
Explore operational technology concepts in ot cybersecurity 101, covering ot components, industrial control protocols like modbus, it vs ot, the Purdue model, and a water treatment plant scenario.
Explore operational technology, where hardware and software control and monitor industrial equipment and processes, using sensors, actuators, PLCs, HMIs, and supervisory control systems.
Explore how industrial control systems interconnect via open and proprietary protocols, focusing on Modbus TCP, Mbap headers and PDU, and security gaps like no authentication, authorization, or encryption.
Explore how critical infrastructures like water treatment plants and industrial control systems ensure safe drinking water and how attackers could disrupt ICS communications.
Contrast IT and OT roles in industrial environments, highlighting ICS attack surfaces, availability-driven OT security, long asset lifecycles, outdated systems, default credentials, and the human factor in cyber risk.
Explore IT and OT convergence under industry 4.0, enabling real-time data analytics, predictive maintenance, and automated operations, and examine the Purdue model’s six to seven zones linking IT and OT.
Examine how attacks on industrial control systems in oil and gas threaten critical infrastructure, fuel supply, and energy prices, with the Colonial Pipeline incident as a real-world example.
Explore how Modbus TCP enables real-time communication between industrial control systems and wellhead equipment, pipeline sensors, and downhole tools for monitoring and remote control in oil and gas.
Demonstrate the attack workflow by first showing the normal operation of the proof of concept, then review assumptions and considerations, and finally launch the attack.
Demonstrate the normal working of an industrial control system with HMI and PLC communication, sensors, valve control, and setpoints, and explore a simulated attack disrupting the process.
Identify the core assumptions for an OT network attack, detailing outsider or insider access and the attacker's knowledge of PLC and HMI configurations, protocols, data addresses, and function codes.
Demonstrates launching a Modbus TCP attack on an industrial control system by manipulating the emergency shutdown and valve via a Modbus client in Metasploit, exposing HMI-to-PLC risk in OT cybersecurity.
"OT Cyber Security 101" is a comprehensive course designed to equip learners with the essential knowledge of how the cyber threats to Operational Technology (OT) environments can be manifested. Delving into the intricacies of OT systems, participants will explore the hardware and software components that control and monitor industrial equipment across various sectors, including water treatment plants and oil refineries. Through a detailed examination of Industrial Control Systems (ICSs) and communication protocols like Modbus, participants will understand the vulnerabilities and security challenges inherent in OT networks. The course emphasizes the critical importance of securing critical infrastructures, such as oil & gas industries, highlighting the potential consequences of cyber-attacks on these systems. Participants will differentiate between Information Technology (IT) and OT, understanding their unique functionalities, operational lifecycles, and security requirements. Practical insights into attack surfaces in OT environments, along with real-world examples like the Colonial Pipeline ransomware attack, provide a nuanced understanding of the cyber threats faced by OT systems. By exploring the convergence of IT and OT and leveraging frameworks like the Purdue Model, learners will develop robust understanding of how IT and OT interconnect. Through a hands-on demonstration, participants will understand how simple it is to launch attacks on Industrial Control Systems.