Skip to main content
The Cyber Security: ethical hacking and cyber security training, Canada
Core

ICS Visibility, Detection and Response

Critical infrastructure security depends on knowing what is on the wire. This course builds operational technology (OT) visibility with passive methods, then turns it into detection and response you can run during production, taught live from Toronto on Eastern Time.

Isolating a compromised host is often not an option. Playbooks here assume the process keeps running and that operations, not security, holds the final call.

Duration
8 weeks
Format
Live online, instructor-led
Prerequisites
ICS and SCADA Security Essentials
Class size
Capped at 12 learners
ICS Visibility, Detection and Response

What you will be able to do

  • Deploy passive collection and produce an OT asset inventory without active scanning
  • Baseline normal process traffic and explain what a deviation means for the plant
  • Write detection rules for unauthorized writes, logic downloads and controller mode changes
  • Place sensors across Purdue levels and state honestly which gaps remain
  • Map observed activity to MITRE ATT&CK for ICS techniques
  • Triage an OT alert by process consequence and decide whether it is an incident
  • Contain an intrusion in ways that stop the attacker without stopping production
  • Collect evidence from an engineering workstation and a controller without interrupting operations

Course outline

6 modules

  • Passive collection: span ports, taps and where to place them
  • Deriving an asset inventory from protocol traffic
  • Configuration and project file review for device detail
  • Serial links and legacy segments
  • Keeping the inventory current as engineering changes things

What you need before you start

  • ICS and SCADA Security Essentials, or equivalent industrial security experience
  • Comfort reading packet captures and writing simple detection logic
  • A laptop able to run a packet analyser and a small virtual machine
  • Around five hours a week outside class for detection and playbook exercises

Who this course is for

  • OT security analysts building or running a monitoring capability
  • SOC analysts whose scope now includes plant networks
  • Incident responders who need playbooks written for industrial constraints
  • Detection engineers writing rules for industrial protocols
  • Control engineers partnering with a security team on monitoring

Where this leads

Prepares you for

CySA+

Awarded by CompTIA

Detection and response practice in this course sits close to what CompTIA assesses in CySA+, with the OT specifics layered on top. The certificate itself comes from CompTIA following their exam; the academy neither administers nor issues it.

Questions about this course

Ready to launch your cyber security career?

Join the next live online cohort. No experience required, just bring the curiosity.