
This lecture establishes the mindset required to work safely and effectively in operational technology environments. You will learn why OT cybersecurity is not simply IT security applied to industrial systems, and why safety, stability, availability, and operational continuity shape every decision. The lecture prepares learners to think like OT security professionals who must balance cyber risk with real-world process impact.
Learning Outcomes:
Understand why OT security decisions must prioritize safety, stability, and availability
Recognize why aggressive IT-style responses may create operational risk in industrial environments
Develop the mindset required to coordinate with operations, engineering, and safety teams
This lecture establishes the practical differences between operational technology and information technology in real industrial sites. You will learn why availability and safety dominate decision making, why untested IT controls can disrupt deterministic operations, and how OT teams evaluate risk using process impact rather than purely data impact. The lecture builds the mindset required to work safely with operations, maintenance, and engineering stakeholders while still applying strong cybersecurity discipline.
Learning Outcomes:
Understand how OT priorities differ from IT, with safety and availability typically leading decisions
Recognize why common IT controls can break operations when applied without OT context
Develop the ability to explain OT risk in terms of process consequence, not only data loss
This lecture maps the essential industrial control system components and explains where they exist within plant and field architectures. You will cover SCADA, Substation Automation System, Distributed Control System, Safety Instrumented System, PLC, RTU, IED, HMI, historian platforms such as PI, and engineering workstations. The focus is on understanding what each component does, what it depends on, and how trust boundaries form around them so you can design security controls without disrupting operations.
Learning Outcomes:
Identify the function and operational role of major ICS components across common industrial environments
Map these components to process layers and typical network zones or trust boundaries
Develop the ability to spot where control points and high impact dependencies usually exist
This lecture maps the essential industrial control system components and explains where they exist within plant and field architectures. You will cover SCADA, Substation Automation System, Distributed Control System, Safety Instrumented System, PLC, RTU, IED, HMI, historian platforms such as PI, and engineering workstations. The focus is on understanding what each component does, what it depends on, and how trust boundaries form around them so you can design security controls without disrupting operations.
Learning Outcomes:
Identify the function and operational role of major ICS components across common industrial environments
Map these components to process layers and typical network zones or trust boundaries
Develop the ability to spot where control points and high impact dependencies usually exist
This lecture teaches safety concepts that directly influence OT security actions, especially during troubleshooting and incident response. You will learn the difference between fail safe and fail secure behavior, what safe state means, and why the same cybersecurity action can be acceptable in IT but unacceptable in a live industrial process. The emphasis is on understanding what must never be done during production, and how to coordinate decisions with operations and safety stakeholders.
Learning Outcomes:
Distinguish fail safe from fail secure and explain why the difference matters in OT
Understand safe state concepts and how they guide containment and recovery decisions
Recognize actions that are unacceptable during live operations and how to avoid them
This lecture introduces essential industrial safety concepts that cybersecurity professionals must understand before working around OT environments. You will learn about lockout/tagout, permit to work, job safety analysis, PPE, hazard identification, safety briefings, and stop-work authority. The lecture reinforces that cybersecurity actions in OT must never bypass established safety procedures or create unnecessary operational danger.
Learning Outcomes:
Understand key industrial safety practices such as LOTO, JSA, PPE, and permit to work
Recognize why cybersecurity actions may require safety and operational authorization
Apply safety-aware thinking before performing testing, containment, scanning, or system changes
This lecture turns the Purdue model into a practical field tool rather than a theoretical diagram. You will learn how industrial networks are typically layered, how data moves between levels, and where real trust boundaries should be enforced. The lecture focuses on common patterns such as control networks, supervisory networks, operations demilitarized zones, and enterprise integration points, and how these patterns guide segmentation and monitoring choices.
Learning Outcomes:
Understand how Purdue levels typically map to real industrial environments and system responsibilities
Identify common trust boundaries and the data flows that create exposure across those boundaries
Develop the ability to use Purdue thinking to justify segmentation and control placement decisions
This lecture expands the Purdue/PERA model by focusing on Levels 0 through 3, where core industrial operations take place. You will learn how physical processes, field devices, controllers, local supervision, HMIs, historians, and site operations systems relate to each other. The lecture helps learners understand how security risk increases as cyber activity moves closer to physical process control.
