized visibility and control over distributed critical infrastructure across oil, gas, water, and power networks. Understand the architecture, components, telemetry, polling, risks, and defense-in-depth security.
Understand distributed control systems’ architecture and security, including redundant controllers, control network, two-tier architecture, and defense-in-depth for continuous processes.
Engineering workstation acts as the central, high-privilege hub to write, configure, diagnose, and update PLCs, DCS, and safety systems, using vendor software and strict mitigations to prevent unauthorized changes.
Capture and store time series data from industrial control systems with a process historian. Compress and archive data for years, ensuring data integrity for compliance and incident investigation.
Explore how a manufacturing execution system bridges ERP planning and plant control, enabling real-time production tracking and quality compliance while detailing ISA95 boundaries and security considerations.
Explore level 2 and 3 security challenges in Windows-based OT networks, including patch delays, remote access risks, and compensating controls like segmentation and OPCDA to OPCUA migration.
Learn how TCP/IP underpins industrial control networks, with IP addressing, subnets, and zone-based segmentation, and how Modbus TCP, OPC UA, and DNP3 rely on it for secure operation through firewalls.
Discover how serial communications, from rs-232 to rs-485 and modbus rtus, underpin OT networks, and why topology, baud rates, and security risks matter for industrial cybersecurity.
Modbus, in RTU and TCP, is a simple master-slave protocol with no authentication, encryption, or session management, creating an attack surface exposed by read and write function codes.
Discover how DNP3 enables wide area telemetry with timestamped events and polling and unsolicited reporting across utilities. Examine its security evolution from no authentication to SAV5 authentication and remaining challenges.
Explore the evolution from OPC data access to unified architecture, highlighting security weaknesses of DCOM, the single port 4840, certificate-based authentication, TLS, and per-node access control.
Explore how Ethernet slash IP carries the Common Industrial Protocol over TCP/UDP, detailing explicit and implicit messaging, CIP object model, and security gaps with compensating controls.
Explore PROFINET and PROFIBUS architectures and real-time classes in Siemens automation, including coexistence via proxy devices. Examine security gaps—no authentication or encryption—and practical layer 2 controls in industrial networks.
Explore how BACnet, the open building automation standard, enables control of heating, ventilation and air conditioning, lighting, and security while exposing unauthenticated read/write, broadcast discovery, and device manipulation risks.
Explore how IEC 61850 standardizes substation data models and fast Goose multicast, MMS client-server communication, and sampled values across a two-bus architecture, plus security challenges.
Explore wireless technologies in industrial control, from Wireless Heart to Wi-Fi and private 5G. Understand key security controls: authentication, encryption, segmentation, rogue device detection, and governance.
Wireless HART uses a self-organizing 2.4 GHz mesh with TDMA and channel hopping for secure, non-critical monitoring, featuring AES-128 encryption and per-message authentication managed by the gateway.
Learn how ISA100.11a, a protocol-agnostic industrial wireless standard, tunnels diverse protocols over a single network, uses a wired IPv6 backbone, and provides AES-128 security across mesh, star, and hybrid topologies.
Explore industrial wifi in OT settings, covering secure deployment, segmentation, WPA3 and WPA2 enterprise with 802.1X, rogue access points, and coexistence with field wireless.
Explore cellular connectivity for ot and scada, from 4g lte to private 5g deployments, and secure traffic with end-to-end vpn, private apn, and robust security controls.
Explore licensed scada radio as an operator-owned backbone for remote telemetry, and understand security gaps, from eavesdropping to command injection, with mitigations like VPN overlays and DNP3 authentication.
Explore Bluetooth and Zigbee in industrial control systems, analyze vulnerabilities from short-range wireless and ungoverned devices, and apply practical hardening and asset inventory strategies.
Explore cross-technology wireless attack vectors in industrial facilities, including jamming, eavesdropping, spoofing, and replay, and learn defenses across Wi‑Fi, Wireless Heart, ISA 100.11a, cellular, licensed radio, Bluetooth, and ZigBee.
Consolidate security controls across wireless technologies into a unified defense framework that protects all wireless infrastructure and the operational technology network through encryption, authentication, segmentation, monitoring, and governance.
Identify who threatens industrial control systems and why, including nation-states, criminals, insiders, and hacktivists, then learn from Stuxnet, Ukraine power grid, and Triton to assess ICS risk.
Explore the MITRE ATT&CK for ICS framework, its tactics and techniques, and how to map attacker behavior to improve threat intelligence, detection engineering, and security assessment.
Explore level 0/1 attack techniques in the Purdue model, including PLC code injection, firmware manipulation, and sensor spoofing, and their direct physical consequences.
Examine level 2 and level 3 attack techniques in supervisory and site operations, focusing on HMI compromise, historian manipulation, and credential theft, and discuss multi-factor authentication and network segmentation.
Explore protocol-based attacks on industrial systems like Modbus, DNP3, OPC, IEC 61850, and IEC 104, where no authentication or encryption enables real world consequences.
Manage supply chain and third-party risks in ICS by securing vendor access and integrator practices. Implement least privilege, MFA, segmentation, monitoring, and lifecycle management to limit the extended attack surface.
Explore insider threats in industrial control systems, including malicious, negligent, and compromised insiders, their risk factors, and defenses through access controls, change management, offboarding, and monitoring.
Apply threat modeling to industrial control systems to proactively identify assets, threats, vulnerabilities, and mitigations, and prioritize security investments across design, modification, and incident response.
Learn asset identification and criticality assessment for ICS environments within threat modeling, discovering and cataloging hardware, software, data, and capabilities, then prioritize defenses around crown jewels.
