Cybersecurity for industrial control systems

Next sessions:

December 10-12, 2025 Paris

Overview

Industrial systems must meet the challenge of increasing global competitiveness. Their digitalization—essential for process automation and efficiency—brings greater technical complexity and increases exposure to cyber threats.
This training offers a comprehensive analysis of the threat landscape facing industrial systems, illustrated through real-life cases and hands-on security solution implementation. It covers cybersecurity standards, industrial architectures, and practical deployment of protection measures.

Objectives

  • Raise awareness among industrial stakeholders about threats specific to production environments
  • Demonstrate risks through Ethical Hacking exercises on cyber-physical systems
  • Analyze threats and design an adapted cybersecurity policy for industrial settings
  • Configure and deploy protection tools: firewalls, access controls, intrusion detection sensors, etc.
  • Implement a security and operational continuity strategy (MCS/MCO) using CTI (Cyber Threat Intelligence) and OSINT (Open Source Intelligence) tools

Program

1. Introduction to Industrial Systems

  • Overview of Industrial Control Systems (ICS)
  • Technologies: PLCs, sensors, actuators
  • Industrial protocols: Modbus, DNP3, OPC UA, TSN
  • Architectures and applications: SCADA, EMS, Historian, CIM

2. Setting Up an Industrial Infrastructure

  • Deployment of an environment including switches, PLCs, HMIs, and supervision software

3. Threat Analysis and Demonstrations

  • Landscape of attacks targeting industrial environments
  • Case studies and simulations in a testbed
  • Hands-on exercises: audit, reconnaissance, vulnerability identification

4. Attack Techniques on Industrial Systems

  • Replay attacks, Man-in-the-Middle, DoS, network scanning, etc.
  • Simulations on a cyber-range and cyber-physical environment

5. Implementing Protection Measures

  • Security standards and norms for industrial systems
  • Defense-in-depth: network segmentation, system hardening
  • Deployment of industrial firewalls, IDS/IPS, access control solutions

6. Security and Operational Continuity Policy

  • MCS/MCO strategy implementation
  • Patch and update management
  • CTI for industrial environments
  • OSINT for proactive threat detection

7. Advanced Hands-on Labs

  • Configuring security tools: firewalls, IDS/IPS, access control
  • Deploying a CTI infrastructure in an industrial use case

8. Summary and Wrap-Up

  • Experience sharing
  • Recommendations for real-world deployment
  • Discussion on future trends in industrial cybersecurity

Teaching methods

This course combines theoretical knowledge and hands-on practice. It uses advanced equipment, including cyber-physical platforms and CyberRange environments, to simulate real-world industrial conditions.
Real-life use cases from collaborative R&D projects enrich the training experience. Participants will alternate between lectures, demonstrations, attack simulations, and tool configuration.

Target Audience & Prerequisites

Who should attend:

  • Engineers, technicians, or managers in cybersecurity, production, or automation
  • CIOs, CISOs, and system architects working in industrial environments
  • Public or private sector professionals involved in securing control systems

Prerequisites:

  • Basic knowledge of networks, industrial systems, or automation
  • Familiarity with cybersecurity concepts is a plus, but not mandatory

Key strengths of the training

  • Comprehensive overview of vulnerabilities, risks, and mitigation strategies
  • Use of state-of-the-art equipment and cyber-physical environments for practical sessions
  • A perfect balance of theory, practice, and real-world application

Contact

academy@irt-systemx.fr