Learning Outcomes:
Describe the purpose of Purdue/PERA Levels 0, 1, 2, and 3
Map common OT assets to physical, field, control, and site operations layers
Recognize how cyber events at lower Purdue levels may create direct process impact
This lecture explains why engineering workstations and engineering tooling are often the highest value targets in OT environments. You will learn how project files, logic downloads, firmware uploads, and configuration management workflows can be abused, and why engineering access is frequently broader than operational access. The lecture focuses on practical hardening, access governance, and workflow controls that reduce risk without stopping legitimate engineering work.
Learning Outcomes:
Recognize why engineering workstations represent a control plane that can change process behavior
Identify common attack and misuse paths through engineering tools, project files, and privileged access
Develop practical controls for engineering workstation hardening, access restriction, and accountability
This lecture introduces ISA or IEC 62443 as a practical way to design OT security using zones and conduits. You will learn how to define zones based on function, consequence, and trust, and how conduits represent controlled communication pathways between zones. The lecture focuses on building segmentation that reflects process reality and supports operations, rather than copying enterprise IT segmentation patterns that can cause disruption.
Learning Outcomes:
Understand the purpose of zones and conduits and why they are foundational to OT security design
Build a basic zone and conduit model for a real facility using consequence and trust as drivers
Develop the ability to define trust boundaries and justify them using operational impact
This lecture shows how to turn 62443 concepts into a phased OT security roadmap that can actually be implemented. You will learn how to sequence governance, asset visibility, segmentation, remote access, monitoring, and incident response in a way that matches maintenance windows and operational readiness. The lecture emphasizes progress that is measurable, defensible, and aligned with business priorities.
Learning Outcomes:
Understand how to structure an OT security roadmap that respects operational constraints and realities
Develop a phased plan that prioritizes governance, visibility, segmentation, monitoring, and response
Recognize how to define milestones and evidence that demonstrate measurable program progress
This lecture focuses on building OT policies and minimum baselines that are enforceable and realistic. You will cover access control, change control, vendor access, removable media, backups, and logging, with emphasis on clarity and operational acceptance. The lecture teaches how to avoid policy documents that look strong but cannot be applied in production, and how to create baseline expectations that can be tested and audited.
Learning Outcomes:
Understand how to write OT security standards that are practical, clear, and enforceable in production
Develop baseline requirements for access, change control, vendor access, removable media, backups, and logging
Recognize how to define evidence and validation steps so baselines are audit ready and measurable
This lecture explains how to translate security objectives into enforceable requirements and measurable outcomes. You will learn how security levels and requirement sets can guide technical implementation, and how to define what good looks like through evidence, testing, and operational validation. The goal is to help you move from policy language to real controls that can be proven during audits and incident reviews.
Learning Outcomes:
Understand how to translate high level requirements into technical controls that can be implemented and verified
Develop the ability to define evidence artifacts that prove controls are operating over time
Recognize what good looks like in OT security through measurable outcomes and validated implementation
This lecture teaches how to embed OT security into procurement so vendors deliver secure outcomes by design. You will learn how to define security clauses, acceptance criteria, access restrictions, auditability requirements, and operational enforcement mechanisms such as time bound access. The lecture emphasizes preventing security gaps created when procurement focuses only on delivery and cost, leaving security as an afterthought.
Learning Outcomes:
Understand how to convert security expectations into clear vendor clauses and deliverable requirements
Develop acceptance criteria that require evidence and testing rather than promises or brochures
Recognize how to enforce vendor access controls through time bound access, logging, and accountability
Qualify integrators, trace firmware provenance, manage SBOMs, enforce maintenance and field service hygiene, and implement site controls and verification to oversee vendor and supply chain risk.
This lecture addresses one of the hardest OT problems, identity and access management under operational constraints. You will learn why shared accounts persist, why local access is sometimes unavoidable, and how to implement multi factor authentication and privileged access controls in ways that do not stop work during outages. The lecture focuses on workable governance, break glass design, and accountability that fits both operations and security needs.
Learning Outcomes:
Understand common OT identity challenges such as shared credentials, local accounts, and vendor access patterns
Develop OT friendly access governance including MFA strategies, privileged access controls, and break glass procedures
Recognize how to preserve accountability and auditability even when perfect identity conditions are not possible
This lecture explains why physical security is a critical part of OT cybersecurity. You will learn how control rooms, engineering areas, field cabinets, substations, remote sites, USB ports, maintenance ports, and vendor visits can affect cyber risk. The lecture shows how physical access can bypass many logical controls and why OT security must extend beyond the network into the field environment.
