Operational Technology Cyber Security for Energy Utilities Training Course
| Course code | SD-CS-053 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Energy utilities operate control environments where a cyber incident can interrupt generation, transmission, distribution, water processing, or field operations. IT security controls alone do not address the realities of SCADA, distributed control systems, programmable logic controllers, remote terminal units, engineering workstations, and vendor-maintained assets. This course helps participants make defensible security decisions while protecting safety, availability, regulatory obligations, and operational continuity across electric, gas, and renewable energy environments.
Participants learn to map operational technology assets and communication paths, distinguish IT and OT risk treatment, identify insecure remote access and supplier connections, and apply IEC 62443 concepts to utility zones and conduits. They practise conducting an OT-focused risk assessment, prioritising vulnerabilities without creating unsafe outage work, analysing attack paths with MITRE ATT&CK for ICS, and defining monitoring, incident response, backup, and recovery controls suited to control-system operations. The course also addresses the governance required to align cyber security, operations, engineering, safety, and third-party service providers.
Instruction combines expert-led technical briefings with utility incident cases, architecture reviews, tabletop response exercises, and facilitated design workshops. Participants work from a realistic utility OT environment containing control centres, substations, field devices, historian systems, and vendor remote access. They leave with an OT Cyber Security Improvement Plan: a documented asset and connectivity view, prioritised risk register, target control recommendations, incident-response actions, and a 90-day implementation roadmap that can be adapted for their own utility.
The programme is designed for professionals who already work around utility operations or industrial systems and need to contribute credibly to cyber risk reduction. It is particularly valuable where IT security teams, OT engineers, and operational leaders must agree practical controls without compromising plant or network availability.
Course objectives
By the end of this course, participants will be able to:
- Map utility OT assets, data flows, trust boundaries, and external connections using an OT asset inventory template
- Apply IEC 62443 zones-and-conduits modelling to segment SCADA, substation, field, and enterprise networks
- Conduct an OT cyber risk assessment that accounts for safety, availability, environmental, and service-continuity impacts
- Analyse utility attack paths using MITRE ATT&CK for ICS techniques and documented adversary behaviours
- Evaluate remote access, engineering workstation, and vendor-support arrangements against least-privilege control requirements
- Prioritise OT vulnerabilities using compensating controls, maintenance windows, operational criticality, and remediation feasibility
- Develop an OT incident response playbook covering detection, operator escalation, containment, evidence handling, and service restoration
- Produce a 90-day OT Cyber Security Improvement Plan with named control actions, owners, dependencies, and success measures
Benefits of attending
For you
- Gain a structured way to discuss cyber risk with control engineers, operators, safety teams, and senior utility leaders
- Build confidence in assessing OT security issues without applying unsuitable enterprise IT controls to operational systems
- Develop a portfolio-ready OT Cyber Security Improvement Plan based on a realistic utility architecture
- Strengthen credibility for roles involving SCADA security, critical infrastructure resilience, or utility cyber governance
- Learn to justify remediation priorities using operational criticality, safety consequences, and implementation constraints
For your organisation
- Create a more consistent method for identifying and prioritising cyber risk across control centres, substations, plants, and field sites
- Reduce exposure from unmanaged vendor access, weak engineering workstation controls, and poorly segmented OT networks
- Improve coordination between IT security, operations, engineering, safety, procurement, and third-party maintenance providers
- Strengthen incident readiness through OT-specific escalation, containment, restoration, and evidence-handling procedures
- Generate an actionable 90-day improvement roadmap that can inform security investment, maintenance planning, and assurance reporting
Target competencies
Who should attend
- OT Cyber Security Specialists — who need a repeatable method for assessing and improving utility control-system security
- SCADA and Control Systems Engineers — who design, maintain, or support operational networks and connected field assets
- Utility IT Security Managers — who must extend enterprise security governance into operational environments without disrupting service
- Substation, Generation, and Distribution Engineers — who need to recognise cyber risk in protection, automation, and control systems
- Operational Technology Managers — who approve security priorities, supplier access, and outage-related remediation decisions
- Incident Response and Business Continuity Practitioners — who must prepare for cyber events affecting utility operations and restoration
Requirements and prerequisites
Participants should have working familiarity with utility operational environments, such as SCADA, DCS, PLCs, RTUs, substations, generation plants, distribution networks, or control-room operations. They should understand basic networking terms including IP addressing, firewalls, VLANs, remote access, and network segmentation, plus core cyber security concepts such as vulnerabilities, access control, logging, and incident response. Prior experience with an OT security platform is not required. Participants do not need to programme PLCs, configure production firewalls, conduct penetration tests, or hold a prior IEC 62443 certification.
