×
 
 Back to all courses

1-1 ESSENTIALS FOR OT CYBERSECURITY

 

03 Oct 2026, Saturday - 30 Apr 2027, FridaySee Schedule below for times (GMT +8:00) Kuala Lumpur, Singapore

 

Singapore University of Technology and Design (SUTD) - 8 Somapah Rd, Singapore 487372, 487372

0%

Overview

This Course is Skillsfuture funded (Up to 90%)

In today’s interconnected world, Operational Technology (OT) systems are critical to industries like manufacturing, energy, utilities, and transportation. However, the growing threat landscape demands that OT professionals not only understand how their systems function but also how to safeguard them from ever-evolving cyber threats.

 

ICS CYBERSECURITY FOUNDATION TRAINING COURSE has been specifically developed to empower industrial personnel with the most essential IT and OT security principles. Completing this series allows the trainee to be cyber aware in their daily job, knowing their risk on the job.

 

This comprehensive ESSENTIALS FOR OT CYBERSECURITY COURSE is designed to equip you with the essential knowledge and skills needed to secure your organization's critical infrastructure. Tailored for OT professionals, the course covers all the essential topics required to design an effective Cybersecurity Program to defend against cyberattacks against OT environments.

 

You’ll gain insights into understanding threat vectors, OT security architecture,  cybersecurity risk mitigation measures, and timely and effective incident response in the event of an actual cyber attack against your environment. These insights are critical in mitigating business risks and ensuring continuity of critical services even during a cyber attack. Whether you’re an OT engineer, technician, or security specialist, this course will empower you to take proactive measures and build a resilient cybersecurity posture for your OT systems.​

WHY CHOOSE THIS COURSE?

  • Practical & Relevant: Designed specifically for OT professionals, offering real-world applications.

  • Hands-on Training: Learn through case studies, practical exercises and reference to industry best practices.

  • Expert-Led: Taught by industry professionals with years of experience in OT cybersecurity.

 

Enhance your expertise, reduce risks, and ensure your OT infrastructure is resilient against the latest cybersecurity threats.​

Enroll today and become the cybersecurity champion your OT systems need

COURSE DURATION:

  • 3 days of Instructor-led training

Course Description & Learning Outcomes

EXPECTATION AFTER THE TRAINING:

  • Participants will be equipped to develop a structured organisational and technical roadmap for enhancing their organisation's current operational posture.

  • Participants will gain the skills to implement industry best practices in OT cybersecurity within their plant operations.

  • Participants will be able to conduct fundamental risk-based analyses using the Vulnerability and Threats Framework, applying their knowledge of risk mitigation strategies.

  • Participants will learn to design and integrate a basic Incident Response strategy tailored to their OT environment.

WHAT WILL BE COVERED IN THE COURSE:

The ISA and the International Electrotechnical Commission (IEC) have collaborated to establish a set of standards known as the ISA/IEC 62443 series. This comprehensive course delves into the fundamental principles of these standards. These standards play a crucial role in the automation of industrial production processes, widely utilized in sectors such as power, water, oil, and natural gas. The ISA/IEC 62443 standards offer guidelines for optimal practices in industrial network security, with new technical specifications being evaluated every three years for potential adoption as new standards. The core concepts will be introduced across various categories, including general, policies and procedures, system requirements, and component requirements. ​

The following will be covered in the course:

  • A high-level overview of the convergence between IT and OT architectures.

  • Understanding the Purdue Model and its impact on cybersecurity perspectives.

  • Introduction to IEC 62443 and its practical applications in real-world scenarios.

  • Fundamental cybersecurity principles in the OT domain and key threat vectors.

  • Leveraging IEC 62443 Cybersecurity Management System (CSMS) to enhance organizational security.

  • A comprehensive guide to structuring organizational personnel for cyber readiness.

  • A training program on reviewing and refining essential organizational policies and procedures, including Business Continuity Planning (BCP), Data Protection, and Cybersecurity.

  • A detailed architectural review of the OT environment.

  • A practical approach to developing an effective Incident Response (IR) process.

  • Introduction to the MITRE security framework.

  • Analysis of common OT cyberattacks and their operational mechanisms.

 

In this training program, we will explore IEC 62443 - 1-1 - Terminology, concepts, and models, which covers the foundations required to implement a security program within the organisation.

Furthermore, we will delve into IEC 62443 - 2-1 - Establishing an industrial automation and control system security program exploring practical measures that asset owners can adopt to implement a robust security program.