Profile threat actors to transform threats into adversaries with motivations, capabilities, and methods. Assess relevance to your organization and build threat-modeling-ready, ICS-focused defense with TTPs.
Map the ICS attack surface by identifying entry points, trust boundaries, and data flows. Prioritize defenses to reduce exposure and strengthen segmentation across zones.
Learn to apply Stride, PASTA, and attack trees for ICS threat modeling, delivering risk-prioritized, defensible results with structured, repeatable analyses.
Turn threat intelligence into action for ICS/OT environments by converting indicators of compromise, tactics, and OT context into actionable detections, threat hunting, and threat modeling.
Learn to identify indicators of compromise (IoCs) in ICS, including network, host, and behavioral indicators, and implement ICS-specific detection at the IT-OT boundary.
Industrial control system endpoints require security balancing process availability, safety, and environmental integrity. IT security fails in OT, so the lecture highlights application whitelisting and hardening as compensating controls.
Hardening Windows endpoints for industrial control systems by reducing attack surface through level one and two CIS benchmarks, selective service disablement, and centralized group policy while preserving process availability.
Hardening Linux and Unix hosts in industrial control systems strengthens security while preserving availability, addressing OT constraints, long asset life cycles, and default configurations that prioritize functionality over security.
Explore how application whitelisting secures fixed-function industrial endpoints with a default deny posture, guided by discovery, baselining, enforcement, and maintenance to withstand operational technology threats.
Learn six-stage patch management for industrial control systems, from asset inventory to verification, balancing safety, availability, and risk while coordinating with vendors and testing in labs.
Explore antivirus and endpoint protection strategies for industrial control systems, contrasting traditional antivirus with endpoint detection and response and highlighting application whitelisting for operational technology.
Enforce removable media governance in industrial control systems by using a scanning kiosk, device and application whitelisting, and physical port controls to protect air-gapped networks from malware.
Back up and recover industrial control systems to restore safe deterministic process control, not just data, by protecting controller programs, HMI configurations, tuning parameters, and network device settings.
Design, validate, and govern industrial network segmentation using zones and conduits, the Purdue model, and a demilitarized zone to protect safety-instrumented systems.
Firewalls in industrial control systems enforce zone and conduit boundaries under IEC 62443, using stateful and deep packet inspection to protect process integrity and human safety.
Design industrial demilitarized zones to safely separate IT and OT, enforcing deny by default, no direct traversal, and minimal services with paired firewalls, jump servers, and historian replication.
Learn defense in depth remote access for industrial control systems, using MFA, jump hosts, DMZs, on-demand sessions, rigorous logging, and strict vendor and session governance.
Establish visibility across industrial control networks with passive monitoring, span ports, and network taps to enable asset discovery, baseline behavior, anomaly detection, and IEC 62443 compliance.
Detect adversary activity in industrial control systems with a layered approach that combines signature-based and anomaly-based detection, using deep packet inspection for industrial protocols in a passive OT environment.
Explore how security information and event management enables centralized correlation of OT and IT log data to detect threats across zones while preserving safety and process integrity.
Explore unidirectional gateways, or data diodes, hardware-enforced one-way data transfer at industrial boundaries and how they complement firewalls to protect safety-critical control systems and data flows.
The GICSP certification is the gold standard for professionals securing industrial control systems. It validates that you can protect the SCADA, DCS, PLC, and SIS environments that run power grids, water treatment plants, oil refineries, and manufacturing facilities. It is also one of the hardest cybersecurity certifications to pass without structured preparation.
Here is the problem. SANS GICSP training costs thousands and requires a week away from work. Self-study means piecing together scattered resources with no clear path through the exam domains. Most candidates underestimate the breadth — the GICSP spans ICS architecture, industrial protocols, field devices, wireless technologies, attack techniques, network defence, endpoint hardening, governance frameworks, risk management, and incident response. Missing any one domain can fail you.
This course is the structured alternative.
Over 30 hours of focused instruction, 13 sections, 95 lessons, and 1,000+ slides, this masterclass covers every GICSP exam domain systematically. You will build from ICS fundamentals and the Purdue Model through Level 0-3 device internals, industrial protocols (Modbus, DNP3, OPC, EtherNet/IP), wireless technologies, and the complete ICS threat landscape — including Stuxnet, TRITON, and the Ukraine power grid attacks analysed through the ICS Kill Chain and MITRE ATT&CK for ICS.
You will then progress through endpoint hardening, network security architecture, governance and compliance (IEC 62443, NIST 800-82, NERC CIP), risk management, incident response with OT-specific containment strategies, and disaster recovery planning. The course concludes with dedicated exam preparation — index building strategies, CyberLive practical question preparation, exam day tactics, a rapid-fire concept review, and two full-length timed practice exams.
What makes this different from reading the GICSP courseware alone? Every lesson connects technical concepts to operational reality. You will understand not just what a PLC scan cycle is, but why it creates security constraints that generic IT controls cannot address. Not just what IEC 62443 requires, but how security levels, zones, and conduits translate into real network architecture decisions. Not just that incident response matters, but how to contain a threat in a live process environment without triggering a plant shutdown.
Built by a practising ICS/OT cybersecurity professional with over 15 years delivering safety-critical control system projects across oil, gas, and energy infrastructure. This is not repackaged IT security content — it is purpose-built for the systems, protocols, and operational realities that the GICSP exam tests.
If you are serious about passing the GICSP and building a career in industrial cybersecurity, this is your complete preparation path. Enrol now and start building toward certification.