
Brochure (PDF)=Method offers the Cyber Security Risk Management training course for those responsible for the security of industrial automation, control and safety systems – known as “operational technology” (OT) to differentiate it from “information technology” (IT). The course recognises that the optimum approach to security in OT may be quite different to what would be considered good practice in an IT environment.
The overall goal of the training is to provide individuals responsible for OT security on industrial sites with sufficient knowledge that they can understand their obligations for legal and regulatory compliance, develop procedures and policies to achieve such compliance and manage the site's approach to OT security.
The course content is designed to explain the requirements of the various international standards for security and is developed to specifically address the guidance developed by the UK Health and Safety Executive on industrial security.
Course Content
The course content is designed to explain the requirements of the various international standards for security and is developed to specifically address the guidance developed by the UK Health and Safety Executive on industrial security.
-
Context and Background
- Business, legal and regulatory context for OT security
- Vulnerabilities in OT systems
- Threats – understanding their nature and scale
- Relationship and conflicts between safety and security
- Relationship between IT and OT
-
Concepts and Guiding Principles for Cyber Security
- The PROTECT > DETECT > RESPOND cycle
- Security measures involving people, processes and technology
- Providing defence in depth
- A graded approach to security measures
- Zones and conduits
- Policy and documentation
- First steps in addressing OT cyber security threats
- Business context
- Initial risk assessment and quick security wins
-
Policy and governance of OT cyber security (management systems)
- Cyber security policy
- Defensive architectures
- Management systems and the cyber security lifecycle
- Methods for cyber security risk management
-
Data to manage cyber security risk
- Process dependencies
- Asset register
-
Cyber security risk assessment
- High level risk assessment
- System level risk assessment
- Implementing and verifying cyber security measures
- Implement and verify counter measures
- Validate, audit, monitor and report
- Prepare (and exercise) incident response measures
- Case study
- A case study and exercise to reinforce the learning points from Days 1 and 2.
Who should attend
Engineers and professionals who are responsible for the management of OT cyber security within their workplace and those who are in a supporting role, including consultants and contractors.
We would also encourage company OT and IT delegates to attend this course together.
Pre-qualification
There are no formal pre-requisites required to attend the training course - we assume no prior knowledge, but of course experience of cyber security and control and safety instrumentation in general is advantageous.
We would also encourage company OT and IT delegates to attend this course together.
After this training course you will be able to:
- Communicate the essential elements of OT cyber security to your colleagues, management and peers in industry
- Apply appropriate cyber security risk management.
- Understand and play a role in cyber security risk assessment analysis.
- Determine which assets require protection and identify suitable counter measures.
What you will get
All delegates receive:
- The course material in printed or electronic format.
- A Certificate of Attendance for each delegate that attends the full course (16 hourws of CPD).
Course Options
Classroom
The Course is delivered over 2-days.
In-House
The course can be delivered at a client's premises in a closed session where we can explore specific circumstances of that client.
About the Trainer

Steve Essery
The trainer for this course is Steve Essery. He is Technical Director at Method Cyber Security & Group Quality Assurance Manager at Method Safety and Security. He is TÜV SÜD Certified Functional Safety Professional Ph.D. – Clinical Immunology and Microbiology B.Sc. (Hons.) – Biological Sciences ISA/IEC 62443 Cybersecurity Expert. Steve Essery's trainer profile.
Price
Click on the specific course dates on this page for pricing information. A quotation can be provided on request.
Course Enquiries
If you have any further questions, please call +44 (0)1462 713313, email support@methodcysec.com or contact us online. If you wish to proceed, check your diary and reserve a place.