Learning Outcomes:
Understand why physical access can create cybersecurity risk in OT environments
Identify common field access risks involving cabinets, control rooms, USB media, and maintenance ports
Recognize practical controls for site access, visitor escorting, tamper evidence, and field asset protection
This lecture explains who targets OT environments and why their motivations matter for defensive planning. You will learn the differences between nation-state actors, ransomware groups, insiders, hacktivists, supply chain attackers, vendors, and accidental or negligent actors. The lecture helps learners connect attacker motivation with realistic attack paths, likely impacts, and appropriate security controls.
Learning Outcomes:
Identify major OT threat actor categories and their typical motivations
Recognize how ransomware, insiders, vendors, and supply chain risk affect OT environments
Use threat actor context to support better risk assessment and control selection
This lecture reviews important OT incident patterns and explains the practical lessons learners should take from them. You will examine examples such as Stuxnet, Ukraine power grid attacks, Triton/Trisis, ransomware disruptions, and remote access incidents. The lecture focuses on lessons learned, including segmentation, remote access control, engineering workstation protection, safety system isolation, monitoring, and recovery readiness.
Learning Outcomes:
Recognize common lessons from major OT and critical infrastructure incidents
Understand how attacks can affect control logic, remote operations, safety systems, and business continuity
Apply historical incident lessons to modern OT security architecture and response planning
This lecture explains how MITRE ATT&CK for ICS can be used as a practical language for describing adversary behavior in industrial environments. You will learn the difference between tactics and techniques, how attacker behavior maps to OT operations, and how ATT&CK can support detection engineering, incident response, and threat modeling. The lecture emphasizes that ATT&CK is a behavior model, not a replacement for engineering context.
Learning Outcomes:
Understand how MITRE ATT&CK for ICS describes attacker behavior in OT environments
Recognize important ICS tactics such as discovery, lateral movement, inhibit response function, and impair process control
Apply ATT&CK concepts to monitoring, threat modeling, and incident response discussions
This lecture teaches how to perform OT risk assessment and threat modeling using the 62443 mindset. You will learn how to define realistic threat scenarios, map them to zones and conduits, and prioritize protections by consequence rather than generic severity scoring. The focus is on producing a risk narrative operations and management can understand, while still guiding concrete security design choices.
Learning Outcomes:
Understand how to convert site realities into threat scenarios that reflect process consequences and operational exposure
Develop the ability to prioritize protections and segmentation choices based on consequence and dependency
Recognize how to link threat modeling outcomes to control requirements, evidence, and practical implementation steps
This lecture explains the electricity ecosystem at an operational level, clarifying how utilities, transmission operators, distribution networks, and independent power producers connect. You will learn typical boundaries, ownership responsibilities, and common interconnection models. The focus is on understanding where control systems meet external parties and how those points influence security design and governance.
Learning Outcomes:
Understand the roles of utilities, transmission, distribution, and independent power producers and how they interact
Develop the ability to identify boundaries and interconnections that create shared risk or shared responsibility
Recognize where cybersecurity control ownership typically shifts across organizational and operational interfaces
This lecture connects electrical concepts to cybersecurity consequences. You will learn what megawatts and gigawatts mean in operational impact terms, why voltage levels such as one hundred thirty two or three hundred eighty kilovolts matter, and how topology changes security priorities. The goal is to help you communicate risk using concepts operations leadership already understands.
Learning Outcomes:
Understand the operational meaning of power capacity and why MW versus GW changes risk conversation and impact
Develop a high level understanding of AC, DC, and HVDC and typical grid use cases
Recognize how voltage level, topology, and interconnection points influence cyber design constraints and priorities
This lecture maps substation automation architecture, including the separation of bay level and station level, the role of IEDs, and how SAS communication flows typically operate. You will learn where cyber control points belong, how to avoid disrupting protection traffic, and what monitoring visibility is needed to detect abnormal behavior without breaking determinism.
Learning Outcomes:
Understand typical SAS architecture and communication paths across bay level and station level
Develop the ability to identify correct cyber control points for segmentation and monitoring in substations
Recognize how protection requirements and timing sensitivity constrain enforcement and inspection choices
This lecture explains control architecture in power generation environments and the dependencies that matter most. You will learn how DCS and SIS differ, how turbine control and balance of plant systems interact, and what credible cyber consequences look like in operations and safety terms. The lecture emphasizes how to prioritize defenses around safety and stability dependencies.
