Critical Infrastructure and OT Security Training

Yellow circular logo with intertwined abstract shapes next to "Business Continuity Management (BCM).
EASMLens external attack surface management platform logo
NSPM network security policy management logo
PhishLens phishing simulation and awareness logo

Our OT security training and critical infrastructure courses help engineers, operators and risk teams protect industrial control systems and meet obligations such as the SOCI Act Critical Infrastructure Risk Management Program (CIRMP), the AESCSF and ISA/IEC 62443. SSC delivers practical courses for energy, water, transport, manufacturing and other critical sectors, live online or on-site.

Engineers in a training lab with industrial control panels and a conveyor rig while an instructor explains network segmentation, representing OT security training
OT security training works best close to the equipment engineers know.

Courses at a glance

CourseTypical durationBest for
OT security fundamentals for engineers2 daysControl, automation and electrical engineers, and operators
ISA/IEC 62443 fundamentals3 daysAsset owners, system integrators and product suppliers
SOCI Act and CIRMP practitioner1 dayRisk, compliance and security teams of responsible entities
AESCSF assessment practitioner2 daysEnergy sector teams completing AESCSF assessments
OT incident response tabletop exercise1 dayOperations, engineering, IT security and leadership together
Board briefing on critical infrastructure risk2 hoursDirectors approving the annual CIRMP report

Course details

OT security fundamentals for engineers

Typical duration: 2 days. Who it is for: engineers and operators who are new to cyber security.

  • How IT and OT differ: safety, availability, legacy systems and change windows
  • Common attack paths into control systems: remote access, removable media, vendors and flat networks
  • Asset inventory, secure remote access, segmentation and backups for control systems
  • Recognising and reporting suspicious activity safely

You will be able to: apply practical security measures without putting safety or availability at risk.

ISA/IEC 62443 fundamentals

Typical duration: 3 days. Who it is for: asset owners, integrators and suppliers.

  • The structure of the ISA/IEC 62443 series and the roles it addresses
  • The security programme for asset owners in 62443-2-1
  • Zones and conduits, risk assessment and target security levels SL1 to SL4
  • The seven foundational requirements, FR1 to FR7
  • Product and component requirements, and certification schemes such as ISASecure

You will be able to: use IEC 62443 to design, specify and assess secure industrial systems.

Electricity substation at dusk with a technician holding a tablet, representing critical infrastructure security training
Critical infrastructure obligations reach from the boardroom to the substation.

SOCI Act and CIRMP practitioner

Typical duration: 1 day. Who it is for: responsible entities for critical infrastructure assets in Australia.

  • Who the Security of Critical Infrastructure Act 2018 applies to, and its positive security obligations
  • The four CIRMP hazard domains: cyber and information security, personnel, supply chain, and physical security and natural hazards
  • Meeting the cyber requirement through a recognised framework such as the AESCSF, Essential Eight, ISO/IEC 27001 or the NIST Cybersecurity Framework
  • Preparing the board-approved annual CIRMP report
  • Incident reporting duties for critical infrastructure assets

You will be able to: maintain a CIRMP that satisfies the rules and stands up to regulator scrutiny.

AESCSF assessment practitioner

Typical duration: 2 days. Who it is for: energy sector participants completing AESCSF assessments.

  • The AESCSF domains, maturity indicator levels and security profiles
  • Determining criticality and target security profile
  • Collecting evidence and avoiding common anti-patterns
  • Turning results into a prioritised uplift roadmap

You will be able to: complete a credible AESCSF assessment and plan the uplift that follows.

Exercising for the worst day

Operators in a utility control room with an instructor behind them during a drill, representing critical infrastructure incident response exercises
A tabletop exercise is the safest place to discover what the plan missed.

Our OT incident response tabletop brings operations, engineering, IT security and leadership into one room to work through a realistic scenario, such as ransomware spreading from the corporate network towards control systems. The exercise tests decisions about isolation, manual operation, safety, regulator notification and communication, and ends with an action plan.

Courses can also cover regional OT requirements, such as Saudi Arabia’s Operational Technology Cybersecurity Controls and Singapore’s Cybersecurity Code of Practice for critical information infrastructure, for organisations operating in those markets.

How the OT and critical infrastructure training is delivered

  • Live online. Instructor-led virtual classes over Microsoft Teams or Zoom, with breakout exercises, shared workbooks and the option to split longer courses into half-day sessions across a week or two.
  • On-site at your premises. Private training for your team at your office, delivered by a consultant who can use your own policies, systems and examples in the exercises.
  • Private and tailored. Every course can be run for a single organisation, with case studies drawn from your sector and the depth adjusted to your team’s experience.

On-site courses can include a walk-through of a real site or control room, agreed in advance with your operations team and always following your safety rules.

What participants receive

  • A course workbook and the slides used in class
  • Reusable templates and checklists, such as audit checklists, risk registers and report formats, depending on the course
  • A case study pack and practice questions
  • A certificate of completion from Security Solution Consultants

Certificates and accredited exams

Every participant who completes a course receives a certificate of completion from Security Solution Consultants. Lead Auditor and Lead Implementer courses can include an accredited certification exam through our accredited training partner, for standards where the partner offers one. Your quote confirms the exam body, exam format and certificate for each course, so there are no surprises on the day.

Why train with SSC

  • Taught by practitioners. Our trainers are working consultants and auditors who assess OT environments, AESCSF maturity and CIRMP programmes for energy and infrastructure clients, so examples come from real engagements rather than slides.
  • We hold ourselves to the same standard. SSC is certified to ISO/IEC 27001 and follows a Secure by Design approach. See our Trust Centre.
  • Hands-on with real tools. Exercises can use GRCLens, the GRC platform built by SSC, so participants practise with risk registers, control libraries and evidence the way they will at work.
  • Training that connects to delivery. If your team needs help after the course, the same people can support implementation, internal audits and certification readiness.

Related: energy sector security assessment and advisory, and the GRCLens AESCSF and SOCI and IEC 62443 modules. See all training courses.

Frequently asked questions

Control and automation engineers, operators, OT and IT security staff, and the risk and compliance teams responsible for critical infrastructure obligations. Leadership should join the incident response exercise.

A series of international standards for securing industrial automation and control systems. It covers security programmes for asset owners, system design with zones, conduits and security levels, and requirements for products and components.

Yes. The CIRMP practitioner course covers the four hazard domains, the recognised cyber frameworks, the board-approved annual report and incident reporting duties.

No. Training uses lab equipment, simulations and documentation. Any site walk-through is agreed in advance with your operations team and follows your safety rules.

No. The AESCSF covers electricity, gas and liquid fuels, and a lite version exists for smaller participants. The course explains which applies to you.

Plan OT and critical infrastructure training for your team

Tell us how many people need training, which courses interest you, and whether you prefer live online or on-site delivery. We will come back with a tailored proposal and quote.

Prefer email? Write to info@secsolutionshub.com