Let’s make it work for you
Overview
This four-day instructor-led course enables professionals to develop the expertise required to plan, design, and implement an effective security programme to protect SCADA and industrial control systems. As critical infrastructure and operational technology environments become increasingly connected, the risks to supervisory control and data acquisition systems continue to grow. A structured and holistic approach to SCADA security is essential.
Participants will gain a deep understanding of common industrial control system threats, vulnerabilities, and risk management techniques. The course focuses on the knowledge and skills required to advise on and manage risks related to SCADA environments, combining technical, operational, and management controls. A comprehensive methodology for implementing a SCADA security programme is presented, equipping learners to lead security initiatives within high-profile and high-impact environments. On completion, participants will be prepared to sit the PECB Certified Lead SCADA Security Manager examination.
Prerequisites
Participants should have:
- A fundamental understanding of SCADA security concepts
- Basic knowledge of industrial control systems and networking
- Familiarity with information security principles is recommended
Target audience
This course is designed for:
- Security professionals seeking to acquire SCADA security management skills
- IT professionals looking to enhance their technical knowledge in operational technology environments
- IT and risk managers seeking a deeper understanding of industrial control systems and SCADA systems
- SCADA system developers
- SCADA engineers and operators
- SCADA IT professionals
Learning Objectives
By the end of this course, learners will be able to:
- Explain the purpose, architecture, and risks associated with SCADA systems, distributed control systems, and programmable logic controllers
- Identify threats and vulnerabilities affecting industrial control system environments
- Develop and support a proactive SCADA security programme, including policy development and vulnerability management
- Design network architectures incorporating defence-in-depth security controls for SCADA environments
- Describe the relationship between management, operational, and technical controls within a SCADA security programme
- Design resilient and high-availability SCADA systems
- Plan and manage a programme of effective security testing activities
Course Outline
Fundamental principles and concepts of SCADA and SCADA security
- Overview of SCADA systems and industrial control systems
- Components of distributed control systems and programmable logic controllers
- Operational technology versus information technology environments
- Key security principles applicable to SCADA systems
- Regulatory and compliance considerations in critical infrastructure
- Security challenges unique to SCADA environments
Industrial control systems characteristics, threats, and vulnerabilities
- Architecture and communication protocols in ICS environments
- Common threat actors and attack vectors targeting SCADA systems
- Vulnerability types within operational technology networks
- Risk scenarios affecting critical infrastructure
- Consequences of cyber incidents in industrial environments
- Case studies of SCADA and ICS security breaches
Designing and developing an ICS security programme based on recognised guidance
- Overview of NIST SP 800-82 guidance for ICS security
- Establishing governance and security policies for SCADA
- Risk assessment methodologies for operational technology
- Asset identification and classification
- Security awareness and training in ICS environments
- Integration of security into system lifecycle management
Network security architecture for SCADA systems
- Segmentation and zoning strategies
- Defence-in-depth architecture principles
- Secure remote access and communication controls
- Firewalls, intrusion detection, and monitoring in ICS networks
- Secure configuration and hardening of SCADA components
- Managing third-party and vendor access
Implementation of security controls for SCADA systems
- Technical security controls for industrial networks
- Access control and identity management in SCADA environments
- Patch and vulnerability management strategies
- Incident response planning for ICS
- Backup, recovery, and business continuity considerations
- Integration of physical and cyber security controls
Developing resilient and robust systems
- High availability design principles
- Redundancy and fault tolerance in SCADA systems
- Secure system design and secure coding practices
- Monitoring and logging strategies
- Evaluating system performance and resilience
- Continuous improvement of SCADA security posture
Security testing of SCADA systems
- Security testing methodologies for industrial environments
- Vulnerability assessments and penetration testing considerations
- Testing limitations in operational technology systems
- Managing testing activities without disrupting operations
- Reporting and remediation planning
- Aligning testing results with risk management processes
Exams and assessments
Participants will sit the PECB Certified Lead SCADA Security Manager examination, which meets the requirements of the PECB Examination and Certification Programme.
- Certification and examination fees are included in the course price
- Participants receive over 450 pages of training material, including practical examples
- An attestation of course completion worth 31 continuing professional development credits is issued to attendees
- In case of exam failure, one retake is available within 12 months at no additional cost
Hands-on learning
This instructor-led course includes:
- Scenario-based exercises focused on risk identification and mitigation
- Group workshops to design secure SCADA network architectures
- Case study analysis of real-world industrial incidents
- Exam-style practice questions to reinforce knowledge
Frequently asked questions
How can I create an account on myQA.com?
There are a number of ways to create an account. If you are a self-funder, simply select the "Create account" option on the login page.
If you have been booked onto a course by your company, you will receive a confirmation email. From this email, select "Sign into myQA" and you will be taken to the "Create account" page. Complete all of the details and select "Create account".
If you have the booking number you can also go here and select the "I have a booking number" option. Enter the booking reference and your surname. If the details match, you will be taken to the "Create account" page from where you can enter your details and confirm your account.
Find more answers to frequently asked questions in our FAQs: Bookings & Cancellations page.
How do QA’s virtual classroom courses work?
Our virtual classroom courses allow you to access award-winning classroom training, without leaving your home or office. Our learning professionals are specially trained on how to interact with remote attendees and our remote labs ensure all participants can take part in hands-on exercises wherever they are.
We use the WebEx video conferencing platform by Cisco. Before you book, check that you meet the WebEx system requirements and run a test meeting to ensure the software is compatible with your firewall settings. If it doesn’t work, try adjusting your settings or contact your IT department about permitting the website.
How do QA’s online courses work?
QA online courses, also commonly known as distance learning courses or elearning courses, take the form of interactive software designed for individual learning, but you will also have access to full support from our subject-matter experts for the duration of your course. When you book a QA online learning course you will receive immediate access to it through our e-learning platform and you can start to learn straight away, from any compatible device. Access to the online learning platform is valid for one year from the booking date.
All courses are built around case studies and presented in an engaging format, which includes storytelling elements, video, audio and humour. Every case study is supported by sample documents and a collection of Knowledge Nuggets that provide more in-depth detail on the wider processes.
When will I receive my joining instructions?
Joining instructions for QA courses are sent two weeks prior to the course start date, or immediately if the booking is confirmed within this timeframe. For course bookings made via QA but delivered by a third-party supplier, joining instructions are sent to attendees prior to the training course, but timescales vary depending on each supplier’s terms. Read more FAQs.
When will I receive my certificate?
Certificates of Achievement are issued at the end the course, either as a hard copy or via email. Read more here.