Learning Outcomes:
Understand the roles of DCS, SIS, turbine control, and balance of plant components and how they interact
Develop the ability to identify critical dependencies that drive the highest operational and safety risk
Recognize credible attack consequences and translate them into defensive priorities and monitoring focus
This lecture focuses on vendor reality in the energy sector, including OEM tooling, proprietary stacks, patch cycles, and remote support patterns. You will learn how these realities shape defensive strategy, especially around access governance, maintenance windows, and evidence collection. The goal is to design controls that work with OEM operations rather than fighting them.
Learning Outcomes:
Understand typical OEM and integrator deployment patterns and how they influence security architecture
Develop practical strategies for managing remote support, patch constraints, and proprietary tooling risks
Recognize how to design vendor controls that remain enforceable, auditable, and operationally acceptable
This lecture builds a standards landscape approach for energy OT security. You will learn how standards influence architecture decisions, monitoring expectations, incident response readiness, and audit evidence. Rather than memorizing a list, you will learn how to interpret obligations and translate them into controls that can be validated in real operational environments.
Learning Outcomes:
Understand how standards and regulations shape energy OT security architecture and monitoring expectations
Develop a method for translating obligations into controls and evidence artifacts without paperwork overload
Recognize how to prepare defensible audit narratives through structured evidence and consistent governance
This lecture explains why OT communications behave differently from typical IT traffic. You will learn polling behavior, broadcast patterns, timing constraints, and why latency and jitter can break operations. The focus is on learning what normal looks like so you can secure networks without disrupting deterministic control processes.
Learning Outcomes:
Understand core OT traffic behaviors such as polling, broadcast, and timing sensitivity and why they matter
Develop the ability to interpret normal OT traffic patterns and identify anomalies safely
Recognize which security actions can introduce latency or disruption and how to avoid breaking operations
This lecture provides a focused understanding of IEC 61850 communication types and their operational criticality. You will learn how GOOSE, MMS, and Sampled Values behave, what each is used for, and why segmentation and monitoring must be designed carefully. The lecture emphasizes security implications without compromising protection and control performance.
Learning Outcomes:
Understand the role of GOOSE, MMS, and Sampled Values and how their criticality differs
Develop segmentation and monitoring approaches that protect IEC 61850 environments without breaking determinism
Recognize common exposure patterns and what security controls are realistically safe to apply
This lecture explains IEC 60870 usage in telemetry and control and how it is commonly deployed. You will learn typical architectures, why certain patterns exist in utilities, and how to secure these communications without disrupting telemetry. The emphasis is on applying compensating controls and visibility rather than fragile enforcement.
Learning Outcomes:
Understand the difference between 101 and 104 deployment models and typical use cases
Develop security controls that reduce exposure while preserving telemetry reliability
Recognize where monitoring, segmentation, and access control provide the safest protection
This lecture introduces widely used industrial protocols and explains why they are frequently exploited. You will learn common weaknesses such as lack of authentication, cleartext commands, and permissive design assumptions. The lecture focuses on compensating controls that work in legacy and mixed environments without requiring unrealistic protocol replacement.
Learning Outcomes:
Understand why common OT protocols were not designed with modern security assumptions
Develop the ability to identify typical protocol level weaknesses and resulting attack opportunities
Recognize compensating controls such as segmentation, strict access control, and protocol aware monitoring
This lecture explains how industrial protocols can be abused and how defenders can monitor suspicious behavior safely. You will learn about unauthorized reads, unauthorized writes, command abuse, device discovery, logic downloads, configuration changes, controller mode changes, abnormal client-server relationships, and unusual timing or traffic volume. The lecture emphasizes passive, protocol-aware monitoring supported by process context and maintenance awareness.
Learning Outcomes:
Recognize common abuse patterns involving ICS protocols and controller communication
Identify high-risk behaviors such as unauthorized writes, logic downloads, and controller mode changes
Apply defensive monitoring concepts that detect suspicious behavior without disrupting OT operations
This lecture teaches firewall placement decisions that reflect process design, safety, and determinism. You will learn where enforcement is helpful, where it can cause outages, and how to choose control points in substations, plants, and remote RTU environments. The goal is to avoid designs that look secure on paper but fail operationally.
