Course Overview
Operational technology environments present security challenges that IT security methodologies cannot solve without modification. Legacy protocols, air-gap assumptions that no longer hold, operational lifespans measured in decades, and the absolute requirement to prioritise availability and safety over confidentiality create an attack surface that is simultaneously critical and fragile. This four-day programme develops the specialist skills to protect complex OT environments against the advanced persistent threats targeting industrial systems in 2026.
Across four mentor-led days, participants conduct OT security assessments using IEC 62443, design network segmentation for complex industrial environments using zone-and-conduit methodology, monitor OT networks passively without disrupting operations, analyse ICS-specific malware including TRITON/TRISIS, FrostyGoop, and VoltRuptor, manage vendor remote access risk, and plan OT-specific incident response without causing physical damage or service disruption.
The programme culminates in a full OT security assessment capstone of a simulated industrial environment, producing an asset inventory, risk rating, zone design, vendor access review, and prioritised remediation roadmap. This course is aligned with IEC 62443, SANS five critical controls for ICS, NCSC OT security guidance, and NIS2 essential entity obligations for industrial operators.
Hands-On Learning
Passive OT asset discovery lab, Dragos and Claroty monitoring deployment exercises, ICS malware indicator analysis, zone-and-conduit design workshop, and a full simulated OT environment capstone assessment.
Mentor-Led Sessions
Practitioner-led analysis of TRITON/TRISIS, FrostyGoop, and VoltRuptor with live commentary on current OT targeting doctrine, IEC 62443 implementation in real environments, and vendor access security design.
Career-Ready Skills
OT security assessment using IEC 62443, passive OT monitoring, ICS malware analysis, zone-and-conduit network design, vendor access security, and OT business continuity planning.
Learning Outcomes
Conduct a full OT security assessment of a complex industrial environment using IEC 62443 methodology.
Design network segmentation for IT/OT convergence environments using zone-and-conduit design principles.
Monitor OT environments using passive network inspection without disrupting any operational process.
Respond to OT-specific cyber incidents without causing physical damage or uncontrolled service disruption.
Apply SANS five critical controls for ICS security to a manufacturing or utilities environment.
Analyse ICS-specific malware indicators including TRITON/TRISIS, FrostyGoop, and VoltRuptor.
Design a vendor access management programme that meets operational requirements and security objectives.
Prerequisites
Professional experience in OT security engineering, industrial control systems, or plant operations security.
Understanding of industrial control system architecture including PLCs, HMIs, and SCADA components.
Familiarity with network security fundamentals including segmentation, monitoring, and access control.
Detailed Syllabus
Step-by-step learning journey from basics to professional practice
Topics Covered
- Pre-reading: IEC 62443 framework overview and SANS five critical controls for ICS security
- Introduction to the Purdue model and OT-specific threat landscape for 2026
- Lab environment access configuration: Dragos and Claroty trial platform setup
- Course objectives, OT security knowledge baseline self-assessment, and pathway alignment
Skills You'll Gain
Master these in-demand skills through hands-on practice
Career Progression
A clear view of the roles this programme supports, what typically comes next, and where learners progress over time
Ways to Learn
Choose the learning format that works best for you and your team
Live Online
Instructor-Led Training
Join live instructor-led sessions from anywhere. Interactive, engaging, and flexible.
- Live instructor interaction (real-time)
- Trainer-led walkthroughs and real examples
- Guided resources and session notes provided
- Structured Q&A and practical discussion
Price per person
Group enrolments and early planning options available.
All prices are exclusive of VAT where applicable. Group enrolments and custom packages available on request.
Prefer a Faster, Personalised Route into IT?
Not everyone learns best in a group. If you want focused guidance, faster clarity, and confidence you can use on the job, our 1-to-1 Fast-Track Training gives you private, mentor-led support tailored to your experience and goals.
"Many learners choose 1-to-1 when they want understanding, not memorisation."
Exam & Certification Information
Everything you need to know about the certification exams
Important Information
You will receive an Xcademia certificate of completion based on participation and successful completion of labs and scenario simulations.
Credential
Certificate of Completion
On successful completion of OT, ICS and SCADA Security Operations, learners receive an Xcademia Certificate of Completion. This standalone certificate is issued directly by Xcademia and is aligned with globally recognised frameworks and best practices.
Frequently Asked Questions
Everything you need to know about this course
OT security engineers, ICS operators, plant managers, manufacturing security leads, and utilities security engineers with direct responsibility for industrial control system security.
Ready to Start Your Learning Journey?
Take the next step in your professional development