
Alexandra Sergi shares years of experience in industrial IT and grid market software, highlighting security lessons for SCADA and ITOT. She invites learners to deepen their cybersecurity knowledge and practice.
Explore how scada systems automate industrial processes with real-time data from field controllers and human-machine interfaces, while cybersecurity and standards guide secure, reliable operation.
Explore the components of a SCADA platform, from field sensors and actuators to RTUs, PLCs, scalar servers, software, and cyber security for real-time data and secure control.
Explore the relationship between SCADA and ITOT, tracing the shift from specialized signaling to TCP/IP networks. Learn why securing standard networks and servers is essential for modern industrial systems.
Apply international standards such as ISO 27001/27002 and IEC guidelines, implement defense in depth and zero trust, and maintain ongoing system management to secure industrial scada and itot architectures.
Plan ITOT designs with a main site and an emergency site, using active-active or active-passive redundancy for availability. Apply data center redundancy principles and account for criticality and site distance.
Use redundancy across networks, servers, power, and climate sources to prevent downtime, remove single points of failure, and avoid unnecessary redundancy for non-critical systems under budget constraints.
Identify single point of failure scenarios, from one power source to redundant components. Examine risks of shared power circuits, host-level VM clustering, and firewall diversity to prevent SPOF.
Plan maintenance windows for redundant units in series, updating one unit at a time. Validate on the passive or secondary unit before updating the partner and observe for hidden issues.
Explore the 2025 threat landscape for industrial SCADA and OT/ITOT, featuring AI-driven attacks, supply chain compromises, firmware tampering, and defense priorities like zero trust and AI-powered anomaly detection.
Explore the CIA triad—confidentiality, integrity, and availability—and how it underpins cybersecurity, guiding vulnerability assessment and the development of security systems and solutions.
Discover zero trust and defense in depth, applying least privilege and deny-by-default access. Implement MFA, known endpoints, encryption in transit and at rest, and monitored user management.
Enforce least privilege through micro-segmentation, MFA, and strict access controls, and use LDAP and Active Directory to manage authentication and authorization in robust AD deployments.
Multi-factor authentication strengthens security with rotating tokens or mobile push, reducing password theft and brute-force risks, while warning of multi-factor fatigue and one-time password expiration and text-message vulnerability.
Endpoints include engineering workstations and field devices; enforce strict access via 802.1X, MAC filtering, and network segmentation, with firmware updates for embedded devices and authorization-based connections.
Learn the 802.1x network protocol, detailing the authentication flow from initialization and unauthorized state to authorize state, with radius exchanges and endpoint agent remediation.
Implement network access control to support zero trust authorization for users and devices, enforce device posture checks, quarantine unsecured devices, manage policies, and assess overall security posture during remote access.
Defense in depth integrates patching, malware detection, asset management, logging, data analysis, sandboxing, and vulnerability testing to prevent threats and enable rapid reaction to suspicious activity.
Adopt zero trust by never trusting and always verifying, ensuring data in transit and at rest are not in clear text. Encrypt backups to prevent attacker access and data exfiltration.
Explore how AI in OT and SCADA enables machine learning anomaly detection on baseline operational data to spot intrusions and malfunctions, while countering evolving supply chain and deepfake threats.
Segment networks by role and risk. Create micro segments for servers such as scalar, database engineering, cybersecurity, and infrastructure, and segregate workstations with two zones and timed access to repositories.
Implement role-based segmentation to isolate historian databases and SQL servers on separate networks, with DMZ or core placements as architecture dictates, and secure infra for authentication using Windows and LDAP.
Understand risk-based segmentation across cybersecurity zones, from zone one internet facing to zone five most difficult to access, with bastion hosts, gateways, data diodes, and dedicated firewalls.
Choose reputable switches with capacity and secure vlan segmentation for core servers, workstations, VMs, and backups; enable redundancy, avoid single points of failure, and consider virtual distributor switches for VMware.
Explore zero trust principles with next-gen firewalls that integrate ips and ids, encrypt data efficiently for real-time systems, and emphasize redundancy and no single point of failure.
Explore intrusion detection and prevention systems: IDS monitors network traffic to detect threats and raise alerts, while IPS actively blocks or remediates threats using signature, anomaly, or hybrid methods.
Encrypt data in transit with tunnels and encrypted protocols, and encrypt data at rest; use TLS 1.2+ for web traffic and SSH v2, avoid telnet or FTP.
Identify and secure remote access for industrial systems by selecting vendors who support required protocols, using bastions or gateways, and restricting traffic to prevent illegitimate access.