Learning Outcomes:
Understand how to choose firewall placement based on process design and critical communication paths
Develop the ability to justify when not to place firewalls and what alternative controls to use
Recognize how determinism and latency sensitivity shape enforcement design in OT environments
This lecture explains proven OT demilitarized zone patterns and secure remote access designs. You will learn how jump hosts, remote access gateways, and brokered sessions can support operations and vendor support while maintaining accountability and auditability. The focus is on making remote access safer without making it unusable.
Learning Outcomes:
Understand OT DMZ design patterns and why they reduce exposure between IT and OT networks
Develop a secure remote access workflow using jump hosts or gateways with strong session accountability
Recognize how to enforce time bound access, logging, and approval to reduce vendor access risk
This lecture compares passive monitoring and detection first strategies against inline blocking approaches that may disrupt operations. You will learn when visibility is safer than enforcement, how protocol aware tools improve detection quality, and how to design monitoring that supports investigations while respecting operational constraints.
Learning Outcomes:
Understand when passive monitoring is safer than inline enforcement in sensitive OT environments
Develop a detection first monitoring design that provides visibility without introducing operational risk
Recognize how protocol awareness improves detection fidelity and reduces false positives
This lecture covers wireless realities in OT, including Wi Fi, private LTE, radio links, and field connectivity used in remote operations. You will learn how to secure authentication, segment wireless access, and monitor exposure while accounting for environmental constraints and operational urgency. The focus is on preventing wireless convenience from becoming an ungoverned backdoor.
Learning Outcomes:
Understand common wireless technologies used in OT and the unique risks they introduce
Develop secure designs for authentication, segmentation, and access control in field connectivity
Recognize monitoring and governance practices that detect misuse without disrupting operations
This lecture explores cybersecurity risks in wireless and remote field communications used across industrial environments. You will learn how Wi-Fi, radio, cellular, private LTE, private 5G, microwave, satellite, and vendor-managed links support remote substations, mines, pipelines, transportation systems, and field cabinets. The lecture explains how to secure these links while preserving availability, monitoring, and local safe operation.
Learning Outcomes:
Identify common wireless and remote communication methods used in OT environments
Recognize risks such as jamming, interception, spoofing, rogue devices, and unmanaged vendor links
Apply practical controls for segmentation, encryption, authentication, monitoring, and resilient field connectivity
This lecture explains where OT environments connect to IT and cloud platforms, and why these interfaces often become the highest risk bridges. You will learn typical patterns such as historian replication, data lakes, remote operations portals, and API driven integrations. The focus is on designing secure data movement and preventing lateral movement paths from enterprise or cloud into control networks.
Learning Outcomes:
Understand common IT OT and cloud integration patterns and why they create concentrated exposure
Develop secure data movement designs using controlled interfaces, least privilege, and strong segmentation
Recognize API and remote operations risks and implement monitoring and governance to reduce attack paths
This lecture teaches OT aware security monitoring and triage based on process impact. You will learn how to interpret alerts using operational context, how to prioritize events based on safety and availability consequences, and why generic IT severity scoring often misclassifies OT incidents. The lecture focuses on actionable triage that supports operations rather than creating unnecessary disruption.
Learning Outcomes:
Understand how to classify incidents by operational consequence rather than only indicators of compromise
Develop triage workflows that integrate process context, asset criticality, and dependency awareness
Recognize how to reduce noise and false escalation by understanding normal OT behavior patterns
This lecture explains how to maintain OT asset inventory and configuration baselines without disrupting production. You will learn what evidence matters, how to handle fragile endpoints, and how to prove change control in environments where scanning and aggressive tooling are not acceptable. The focus is on building an audit ready operational record of what exists and what changed.
Learning Outcomes:
Understand practical OT asset inventory methods that respect operational constraints
Develop configuration baseline practices with evidence that supports audit and incident investigation
Recognize how to maintain change evidence and accountability without disruptive scanning or tooling
This lecture addresses OT patching realities, limited downtime, vendor dependencies, and safety constraints. You will learn how to prioritize vulnerabilities by consequence, how to plan patch cycles around maintenance windows, and how to apply compensating controls when patching is delayed. The goal is to create a defensible patch strategy rather than an unrealistic patch demand.
