
Introduce ICS/SCADA cybersecurity with real-world power utility industry experience; cover architecture, technologies, popular protocols, security standards such as nerk sip, threat landscape, attack surfaces, and practical defenses.
Define industrial control systems and scada, distinguishing local ics processes from remote scada monitoring, with examples like car plants, energy substations, and safety instrumented systems safeguarding pipelines.
The Purdue model outlines levels 0–5 of a cska/scada architecture, from the physical industrial process to corporate IT, detailing sensing, control, and dmz-separated business layers.
Examine the range of scada software, including device firmware, hardware administration tools, plc ladder updates, opc/pc middleware, hmi interfaces, energy management systems, and mobile monitoring apps.
Explore common ICS/SCADA protocols, including DNP3, Modbus, BACnet, S7, OPC, and Ethernet/IP, and understand master remote and client-server data exchange and control across substations.
Explore current security standards and guidance for critical infrastructure, including nerk cip standards for the North American Electric Reliability Corporation's critical infrastructure protection and related best practices.
Defend ICS/SCADA by addressing insecure, unauthenticated protocols like Modbus that expose devices to cleartext access. Recognize hardware and software vulnerabilities, including hard-coded credentials and back doors, and monitor DHS alerts.
Explore the ICS/SCADA threat landscape by examining historic and current threat activity events, including supply chain risks, spear phishing, waterhole and remote access, that threaten availability and safety.
Identify and defend against ICS/SCADA attack surfaces by examining hardware, backdoors, software, operating systems, and mobile threats, including ports, services, and data flows.
Know thyself to defend ICS/SCADA environments by hands-on lab work with the IO logic device, researching hardware and software using Wireshark and Nmap.
Examine the device manual ports and services, verify findings with scans and traffic captures, and learn Modbus function codes and IO admin interactions on the Mock's device.
Learn how snmp (smp) uses management information bases and IDs to monitor devices, compare v1 insecure cleartext with v3 encryption and authentication, and defend http on port 80 and 9900.
Identify undocumented and documented open ports on the Moxa device, monitor traffic and enforce port closures or blocking with firewalls and IDS/IPS, then harden protocols and monitor trusted data flows.
Baseline and verify software using vendor hashes, file hashes, and user inventories; identify hard-coded or missing passwords, and use PowerShell and Windows commands to defend ICS/SCADA systems.
Understand why logging matters in ICS/SCADA, monitor hardware and software health, safety, and security incidents, and evaluate SNMP traps and IO event log usage across devices.
Learn to defend industrial systems by monitoring internet facing devices and rogue wireless or cellular nodes. Track IP ranges and traffic to detect anomalies and prevent unauthorized access.
Our world is growing more and more dependent upon technology and systems that monitor and control industrial processes. The electric power grid, water and sewage systems, oil and natural gas pipelines, and many more critical infrastructure utilize Industrial Control Systems/Supervisory Control and Data Acquisition (ICS/SCADA) systems. ICS/SCADA is used to monitor and control these infrastructure processes. This ICS/SCADA Cyber Security course will provide you with a strong foundation in the field of ICS/SCADA Cyber Security. You will learn about various topics such as What is ICS/SCADA? What is the current ICS/SCADA Threat Landscape? How to defend yourself? and many more topics.