ICS Visibility, Detection and Response
Critical infrastructure security depends on knowing what is on the wire. This course builds operational technology (OT) visibility with passive methods, then turns it into detection and response you can run during production, taught live from Toronto on Eastern Time.
Isolating a compromised host is often not an option. Playbooks here assume the process keeps running and that operations, not security, holds the final call.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- ICS and SCADA Security Essentials
- Class size
- Capped at 12 learners

What you will be able to do
- Deploy passive collection and produce an OT asset inventory without active scanning
- Baseline normal process traffic and explain what a deviation means for the plant
- Write detection rules for unauthorized writes, logic downloads and controller mode changes
- Place sensors across Purdue levels and state honestly which gaps remain
- Map observed activity to MITRE ATT&CK for ICS techniques
- Triage an OT alert by process consequence and decide whether it is an incident
- Contain an intrusion in ways that stop the attacker without stopping production
- Collect evidence from an engineering workstation and a controller without interrupting operations
Course outline
6 modules
- Passive collection: span ports, taps and where to place them
- Deriving an asset inventory from protocol traffic
- Configuration and project file review for device detail
- Serial links and legacy segments
- Keeping the inventory current as engineering changes things
What you need before you start
- ICS and SCADA Security Essentials, or equivalent industrial security experience
- Comfort reading packet captures and writing simple detection logic
- A laptop able to run a packet analyser and a small virtual machine
- Around five hours a week outside class for detection and playbook exercises
Who this course is for
- OT security analysts building or running a monitoring capability
- SOC analysts whose scope now includes plant networks
- Incident responders who need playbooks written for industrial constraints
- Detection engineers writing rules for industrial protocols
- Control engineers partnering with a security team on monitoring
Where this leads
Prepares you for
CySA+
Awarded by CompTIA
Detection and response practice in this course sits close to what CompTIA assesses in CySA+, with the OT specifics layered on top. The certificate itself comes from CompTIA following their exam; the academy neither administers nor issues it.
Questions about this course
More in industrial control systems and ot security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



