picto-module-4

Module 4

Operational cybersecurity for IT/OT professionals

Duration : 5 consecutive days  | For who? IT/OT professionals and technical managers

Number of participants: Minimum 6 (2 managers + 4 technicians) – maximum 15 (5 managers + 10 technicians)

cyber-range-green-baseline

Access to the training courses is free !!
Don’t wait!

Why take part?

Because in a crisis situation, the competences and reflexes of your technical teams are essential too limit the impact of an attack.

Module presentation

This intensive week of training is for IT and OT professionals. It aims to increase the teams’ maturity and operational readiness in facing cyber-attacks, by training them to detect threats, contain them, eliminate them and quickly restore operations following an incident.
The training courses will also help the participants elaborate a practical communication and coordination guide to be used in the case of an incident, a real ready-to-use tool that will serve as a reference material for technicians to ensure efficient and structured management of cybersecurity crises.

What you will learn

  • Reinforce the maturity and the operational readiness of your team in facing cyberattacks
  • Detect, contain, eliminate threats and restore operations following an incident
  • Elaborate a practical communication and coordination guide to be used for the management of cybersecurity incidents
module-4

Who is this training course for

This training course is for the following professionals: system administrator, network engineers, IT/OT engineers, OT developers and their managers.

The participants must master the following competencies:

  • Networks: TCP/IP, DNS, DHCP, VLAN, basic routing, firewall, NAT
  • Logs and investigation: knowing how to read journals (system, network, application) and understanding the cycle of an incident (detection → response → recovery)
  • IT tools: command line (Windows PowerShell and Linux bash), understanding of AD/LDAP environments (minimal notions)
  • Soft skills: able to work as part of a team, to document and follow procedures (runbooks)

Number of participants

Number of participants: Minimum 6 ( 2 managers + 4 technicians) – maximum 15 (5 managers + 10 technicians)

Programme

For the managers:

  • Day 4: Understand the 4 technical topics address but with a managerial point of view
  • Day 5: Cooperative practical activity, management of a crisis and debrief of the week.

For the technicians:

  • Day 1: Ransomware – Understand the chain of attack and the initial access methods, put in pace confinement and recuperation strategies, test back-up and communication plans
  • Day 2: Persistence and surveillance – Detecting stealth persistence, escalating privileges, data exfiltration, improving surveillance and journaling
  • Day 3: OT and sabotage – Recognising specific OT risks, securing the PLC/SCADA, responding to sabotage attempts
  • Day 4: Forensic – practicing an analysis of the acquisition of volatile and non volatile data, control chain cause analysis with explicit reporting
  • Day 5: Cooperative practical activity, management of a crisis and debrief of the week.

Sign up for our training