Learning Outcomes:
Understand how to prioritize vulnerabilities in OT using consequence and operational dependency
Develop patch planning methods that align with maintenance windows and vendor constraints
Recognize compensating controls that reduce risk when patching cannot be done immediately
Explore how OT visibility rises with IDS and IPS paired with SIEM, using Nozomi, Clarity, and Dragos to detect anomalies, correlate events, and prioritize security.
This lecture defines what OT backup and recovery must include to restore operations safely. You will learn why backing up PLC logic, configurations, firmware, and golden images matters, and how to test restores in a controlled manner. The focus is on recovering to a safe operational state rather than only restoring devices.
Learning Outcomes:
Understand OT backup scope including logic, configuration, firmware, and golden images across key assets
Develop restore testing practices that validate both technical recovery and operational safety
Recognize how to build recovery procedures that minimize downtime and avoid unsafe reactivation
This lecture explains how disaster recovery and business continuity differ in ICS and OT environments. You will learn why recovery must restore safe and trusted operation, not only files or servers. The lecture covers PLC logic backups, DCS and SIS configurations, HMI projects, historian settings, engineering workstation images, firmware, licenses, golden images, RTO, RPO, manual workarounds, spare parts, and recovery testing.
Learning Outcomes:
Understand why OT disaster recovery must restore safe, validated, and trusted operation
Identify the OT-specific assets and configurations that must be backed up and protected
Develop business continuity thinking around degraded operation, manual procedures, recovery testing, and resilience
Explore tabletop exercises, purple teaming, and digital twin rehearsals to de-risk changes, validate plans, and foster a culture of continuous improvement across tech, people, and processes.
This lecture teaches how to design OT visibility that is safe, actionable, and sustainable. You will learn what to log, where to place sensors, how to handle time synchronization, and how to avoid collecting data that cannot be used. The lecture focuses on building a visibility architecture that supports detection, investigations, and audit evidence without disrupting operations.
Learning Outcomes:
Understand what visibility sources matter most in OT and how to prioritize them for maximum value
Develop safe sensor placement and logging designs that preserve determinism and availability
Recognize the role of time synchronization and event correlation in OT investigations and evidence
This lecture covers OT safe hardening for Windows systems commonly used in control environments. You will learn how to reduce privilege, control services, manage removable media, and implement secure configuration baselines without breaking vendor support requirements. The focus is on practical hardening with evidence, not aggressive changes that operations cannot sustain.
Learning Outcomes:
Understand OT appropriate Windows hardening priorities for HMI, engineering workstations, and historians
Develop baseline configuration controls that reduce exposure while preserving vendor support requirements
Recognize how to produce evidence of secure configuration through policies, settings, and change records
This lecture explains how to harden critical OT endpoints while respecting operational availability, vendor support, and maintenance constraints. You will learn how engineering workstations, HMIs, historians, and OT domain controllers each require different hardening priorities based on their operational role. The lecture covers least privilege, local accounts, shared credentials, allowlisting, removable media control, patching constraints, logging, backups, and golden images.
Learning Outcomes:
Understand why OT endpoints must be hardened based on role, criticality, and process impact
Recognize security priorities for EWS, HMI, historians, and OT identity infrastructure
Apply practical hardening controls without disrupting visibility, control, engineering access, or recovery
This lecture defines an OT incident response lifecycle that prioritizes safety and stability over rapid isolation. You will learn why the OT response sequence differs from IT, how containment choices can create physical risk, and how to coordinate decisions with operations. The focus is on controlling damage without creating new hazards.
Learning Outcomes:
Understand OT incident response priorities and why safety comes before technical containment speed
Develop decision thinking that balances stability, continuity, and evidence preservation
Recognize coordination requirements with operations and safety stakeholders during incidents
This lecture builds practical playbooks for containment actions that can be executed under pressure. You will learn how to tighten segmentation safely, disable access through kill switch mechanisms, and plan controlled shutdown scenarios with defined authority. The emphasis is on safe actions, clear escalation, and defensible documentation.
Learning Outcomes:
Understand containment options and when each is safer or riskier in OT environments
Develop playbooks that define authority, triggers, and step by step actions under pressure
Recognize how to document containment actions so they remain defensible after the event
This lecture teaches OT safe evidence collection, acknowledging fragile endpoints and limited instrumentation. You will learn safe packet capture, log preservation, and chain of custody practices that preserve evidence integrity while avoiding operational disruption. The focus is on collecting what is feasible and valuable, not what is ideal in IT labs.