Training methodology
The course uses instructor-led sessions to establish utility OT security principles, followed by hands-on architecture reviews and risk-analysis exercises. Participants examine a simulated energy utility environment spanning a control centre, substation network, field communications, historian platform, and supplier remote-access gateway. Small groups use IEC 62443, NIST CSF 2.0, and MITRE ATT&CK for ICS to make control decisions, defend priorities, and run an incident tabletop. The final workshop converts findings into a practical 90-day improvement plan for workplace application.
Course outline
Day 1: Utility OT threat landscape and asset visibility
- Energy utility OT architecture: control centres, substations, plants, and field networks
- Differences between IT, OT, industrial control systems, and critical infrastructure risk
- SCADA, DCS, PLC, RTU, IED, historian, and engineering workstation functions
- Safety, availability, reliability, and environmental impact as cyber risk factors
- OT asset inventory fields, ownership models, and criticality classification
- Passive discovery versus active scanning in operational environments
- OT communication paths, protocol exposure, and trust-boundary identification
Workshop: Participants build an asset inventory and connectivity map for a simulated utility control environment, identifying critical systems and unmanaged connections.
Day 2: Segmentation, access control, and secure architecture
- IEC 62443 security levels, foundational requirements, and lifecycle concepts
- Zones-and-conduits modelling for utility OT environments
- Purdue Model interpretation and limitations in modern utility architectures
- Firewall policy design between enterprise, DMZ, control, and field zones
- Secure remote access patterns for vendors, operators, and engineering support
- Privileged access management for shared OT accounts and engineering tools
- Hardening controls for engineering workstations, jump hosts, and portable media
Workshop: Participants create a zones-and-conduits diagram and draft remote-access control requirements for a utility vendor-support scenario.
Day 3: Threat analysis and OT risk prioritisation
- Utility threat actors, motivations, and attack campaign patterns
- MITRE ATT&CK for ICS tactics, techniques, and procedure mapping
- Attack-path analysis from enterprise compromise to operational disruption
- OT vulnerability assessment constraints and safe validation practices
- Risk scoring using likelihood, operational impact, safety impact, and recoverability
- Compensating controls for legacy and unsupported control-system assets
- Risk treatment decisions: remediate, mitigate, transfer, accept, or monitor
Workshop: Participants analyse an attack path involving compromised vendor credentials and produce a prioritised OT risk register with treatment recommendations.
Day 4: Detection, response, and resilient recovery
- OT security monitoring use cases for network, endpoint, and authentication events
- Baseline behaviour and anomaly detection in industrial communications
- Log sources from firewalls, jump servers, historians, Windows hosts, and security appliances
- OT incident classification, operator notification, and command escalation
- Containment options that preserve safe operation and avoid uncontrolled outages
- Forensic evidence handling in safety-critical and operationally sensitive environments
- Backup, golden-image, configuration recovery, and restoration testing for OT assets
Workshop: Participants conduct a tabletop response to suspicious substation network activity and produce an OT incident playbook with escalation and recovery actions.
Day 5: Governance, assurance, and improvement planning
- NIST Cybersecurity Framework 2.0 application to utility OT governance
- Security roles across operations, engineering, IT, safety, procurement, and executive leadership
- Third-party cyber security requirements for integrators, OEMs, and maintenance providers
- Security requirements for new OT projects, upgrades, and procurement specifications
- OT security metrics for asset coverage, access control, vulnerability treatment, and recovery readiness
- Audit evidence and assurance reporting for critical infrastructure stakeholders
- 90-day improvement roadmap design, dependency mapping, and executive communication
Workshop: Participants consolidate their course outputs into an OT Cyber Security Improvement Plan with prioritised actions, accountable owners, dependencies, and measures.
Tools & standards covered
IEC 62443, NIST Cybersecurity Framework 2.0, MITRE ATT&CK for ICS, Microsoft Defender for IoT
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
COBIT 2019 Cyber Risk Governance Training Course
Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding …
Advanced Cyber Threat Hunting and Incident Response Training Course
Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitim…
IBM QRadar SIEM Administration and Offence Investigation Training Course
IBM QRadar administrators and SOC analysts are expected to turn high-volume event data into defensible security decisions. That requires mor…
Zero Trust Architecture Using NIST SP 800-207 Training Course
Perimeter-based security controls do not adequately protect organisations where users work remotely, workloads span cloud and data centre en…