Operational Technology Cyber Security for Energy Utilities Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-053
Duration5 days
LevelIntermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Energy utilities operate control environments where a cyber incident can interrupt generation, transmission, distribution, water processing, or field operations. IT security controls alone do not address the realities of SCADA, distributed control systems, programmable logic controllers, remote terminal units, engineering workstations, and vendor-maintained assets. This course helps participants make defensible security decisions while protecting safety, availability, regulatory obligations, and operational continuity across electric, gas, and renewable energy environments.

Participants learn to map operational technology assets and communication paths, distinguish IT and OT risk treatment, identify insecure remote access and supplier connections, and apply IEC 62443 concepts to utility zones and conduits. They practise conducting an OT-focused risk assessment, prioritising vulnerabilities without creating unsafe outage work, analysing attack paths with MITRE ATT&CK for ICS, and defining monitoring, incident response, backup, and recovery controls suited to control-system operations. The course also addresses the governance required to align cyber security, operations, engineering, safety, and third-party service providers.

Instruction combines expert-led technical briefings with utility incident cases, architecture reviews, tabletop response exercises, and facilitated design workshops. Participants work from a realistic utility OT environment containing control centres, substations, field devices, historian systems, and vendor remote access. They leave with an OT Cyber Security Improvement Plan: a documented asset and connectivity view, prioritised risk register, target control recommendations, incident-response actions, and a 90-day implementation roadmap that can be adapted for their own utility.

The programme is designed for professionals who already work around utility operations or industrial systems and need to contribute credibly to cyber risk reduction. It is particularly valuable where IT security teams, OT engineers, and operational leaders must agree practical controls without compromising plant or network availability.

Course objectives

By the end of this course, participants will be able to:

  • Map utility OT assets, data flows, trust boundaries, and external connections using an OT asset inventory template
  • Apply IEC 62443 zones-and-conduits modelling to segment SCADA, substation, field, and enterprise networks
  • Conduct an OT cyber risk assessment that accounts for safety, availability, environmental, and service-continuity impacts
  • Analyse utility attack paths using MITRE ATT&CK for ICS techniques and documented adversary behaviours
  • Evaluate remote access, engineering workstation, and vendor-support arrangements against least-privilege control requirements
  • Prioritise OT vulnerabilities using compensating controls, maintenance windows, operational criticality, and remediation feasibility
  • Develop an OT incident response playbook covering detection, operator escalation, containment, evidence handling, and service restoration
  • Produce a 90-day OT Cyber Security Improvement Plan with named control actions, owners, dependencies, and success measures

Benefits of attending

For you

  • Gain a structured way to discuss cyber risk with control engineers, operators, safety teams, and senior utility leaders
  • Build confidence in assessing OT security issues without applying unsuitable enterprise IT controls to operational systems
  • Develop a portfolio-ready OT Cyber Security Improvement Plan based on a realistic utility architecture
  • Strengthen credibility for roles involving SCADA security, critical infrastructure resilience, or utility cyber governance
  • Learn to justify remediation priorities using operational criticality, safety consequences, and implementation constraints

For your organisation

  • Create a more consistent method for identifying and prioritising cyber risk across control centres, substations, plants, and field sites
  • Reduce exposure from unmanaged vendor access, weak engineering workstation controls, and poorly segmented OT networks
  • Improve coordination between IT security, operations, engineering, safety, procurement, and third-party maintenance providers
  • Strengthen incident readiness through OT-specific escalation, containment, restoration, and evidence-handling procedures
  • Generate an actionable 90-day improvement roadmap that can inform security investment, maintenance planning, and assurance reporting

Target competencies

OT asset mappingZones and conduitsICS threat analysisOT risk assessmentRemote access securityIncident response planning

Who should attend

  • OT Cyber Security Specialists — who need a repeatable method for assessing and improving utility control-system security
  • SCADA and Control Systems Engineers — who design, maintain, or support operational networks and connected field assets
  • Utility IT Security Managers — who must extend enterprise security governance into operational environments without disrupting service
  • Substation, Generation, and Distribution Engineers — who need to recognise cyber risk in protection, automation, and control systems
  • Operational Technology Managers — who approve security priorities, supplier access, and outage-related remediation decisions
  • Incident Response and Business Continuity Practitioners — who must prepare for cyber events affecting utility operations and restoration

Requirements and prerequisites

Participants should have working familiarity with utility operational environments, such as SCADA, DCS, PLCs, RTUs, substations, generation plants, distribution networks, or control-room operations. They should understand basic networking terms including IP addressing, firewalls, VLANs, remote access, and network segmentation, plus core cyber security concepts such as vulnerabilities, access control, logging, and incident response. Prior experience with an OT security platform is not required. Participants do not need to programme PLCs, configure production firewalls, conduct penetration tests, or hold a prior IEC 62443 certification.

Training methodology

The course uses instructor-led sessions to establish utility OT security principles, followed by hands-on architecture reviews and risk-analysis exercises. Participants examine a simulated energy utility environment spanning a control centre, substation network, field communications, historian platform, and supplier remote-access gateway. Small groups use IEC 62443, NIST CSF 2.0, and MITRE ATT&CK for ICS to make control decisions, defend priorities, and run an incident tabletop. The final workshop converts findings into a practical 90-day improvement plan for workplace application.