Apply zero trust for corporate access with privileged access management (pam) and jump hosts over https, using vault-stored credentials, session recording, and time-limited access for vendors and reporting purposes.
Explore remote devices and serial and proprietary protocols, including Modbus over TCP. Learn how encryption, authentication, authorization, OPC security, and compensating measures shield industrial networks.
Explore how physical servers enable remote management and require a dedicated management VLAN. Avoid insecure protocols like SNMP v1 and http while noting patching tradeoffs in virtualization.
Examine cloud servers in industrial SCADA and ITOT, addressing real-time latency, non‑tcp/ip end devices, on-premises security, data localization, and legacy software constraints.
Assess virtualization layers for industrial SCADA and ITOT security, comparing VMware with Hyper-V, and examining redundancy, snapshots, migration, and real-time failover considerations.
Compare Windows and Linux security realities, debunk myths about Linux, and avoid root or local accounts while enabling encryption at rest and timely updates.
Synchronize all devices to the same time source using GPS receivers, ensure redundancy, and secure http interfaces with authentication while considering data diodes for one-way transfer.
Apply defense in depth for industrial SCADA and ITOT by balancing proactive measures—patching, upgrades, hardware refresh, malware/IPS updates, and regular vulnerability scans—with reactive procedures, monitoring, and escalation to SOC/NOC.
Patch management spans Windows, Linux, embedded devices, and network equipment firmware, with staging via AWS or local repositories, maintenance windows, testing in a staging environment, and cautious rollout.
Defend industrial scada and itot against malware and data stealing by deploying a next-gen endpoint security solution, sandboxing unknown apps, and trusted application controls with trusted certificates and whitelisting, monitoring.
Learn secure patching for out-of-band networks by using limited, timed access to local management and repositories during maintenance windows, avoiding trojan horse risk with strict protocol whitelisting.
Move from decentralized to centralized management by using a centralized repository to apply policies, patch, monitor logs, and track hardware and software changes across Windows, Linux, virtualization, and physical environments.
Analyze securing common network protocols on the scatter platform, compare secure variants, and compile a holistic list of protocols, highlighting HTTPS, StartTLS, TLS 1.1, SSH, WMI, SNMP, and compensation controls.
Explore vulnerability testing and assessment using tools like Kali Linux and Nessus, learn to think like a hacker, and plan red, blue, and white team exercises with external consultants safely.
Monitor the platform to detect anomalies such as unusual traffic and latency on TCP ports or services. Integrate Nagios or PRTG to trigger operator alarms and responses, including read-only dashboards.
Automate asset inventory scans to monitor hardware and software across SCADA and ITOT environments. Detect rogue and temporary devices and unauthorized software, triggering investigations with network scans and ping sweeps.
Identify threats with a properly installed and configured syslog server and secure against tampering; avoid using it for reconnaissance. Allocate storage for data retention and deduplication, and back up logs.
Analyze traffic using data analysis, mirroring, trapping, and network taps to detect patterns and lateral movement that ips and scanners miss across physical and virtual distributed switches.
NetFlow and sFlow analyze network traffic through interfaces, revealing origin, destination, and volume. NetFlow is Cisco proprietary, with SNMP as an alternative when unavailable, though performance may be impacted.
Learn how firewalls decrypt encrypted traffic for analysis using a middlebox, inspect https traffic with a trusted certificate, and route it to a mirror analyzer to block or detect malware.
Explore siem, security information and event management, collecting and correlating syslog and windows events across vendors to trigger meaningful alerts with minimal false alarms and clear operator response.
Implement scatter platform backups that minimize impact on real-time traffic, avoid concurrent backups, include testing and restoration procedures, and define RPO/RTO per server, while distinguishing backups from archival for compliance.
In this course, I will give an overview on how to design and implement highly secure SCADA platforms. This course can be a good start point for beginners and also I hope will be interesting to follow even for experts in the field. The theory from this course will surely need adaptation over time while new threats will appear.
The course follows zero trust techniques that I am also using in my daily activities. They are very important because older frameworks which contains even methods like just unplugging cable and considering it more secure. methods that was proven in practice to be a really bad one.
This course is intended to share the knowledge I gathered in many years of experience. I will happily accept discussions invites and debates and maybe they will me and also this course to improve while we all improve the security of our systems.
This will not be the definite containing all and have the direct and proven path to success. I can't say enough, cyber security needs to evolve over time at same rate or better than vulnerabilities evolves. Our lives start to depend more end more on IT and OT is just a part that usually we don't easily see with our own eyes but believe me, you don't want an OT system to be hacked and used in malicious activities.