ICS Security for Leaders
This operational technology (OT) cyber security course is for the person who signs off the budget, not the person configuring the firewall. Four weeks, built around decisions: what to fund, what to accept, who owns what, and what happens at three in the morning when a plant goes down.
You leave with a programme outline, a risk framing your board will follow, and a way of talking to operations that does not end the conversation.
- Duration
- 4 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Frame OT risk in terms of safety, production and environmental consequence rather than data loss
- Decide where OT security sits in your organization and who owns each control
- Choose between IEC 62443, NIST 800-82 and the CIS Controls, and justify the choice
- Build a budget case that survives a finance review
- Write an incident plan that states in advance what may be isolated and who decides
- Run a tabletop with plant operations that produces actions rather than blame
- Set security requirements for vendors and integrators in contract language
- Report programme progress with metrics an executive team will act on
Course outline
6 modules
- Consequence first: safety, environment, production, reputation
- Why confidentiality ranks last here and what that changes
- Risk registers that operations will recognize
- Putting a number on downtime and process upset
- Presenting risk to a board without theatre
What you need before you start
- Management or technical leadership responsibility for an industrial site or programme
- No engineering or control systems background required
- Roughly two hours of live class plus light preparation each week
Who this course is for
- Plant managers and operations leaders taking on security accountability
- IT and security managers whose scope has expanded into OT
- Engineering leads asked to stand up an industrial security programme
- Risk, audit and compliance staff at utilities and resource companies
- Executives sponsoring OT security spend who need to ask better questions
Where this leads
Prepares you for
CISM
Awarded by ISACA
The management framing here overlaps with ISACA CISM, particularly governance and incident management, though this is not exam preparation. ISACA examines and awards CISM; the academy plays no part in issuing it, and the credential carries its own experience requirement.
Questions about this course
More in industrial control systems and ot security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



