T06. Workshop on Industrial Cybersecurity Incident Management
Objetive:
To train professionals in the management of cybersecurity incidents in industrial automation and digitalization scenarios, minimizing the impact.
Content of the Industrial Cybersecurity Incident Management Workshop
Proper management of a high-impact cyberattack or incident is essential to maximize resilience and minimize the impact on any targeted industrial facility.
Before taking reactive actions to address the incident, it is necessary to plan, establish procedures, set controls, and conduct a series of exercises focused on managing the situation. For this, it is crucial to know the procedures to define, as well as the tools and solutions that should take prominence in each case.
With this exclusive CCI training, T06 – Incident Management, students will gain insight into the wide range of high-impact attacks that an industrial automation and digitalization infrastructure can face.
From there, they will learn how to resolve these incidents with the least possible impact by executing precise and appropriate actions, communications, and management in each case. Additionally, participants can leverage the CCI’s ESCIM platform: High-Impact Cybersecurity Incident Scenarios Platform.
During the training, a practical exercise will be conducted, supported by the expert instructor’s experience and exclusive materials developed by CCI (such as the Guide for Building an Industrial Cybersecurity Operations and Response Center).
What you will learn in this training
7 hours of practical training in which you will learn to identify and manage high impact cybersecurity incidents in an industrial automation environment.
Workshop programme:
- Understand attack vectors and the types of incidents that an industrial organization can experience.
- Familiarize yourself with the phases of incident management and the particularities of the organizations involved in an industrial environment.
- Share important aspects that should be considered in incident management of an automation and control environment with other professionals from various profiles and experiences in the industry.
- Learn the main controls that can be employed for the prevention, detection, and response to cybersecurity incidents in an OT environment.
Throughout the training, various practical use cases will be presented to identify risks in your industrial automation/digitalization installation. At this point, involved students will have the opportunity to participate in the identification and resolution process. They will directly engage in cyber exercises to address high-impact incidents, following their life cycle stages.
Simultaneously, and also in a practical manner, the necessary technical capabilities in an industrial SOC will be analyzed, and students will learn how to report incidents according to regulatory requirements, using the NIS directive as a case study.
Who is it for?
This highly practical 7-hour workshop is aimed at professionals, especially those involved in incident response teams from the following participants:
- Industrial organizations
- Operation and maintenance
- Emergency response
- IT/OT engineering and integrators
- Cybersecurity professionals
- IT and OT manufacturers
*Recommended and focused on professionals with prior knowledge in industrial cybersecurity.
Equipo docente del taller
Organisations that have entrusted the training of their professionals to the ICC College
ONLY 15 PLACES AVAILABLE
Exclusive training!
Frequently asked questions
Do I need prior knowledge of cybersecurity?
We consider it essential that students have an initial knowledge of industrial environments, including aspects of automation and industrial communications, ideal for this Diagnostic Workshop.
To facilitate this foundation, prior to the start of the course, the JRC will provide access to a virtual and dynamic educational resource. This material aims to provide students with a solid understanding of these fundamental concepts.
Our ongoing goal is to ensure maximum success for our students and participants.
Why participate in cyber exercises for industrial cybersecurity incident management?
Acquiring knowledge based on experience is one of the best ‘tools’ a professional can have.
Through this workshop and the CCI Guide, developed by an experienced professional, students will be able to identify the best practices in incident management and share their experiences with other professionals.
The occurrence of cyber incidents is a reality. The biggest difference in the consequences they can cause in an organization lies in our level of preparation for them. The way to handle a cyber incident differs greatly between the IT and OT worlds.
Our main objectives: being prepared, minimizing impact, and quickly recovering our systems—being cyber resilient—will be achieved to a greater extent with knowledge and practice. This workshop will meet all your expectations and fully prepare you to face any situation in an industrial environment.
What is the complete program like?
- Identify the cyber risks that an industrial facility may be exposed to.
- Incident response lifecycle (Preparation, Detection, Containment, Recovery, and Post-Incident)
- Table-top exercise with various scenarios, presenting high-impact incidents that need to be addressed both technically and organizationally.
- Exercise to analyze the necessary technical capabilities and their correspondence in an industrial environment, both at the plant level and in the SOC.
- Regulatory requirements (NIS directive case) and adaptation from incident management to proper notification preparation.
- Analysis of organizational needs to comply with regulations (NIS directive case).
When will the sessions be held?
The training will take place in 2 sessions from 15:00h to 18:30h (Spain time – CET).
What support material will I receive?
Each student will receive:
One copy for individual use of the following documents:
Best Practices for Cybersecurity Diagnostics in Industrial Environments (Market value 250€).
Guide + Tool – Cybersecurity Requirements for Service Providers.
Presentations used in the course training
Case studyCan my company subsidise this training?
Yes, you will be able to subsidise the number of hours included in this training using your training credit through FUNDAE (State Training for Employment Training).
The Centro de Ciberseguridad Industrial is not in charge of the management and processing of your bonus, but we will provide you with all the information and documentation you need so that you can do it.
Are the classes live or are they video recorded?
The training modality is SYNCHRON ONLINE (with free access from any location, you only need a stable internet connection).
The sessions will be live via the videoconference system provided by the JRC. These sessions will be recorded and will be available for subsequent viewing by the student for a limited time.
How long will the material be available to me after the end of the training?
The training material as well as the recording of the sessions and everything shown during the training will be available to the student for a period of 1 calendar month. During this time, the student will be able to enjoy the training with total freedom and availability with remote access.
Which document proves my participation?
At the end of the training and having fulfilled the necessary requirements, you will receive an accreditation certificate from the school certifying your attendance, participation and compliance with the training requirements. The CCI School is an internationally recognised organisation whose training, experience, teaching staff and professional team accredit it.
Along with the accreditation certificate, you will receive the White Professional Credential (which is obtained through the student’s knowledge acquired during the training) of our CCI Industrial Cybersecurity Commitment Recognition Programme.
What are the payment methods?
Payment must be made by credit/debit card. If you can only pay by bank transfer, please contact us for support in this process at escuela@cci-es.org.
Can my company subsidise this training?
Yes, you will be able to subsidise the number of hours included in this training using your training credit through FUNDAE (State Training for Employment Training).
The Centro de Ciberseguridad Industrial is not in charge of the management and processing of your bonus, but we will provide you with all the information and documentation you need so that you can do it.
Prices and enrolment conditions
This workshop has personalised prices for members of the CCI ecosystem. Conditions that allow exclusive benefits and price reductions in the School’s training courses.
- Non-CCI Member: €400
- Basic Member: €360
- Professional Member: €340
- Enterprise Member: €340
- Platform Member: €320
- Subscription Member: €300
Prices do not include VAT or taxes.
FUNDAE subsidised by FUNDAE
Only 15 students per edition