Method Cyber Security
Group Home About us Contact us Terms & Policies
 +44 (0)1462 713313  support@methodcysec.com

Introduction to Cyber Security for Industrial Automation and Control Systems Training Course

The optimum approach to security in IACS / OT

The Solution =Method

8 CPD hours Brochure (PDF)A 1-day Introduction to Security Program requirements for Industrial Automation and Control Systems (IACS) asset owners, COMAH duty holders and those responsible for the security of industrial automation, control and safety systems – collectively known as “operational technology” (OT) to differentiate it from “information technology” (IT).

The course recognises that the optimum approach to security in IACS / OT may be quite different to what might be considered best practice in an IT environment and would encourage both OT professionals and IT professionals looking to gain knowledge of OT cyber security to attend.

OG86 to ISA / IEC 62443 Transition. As of April 2026 the UK Health and Safety Executive will be transitioning from OG86 to ISA / IEC 62443 as the basis of COMAH site inspections. Given that the ISA /IEC 62443 family of standards contains a far more comprehensive set of requirements than the out-going OG86 document. This revised course reflects this change.

Course Content

Part 1.

The presentation material will compare and contrast OT and IT functions, technologies, and security approaches, identify relevant regulatory frameworks, international standards, and guidance, outline key security concepts, describe the constituent parts of an organisational Security Program, how they are assembled and maintained, and finish with important external interfaces:

  • Introduction to OT / IACS
  • Regulatory frameworks, international standards, and security guidance
  • Threats, vulnerabilities and risk
  • Key security concepts
  • Assembling the parts, establishing, operating, maintaining, and maturing the Security Program
  • Important relationships including with business continuity, IT, and safety, personnel and physical security.
  • Addressing the challenges of supply chain security.

Part 2.

There will also be an opportunity for discussion with participants about the key evidence an HSE specialist inspector or cyber security auditor will want to see for OT cyber security, including exploring the following using a simplified case study:

  • Simple Network Diagram for OT, preferably using the Purdue / ISA-95 architecture model
  • Assessment of essential functions and adverse outcomes (including safety top events)
  • Configuration management databases and asset registers for OT systems (including specific fields about software configuration)
  • Policy document setting out governance and OT risk ownership
  • Threat and vulnerability management for OT
  • Risk assessment, corporate tolerable risk, and defining Security Levels
  • Maintenance of security countermeasures
  • Evidence of activities to deliver staff awareness, skills, competencies
  • Evidence of a continually improving Security Program.
  • Business continuity and incident response planning

Who should attend

Although primarily intended for engineers and professionals who are responsible for managing or supporting the OT cyber security of COMAH sites, the course will benefit managers and engineers from other manufacturing and utilities organisations where security plays a key role in business continuity and those who are in a supporting role, including system integrators, maintenance providers, consultants, and contractors.

We would also encourage company OT, IT, maintenance and procurement delegates to attend this course together.

Prereading

Although not essential we would recommend that prospective attendees are familiar with the following open-source resources:

After this training course you will be able to:

Describe in practical terms the activities, artefacts and relationships that make a Security Program, as expected by the UK HSE for COMAH sites and as described in IEC 62443.

What you will get

All delegates receive:

  • The course material in printed or electronic format.
  • A Certificate of Attendance for each delegate that attends the full course (8 hours of CPD).

Course Options

Classroom

Classroom Training

The Course is delivered over 1 day in public classroom sessions.

In-House

Live Online Training

The course is delivered at a client's premises as a closed course, and can be customised to suit your needs. Please contact us for more information.

Live Online

Live Online Training

The Course is delivered as 2 x 4 hours sessions (usually mornings).

About the Trainer

David Sparkes
Steve Essery

The trainer for this course is Steve Essery. He is Technical Director at Method Cyber Security & Group Quality Assurance Manager at Method Safety and Security. He is TÜV SÜD Certified Functional Safety Professional Ph.D. – Clinical Immunology and Microbiology B.Sc. (Hons.) – Biological Sciences ISA/IEC 62443 Cybersecurity Expert. Steve Essery's trainer profile.

Price

Click on the specific course dates on this page for pricing information. A quotation can be provided on request.

Course Enquiries

If you have any further questions, please call +44 (0)1462 713313, email support@methodcysec.com or contact us online. If you wish to proceed, check your diary and reserve a place.

Check your diary and reserve a place


Delegate comments

In course feedback our delegates rated this course 86.3%. See recent comments below, or more comments here.

Intro to Cyber course rating

Have improved my understanding and knowledge.

I have learned a lot today.

I have learned that HSE expectations will shift.

Good insights, covers information for various roles.

Good awareness - i now know where to look.

Read more comments.


Share this course page with a colleague using your preferred links below: