Course Description
Industrial control systems were designed for reliability and availability, not security — and then they were connected. PLCs, DCS and SCADA systems now carry cyber risk with physical consequences, and the engineers who run them are the people best placed to defend them, provided they understand how attacks work.
This course develops practical ICS and SCADA security understanding for engineers. Participants learn control system architecture and the Purdue model, industrial protocols and their weaknesses (Modbus, S7, DNP3, OPC-UA), how real attacks on industrial systems have worked, vulnerability assessment approaches safe for fragile systems, and the technical controls that harden industrial environments.
What you will achieve
By the end of this training course, participants will be able to:
- Explain why ICS security differs from IT security
- Describe control system architecture and the Purdue model
- Understand PLC, DCS, SCADA and HMI components
- Explain industrial protocols and their security weaknesses
- Understand how real attacks on ICS have worked
- Apply safe assessment methods to sensitive systems
- Implement technical controls and hardening
- Build defence in depth for industrial environments
How the course is delivered
The course combines control system architecture with security analysis, using real industrial attack case studies. Participants work through protocol weaknesses, architecture review and hardening scenarios on realistic plant configurations.
The programme is designed for engineers who own and operate control systems, emphasising safe assessment of systems that cannot simply be patched or taken offline.
Designed for
This training course is ideal for:
- Automation, control and instrumentation engineers
- OT and plant engineers
- Maintenance and reliability engineers
- IT security staff supporting industrial sites
- Anyone responsible for control system security
Daily programme
- Why ICS security is different: safety and availability
- Control system architecture
- The Purdue reference model
- PLC, DCS, SCADA, HMI and historians
- Modbus and its weaknesses
- S7, DNP3 and legacy protocols
- OPC and OPC-UA
- Protocol security and monitoring
- How real ICS attacks have worked
- Threat actors and industrial malware
- Safe vulnerability assessment on fragile systems
- Asset inventory in OT
- Technical controls and hardening
- Secure remote access
- Monitoring and detection in OT
- Defence in depth, workshop and review
Certification & accreditation
BII Certificate of Completion
BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.