Learning Outcomes:
Understand what OT evidence can be collected safely and what collection actions can create risk
Develop safe approaches for pcap and log capture that preserve integrity and continuity
Recognize chain of custody practices that maintain evidentiary value without disrupting operations
This lecture provides scenario-based practice for responding to OT cybersecurity incidents safely and effectively. You will review situations involving ransomware on HMIs, unknown devices communicating with PLCs, engineering workstation compromise, vendor access outside maintenance windows, PLC logic changes, and historian disruption. The lecture reinforces the OT incident response principle of safety first, stability second, and evidence third.
Learning Outcomes:
Apply safety-aware decision-making to common OT incident response scenarios
Recognize when containment actions require coordination with operations and engineering
Select response actions that protect safety, preserve stability, and support investigation
This lecture explains how to convert incident lessons into measurable improvements across architecture, monitoring, vendor controls, and standards. You will learn how to avoid shallow fixes and instead implement structural changes that reduce recurrence. The focus is on linking root causes to program updates and evidence of improvement.
Learning Outcomes:
Understand how to turn root cause findings into structural control improvements across the OT program
Develop improvement actions that update architecture, monitoring, vendor access, and baselines
Recognize how to measure improvement over time using evidence and operational outcomes
Explore how OT and security operations centers integrate by normalizing telemetry from PLCs, DCS, and SCADA, enabling unified analysis, runbooks, and cross-disciplinary collaboration.
This lecture focuses on ransomware as a dominant real world threat and teaches OT specific decision making. You will learn when isolation is safer, when continuity must be preserved, and how to coordinate response without triggering unsafe states or unnecessary shutdowns. The lecture emphasizes recovery paths, segmentation actions, and evidence preservation under extreme time pressure.
Learning Outcomes:
Understand ransomware impact patterns in OT and why response choices differ from IT environments
Develop decision logic for isolation versus continuity that prioritizes safety and recovery readiness
Recognize actions that preserve restore paths and reduce spread while maintaining operational stability
Explore how NIST SP-882 and ISO 27019 secure industrial control systems and energy sector operations, balancing availability, safety, and governance through defense-in-depth, segmentation, and incident response.
Learn how audits and maturity models drive organizational learning and continuous improvement, using KPIs, KCIs, and evidence packs. Build an effective audit calendar and close findings with measurable improvements.
Build a cyber safety culture that bridges IT and OT mindsets, empowers operators, and embeds human factors and clear communication into daily operations for secure, resilient uptime.
Design a secure OT architecture for critical infrastructure by applying segmentation, controlled remote access, visibility, resilience, and governance.
This lecture explains mining OT environments and their unique constraints, including remote sites, harsh connectivity, and distributed operations. You will learn key processing systems, typical control stacks, and where the highest dependency risks occur. The focus is on understanding why remote operations and legacy deployments change security design priorities.
Learning Outcomes:
Understand typical mining OT components and how processing plants and remote sites connect
Develop the ability to identify key dependencies and remote connectivity risk patterns
Recognize practical control points for access governance, segmentation, and monitoring in mining
This lecture maps realistic threat scenarios in mining, focusing on operational consequences such as downtime, safety risk, and production disruption. You will learn common attack paths involving remote access, contractor exposure, and weak segmentation. The focus is on understanding likely scenarios and designing defenses that reduce impact.
Learning Outcomes:
Understand common mining threat scenarios and the operational consequences they create
Develop the ability to map attack paths through remote access, legacy systems, and contractor workflows
Recognize control priorities that reduce downtime risk and improve detectability and recovery
This lecture explains how compliance influences OT security in mining without overwhelming learners with regulation lists. You will learn how to build evidence in remote and constrained sites, how to align safety expectations with security controls, and how to maintain defensibility when legacy systems limit mitigation options.
Learning Outcomes:
Understand how compliance and safety expectations shape mining OT security control requirements
Develop a compliance aware control plan that produces realistic evidence artifacts
Recognize how to maintain defensible risk decisions when legacy and remoteness constrain options
This lecture translates industry practices and compliance expectations into enforceable controls and evidence. You will learn how to build governance that supports audit readiness while remaining operationally realistic. The emphasis is on designing controls that can be proven, not only written.
Learning Outcomes:
Understand how sector expectations shape control requirements and evidence needs in oil and gas
Develop a method to translate obligations into implementable controls and measurable proof
Recognize how to balance strong oversight with operational practicality in contractor and vendor environments
This course contains the use of artificial intelligence.
