Service 03
Training and awareness
OT cybersecurity training for plant and engineering teams, with sector-specific cases, not generic slides.
- Problem
- Generic cybersecurity awareness training — designed for office environments — doesn't translate to a plant operator or a control engineer what an incident means when the "endpoint" is a PLC controlling a valve. The usual outcome is paper compliance (the course was taken) without any real change in behavior.
- Scope
- Role-differentiated training — plant operations, control engineering, middle management — with real industrial-sector cases and IEC 62443-2-1 vocabulary (roles and responsibilities of the security program, awareness as an organizational control), without carrying over unadapted office cybersecurity content. In-person or remote format depending on the plant.
- Deliverables
- Training session adapted to each audience's role (operations, engineering, management)
- Post-training reference material in the plant's working language
- Industrial-sector case studies, not generic office phishing examples
- Fit
- Complements the audit and the architecture/segmentation service: neither holds up its results if the team operating the plant doesn't understand why those controls exist. It's most valuable after an architecture change or an audit, so the team understands the why behind the new controls, not just the what.
Why the generic awareness course doesn’t work
Most cybersecurity awareness programs are designed for IT risk: email, credentials, browsing. A plant operator doesn’t face that risk at their workstation — they face decisions like plugging a maintenance laptop into the control network, or installing an update a vendor sends over USB. Training them with the same content as an office employee doesn’t translate.
IEC 62443-2-1 treats awareness and training as an organizational control of the security program, not a compliance formality: it requires personnel to understand their role within the program, not just sign off on having attended.
How it’s structured
- Plant operations: what to do and not do when the control system behaves anomalously, without requiring technical cybersecurity knowledge.
- Control engineering: why the zones and conduits limiting their access exist, and how to avoid introducing an undocumented route when solving an urgent problem.
- Middle management: what questions to ask when a network change is proposed or a third-party vendor with remote access is contracted.
What this service produces
Training sessions with real sector cases — not generic cybersecurity slides reused from an office context — and reference material the team can consult afterward, in the language the plant works in.