Course outline

Day 1: Utility OT threat landscape and asset visibility

  • Energy utility OT architecture: control centres, substations, plants, and field networks
  • Differences between IT, OT, industrial control systems, and critical infrastructure risk
  • SCADA, DCS, PLC, RTU, IED, historian, and engineering workstation functions
  • Safety, availability, reliability, and environmental impact as cyber risk factors
  • OT asset inventory fields, ownership models, and criticality classification
  • Passive discovery versus active scanning in operational environments
  • OT communication paths, protocol exposure, and trust-boundary identification

Workshop: Participants build an asset inventory and connectivity map for a simulated utility control environment, identifying critical systems and unmanaged connections.

Day 2: Segmentation, access control, and secure architecture

  • IEC 62443 security levels, foundational requirements, and lifecycle concepts
  • Zones-and-conduits modelling for utility OT environments
  • Purdue Model interpretation and limitations in modern utility architectures
  • Firewall policy design between enterprise, DMZ, control, and field zones
  • Secure remote access patterns for vendors, operators, and engineering support
  • Privileged access management for shared OT accounts and engineering tools
  • Hardening controls for engineering workstations, jump hosts, and portable media

Workshop: Participants create a zones-and-conduits diagram and draft remote-access control requirements for a utility vendor-support scenario.

Day 3: Threat analysis and OT risk prioritisation

  • Utility threat actors, motivations, and attack campaign patterns
  • MITRE ATT&CK for ICS tactics, techniques, and procedure mapping
  • Attack-path analysis from enterprise compromise to operational disruption
  • OT vulnerability assessment constraints and safe validation practices
  • Risk scoring using likelihood, operational impact, safety impact, and recoverability
  • Compensating controls for legacy and unsupported control-system assets
  • Risk treatment decisions: remediate, mitigate, transfer, accept, or monitor

Workshop: Participants analyse an attack path involving compromised vendor credentials and produce a prioritised OT risk register with treatment recommendations.

Day 4: Detection, response, and resilient recovery

  • OT security monitoring use cases for network, endpoint, and authentication events
  • Baseline behaviour and anomaly detection in industrial communications
  • Log sources from firewalls, jump servers, historians, Windows hosts, and security appliances
  • OT incident classification, operator notification, and command escalation
  • Containment options that preserve safe operation and avoid uncontrolled outages
  • Forensic evidence handling in safety-critical and operationally sensitive environments
  • Backup, golden-image, configuration recovery, and restoration testing for OT assets

Workshop: Participants conduct a tabletop response to suspicious substation network activity and produce an OT incident playbook with escalation and recovery actions.

Day 5: Governance, assurance, and improvement planning

  • NIST Cybersecurity Framework 2.0 application to utility OT governance
  • Security roles across operations, engineering, IT, safety, procurement, and executive leadership
  • Third-party cyber security requirements for integrators, OEMs, and maintenance providers
  • Security requirements for new OT projects, upgrades, and procurement specifications
  • OT security metrics for asset coverage, access control, vulnerability treatment, and recovery readiness
  • Audit evidence and assurance reporting for critical infrastructure stakeholders
  • 90-day improvement roadmap design, dependency mapping, and executive communication

Workshop: Participants consolidate their course outputs into an OT Cyber Security Improvement Plan with prioritised actions, accountable owners, dependencies, and measures.

Tools & standards covered

IEC 62443, NIST Cybersecurity Framework 2.0, MITRE ATT&CK for ICS, Microsoft Defender for IoT

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand the purpose of common utility OT components such as SCADA systems, PLCs, RTUs, IEDs, control networks, or engineering workstations. Basic networking and cyber security vocabulary is assumed, but you do not need prior IEC 62443 certification or penetration-testing experience.

A standard laptop capable of joining the classroom or live-online environment is sufficient. Course exercises use instructor-provided templates, diagrams, scenarios, and guided demonstrations; participants will not connect to live utility systems or need licensed production tools.

It is designed for both groups because effective OT security depends on shared decisions between cyber teams and operational specialists. Security professionals gain utility context, while engineers and operations personnel gain structured methods for recognising and reducing cyber risk.

The course addresses the constraints of operational systems: safety, uptime, legacy equipment, maintenance windows, industrial protocols, and operator-led incident decisions. It applies IEC 62443, MITRE ATT&CK for ICS, and utility architecture scenarios rather than focusing on enterprise endpoints and office networks alone.

Participants can use the asset inventory, connectivity mapping, risk register, zones-and-conduits model, and incident playbook formats with their own sites and systems. The final 90-day roadmap is designed to support practical conversations with operations, IT, suppliers, and budget holders.

You will leave with a completed OT Cyber Security Improvement Plan developed through the course scenario. It includes an asset and connectivity view, prioritised risks, recommended controls, incident-response actions, and a sequenced implementation roadmap that can be tailored to your utility.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

COBIT 2019 Cyber Risk Governance Training Course

Cybersecurity teams often maintain risk registers, security controls and incident reports without a clear governance mechanism for deciding …

5 Days Certificate

Advanced Cyber Threat Hunting and Incident Response Training Course

Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitim…

5 Days Certificate

IBM QRadar SIEM Administration and Offence Investigation Training Course

IBM QRadar administrators and SOC analysts are expected to turn high-volume event data into defensible security decisions. That requires mor…

10 Days Certificate

Zero Trust Architecture Using NIST SP 800-207 Training Course

Perimeter-based security controls do not adequately protect organisations where users work remotely, workloads span cloud and data centre en…