Operational Technology is no longer isolated from cybersecurity risk. Industrial environments now depend on connected systems, remote access, vendor support, cloud integrations, engineering workstations, historians, wireless field communications, and complex IT-OT interfaces. At the same time, these environments must protect safety, reliability, production, and critical infrastructure operations.
This course is a practical, structured, and real-world focused masterclass designed to help cybersecurity professionals, engineers, consultants, auditors, SOC analysts, risk professionals, and managers understand how OT and industrial cybersecurity work in real environments.
Unlike traditional IT security courses, this course does not treat industrial systems as normal servers or endpoints. You will learn how OT security decisions must consider safety, process stability, engineering constraints, maintenance windows, vendor dependencies, legacy systems, physical access, and operational continuity.
You will start by building a strong foundation in OT and ICS concepts, including the difference between OT and IT, ICS building blocks, PLCs, RTUs, DCS, SIS, HMIs, historians, engineering workstations, field devices, Purdue/PERA levels, control theory basics, industrial safety essentials, and the role of engineering systems as the real control plane.
From there, you will learn how to design an OT security program using ISA/IEC 62443 principles. The course explains zones and conduits, risk-based segmentation, security levels, policies, minimum baselines, procurement requirements, vendor contracts, supply chain risk, identity, shared credentials, MFA, break-glass access, physical security, threat actors, historical OT incidents, MITRE ATT&CK for ICS, and OT risk assessment.
The course then moves into real industrial architecture and sector knowledge, with a deep dive into energy OT environments, including utilities, transmission, distribution, substations, IEDs, SAS architecture, power plants, DCS, SIS, turbine control, balance of plant, OEM realities, and energy-related standards and regulations.
You will also learn how OT protocols behave differently from traditional IT traffic. The course covers IEC 61850, GOOSE, MMS, Sampled Values, IEC 60870-5-101/104, Modbus, DNP3, PROFINET, EtherNet/IP, protocol abuse patterns, defensive monitoring, firewall placement, OT DMZ design, jump hosts, remote access gateways, protocol-aware monitoring, inline blocking considerations, wireless OT, private LTE, radio links, field communication risks, historians, data lakes, remote operations, cloud interfaces, and API exposure.
A major part of the course focuses on OT security operations and monitoring. You will learn how to perform OT SOC triage with process context, manage assets and configurations, handle vulnerability and patch management in maintenance-window-driven environments, use IDS/IPS and SIEM for OT visibility, manage backups and recovery for PLC logic, configurations, firmware, and golden images, build ICS disaster recovery and business continuity plans, harden OT endpoints, secure Windows systems in OT, protect HMIs, EWS, historians, and domain controllers, and monitor secure remote access.
You will also learn how OT incident response differs from traditional IT incident response. The course uses the principle of safety first, stability second, and evidence third. You will explore containment playbooks, segmentation tightening, access kill-switches, controlled shutdown, OT forensics, ransomware decision-making, incident response scenarios, post-incident hardening, and the implementation of OT SOC capabilities.
The course also includes a broad view of OT risk management, regulatory mapping, and sector-specific cybersecurity. You will explore OT risk frameworks, critical infrastructure cybersecurity frameworks, IEC 62443 recap, NIST SP 800-82, ISO/IEC 27019, NIS2 and DORA mapping to OT controls, audit and maturity assessment, mining OT, oil and gas OT, transportation OT, rail, aviation, ports, smart infrastructure, industrial IoT, AI-driven predictive maintenance, cloud, digital twins, and emerging technology considerations.
This course is also useful for learners preparing for CompTIA SecOT+ and GIAC GICSP-style industrial cybersecurity knowledge. It is not an official CompTIA, GIAC, or SANS course, and it does not claim endorsement or guaranteed exam coverage. However, the course strongly supports the practical knowledge areas these certifications emphasize, including OT safety, industrial systems, ICS architecture, Purdue/PERA, IEC 62443, protocols, endpoint hardening, threat modeling, monitoring, incident response, wireless technologies, disaster recovery, and business continuity.
By the end of this course, you will be able to think, speak, design, assess, and respond like an OT security professional. You will understand how to protect industrial systems without blindly applying IT controls, how to communicate with operations and engineering teams, how to design practical OT security architectures, and how to build security programs that support safety, reliability, and resilience.