 

Additionally, the training will cover foundational technical knowledge in OT cybersecurity, encompassing basic ICS Architecture within the environment and the setup of an OT plant. We will analyze a hypothetical scenario that illustrates how a particular setup could expose vulnerabilities and potential attacks on the organisation. Practical discussions within the group will address fundamental responses required during a cyber incident, which should be in place across all organisations.

 

These responses include:

• Business Continuity Plan

• Backup and Restoration Procedures

• Crisis Communication Plan

• Incident Response Plan

• Security Policies

 

This course is designed to provide a highly practical learning experience for OT security practitioners by integrating theoretical foundations with hands-on activities. Participants will not only engage in lectures but will also take part in interactive discussions, case studies, and real-world simulations. The course emphasises practical problem-solving, where participants will analyse cybersecurity incidents, assess risks using structured frameworks, and develop actionable strategies to enhance their OT security posture. Through collaborative exercises and guided workshops, attendees will gain the skills necessary to apply industry best practices in securing and strengthening their OT environments effectively.

Learning Objective

 

By the end of the course, participants will be able to:

  • Develop a structured organisational and technical roadmap to strengthen the cybersecurity posture of their Operational Technology (OT) environment.

  • Apply industry best practices in OT cybersecurity to improve the security of plant operations and industrial control systems.

  • Conduct basic risk-based assessments using vulnerability and threat frameworks, and identify appropriate risk mitigation strategies.

  • Design a basic incident response approach tailored to their OT environment to support effective response and recovery during cyber incidents.

Supporting Image

Schedule

Start Date: 03 Oct 2026, Saturday
End Date: 30 Apr 2027, Friday

Class dates are planned based on demand.

Location: Singapore University of Technology and Design (SUTD) - 8 Somapah Rd, Singapore 487372, 487372

Agenda

Day/TimeAgenda Activity/Description
Day 1Concepts and Terminology in Operational Technology (OT) Operational Technology (OT) Cybersecurity Fundamentals Details of OT Components – Purdue Enterprise Reference Architecture (PERA) / Purdue Model Introduction to IEC 62443 Industrial Cybersecurity Standard
Day 2Introduction to Cybersecurity Management System (CSMS) CSMS – People CSMS – Process CSMS – Technology
Day 3Introduction to Cyber Attack Frameworks Incident Response for OT Environments Tabletop Exercise for Incident Response Practice Best Practices for Supervisory Control and Data Acquisition (SCADA) Security Assessment

Pricing

Course fees: $3,815 (Before Funding), $1,144.50 (Singaporean/PR), $444.50 (Singaporean > 40 years old) inclusive of 9% GST.

Course Pricing

Skills Covered

PROFICIENCY LEVEL GUIDE
Beginner: Introduce the subject matter without the need to have any prerequisites.
Proficient: Requires learners to have prior knowledge of the subject.
Expert: Involves advanced and more complex understanding of the subject.

  • Cybersecurity (Proficiency level: Proficient)

Speakers

Trainer's Profile:

Matthias Yeo, CEO, CyberXCenter Pte Ltd
Matthias Yeo

Matthias is the Co-founder and Chief Executive Officer of CyberXCenter, a Cyber security firm in Singapore. The company specializes in building cybersecurity capabilities for Industrial Control Systems (ICS) by offering services such as training, cyber exercises, and research. He conducts research on vulnerabilities in critical infrastructure, including Operational Technology (OT) and 5G networks, to enhance national security. Matthias is actively involved in national level cyber exercise such as CISS (Critical Infrastructure Security Showdown) and CiDex (Critical Infrastructure Defence Exercise) organized by DoD (Department of Defense). He ran Tabletop Exercise (TTX) and programme planning for United Nation. CyberXCenter has received multiple accolades, including the 2024 Cyber Security Excellence Award

Trainer's Profile:

Jonathan Choo, Researcher, CyberXCenter Pte Ltd
Jonathan Choo

Jonathan Peter Choo is a cybersecurity researcher specializing in Operational Technology (OT) security and 5G infrastructure. He has 1.5 years of hands-on experience deploying and managing on-premise Kubernetes clusters on Proxmox, analyzing 5G traffic with Wireshark, and developing training materials on call flows and PDU session establishment. He has also studied Modbus traffic and built personal labs simulating enterprise and OT environments. Jonathan holds a Specialist Diploma in OT Cybersecurity (Network and System Defence, 2026), ISC² Certified in Cybersecurity, CompTIA Security+, and Security Blue Team Level 1, equipping him to teach practical OT cybersecurity concepts effectively.

Technology:
Industries: