Key information
Next application deadline: TBC
Next course starts: TBC
Format: Fully online, asynchronous and synchronous
Course duration: 12 weeks
Language: English
EQF Level: 7
Delivered by: POLIMI/CEFRIEL
Awarding Institution: German University of Digital Science
Certification: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
Fees: €350
Microcredential Information
This module aims to equip learners with comprehensive knowledge and practical skills in OT (Operational Technology) security, highlighting the differences and overlaps with IT (Information Technology) security. The focus will be on understanding key principles, risk modelling, and the legal and regulatory landscape, alongside developing skills to analyse, evaluate, and implement effective security measures in industrial environments.
Key Details
Time commitment
- (Estimated) Total workload: 125hours
- Contact Hours: 48 hours
- Self-study: 71 hours
- Examination: 6 hours
Assessment
- Flipped classroom Works: 50h preparation + 3h presentation (30%)
- Collaborative work: 9h (10%)
- Final proctored exam: 3h (60%)
Subjects covered
Lecture Content
1. The overlapping and differences between IT and OT security 1/2 The module introduces the basic concepts of OT security. Gartner defines Operational Technology (OT) as “hardware and software that detects or causes a change, through the direct monitoring and/or control of industrial equipment, assets, processes and events”. OT differs from IT in terms of functionalities, the culture of operators, and threats. OT is a novel and rapidly expanding area for cybercrime and industry. The number of attacks against OT infrastructures is increasing; the pandemic and the geopolitical crisis played a considerable role because of the acceleration of digital transformation. For example, the reduction of on-site staff put a strain on OT systems and the already limited resources and required increased external connectivity. However, from a cybersecurity point of view, IT and OT need specific competence and sensibility. The primary need is an integrated approach that includes cybersecurity, physical and cyber-physical security, integrated cyberrisk estimation, and governance models spanning IT and OT domains.
2. The overlapping and differences between IT and OT security 2/2
3. OT Threat Landscape This module aims to increase comprehension of the OT threat landscape and its differences from the IT world. OT security is not an extension of IT security and requires a unique set of competencies. Nonetheless, threat actors use different Tactics and Procedures. Background knowledge, such as the ATT&CK framework, is presented.
4. Tactics, techniques and procedures of the cybercrime and their evolutions ½ In the deep analysis of the tactics, techniques and procedures used by threat actors in the context of attacks against OT and cyber-physical systems. The specialised framework for industrial systems of the ATT&CK framework is used. The module also aims to perform reverse code engineering of the most prominent cases. According to the attendance, basic elements of reverse code engineering will be presented as a prerequisite to the malware analysis module. This module is intended for managerial profiles and not for technical profiles.
5. Tactics, techniques and procedures of the cybercrime and their evolutions 2/2
6. Analysis of recent and paradigmatic attack cases and lessons learnt – flipped classroom 1/2 In this module, we’ll look at different real-life examples, some of which come from students’ homework. Students must study a piece of harmful software or a cyber-attack related to OT security. Then, students will share what they have learned with the rest of the class and the teachers in a flipped classroom approach.
7. Analysis of recent and paradigmatic attack cases and lessons learnt – flipped classroom 2/2
8. This course is pivotal for understanding how to mitigate risks in integrated systems and protect against cyber and manmade threats. Even from a cyber risk modelling point of view, OT security is not an extension of IT security and re- quires a unique set of competencies. The module will analyse the differences among classic cyber risk modelling techniques and theory and modelling of cyber-physical systems, with particular attention to correlation among different types of risk and the cascading effects on non-cyber systems (e.g., risks of explosion, etc). The module also discussed the role of humans in human-related threats.
9. Standards, best practices and EU laws for cybersecurity in the context of OT cybersecurity 1/2 Having a comprehensive view of the EU cybersecurity law framework specifically applicable to industry, the student will be able to determine if their industry and activities are subject to a particular piece of cybersecurity legislation, assess the extent of this applicability, and understand the key concepts and requirements necessary for achieving compliance and demonstrating accountability. EU laws that could specifically impact the industry in the Cybersecurity domain, such as the NIS 2 Directive, the Cybersecurity Act, the Cyber Resilience Act, the Medical Device Regulation(s), the EU Machinery Directive, and ISO reference standards such as ISO-62443.
10. Standards, best practices and EU laws for cybersecurity in the context of OT cybersecurity 2/2
11. The impact of the new technologies 1/2 The field of OT is undergoing a phase of evolution where new solutions (e.g., AI, 5G, IIoT, Quantum Computing, Quantum Cryptography) are being developed. These new technologies particularly impact integrated IT and OT systems, where cyber risks could have cascading effects on non-cyber risks. The existing literature recognises the critical need for robust cybersecurity measures to safeguard against intentional threats and hybrid attacks. Traditional approaches often involve individually securing data flows, network layers, and software components, emphasising preventing unauthorised access and ensuring data integrity. The module will analyse and discuss the impact of these new technologies and present foreseen coming threats.
12. The impact of the new technologies 2/2
Register your interestLearning objectives
This module provides a comprehensive overview of the essential knowledge, skills, and competencies necessary for addressing cybersecurity in Operational Technology (OT) environments, highlighting the unique challenges compared to IT security. It covers key concepts such as risk modeling specific to OT, legal and regulatory frameworks, and emerging technologies like AI, 5G, and IIoT.
The ability to analyze OT’s evolving threat landscape, assess industrial cyber risks, and evaluate real-world attack cases is emphasized, along with the need to apply relevant standards and best practices. Competencies include identifying vulnerabilities, synthesizing remediation measures, and managing continuous risk assessments, all while navigating the complexities of modern OT security governance and human-related threats.
Learning Outcomes: On successful completion of this module, the learner will be able to:
• LO1: Evaluate the principles and challenges of OT security, differentiate them from IT security, and align security strategies with industry standards and best practices.
• LO2: Critically assess and compare the OT threat landscape with IT, including analysing specific tactics, techniques, and procedures used in OT-focused cyber-attacks.
• LO3: Examine and evaluate recent case studies of cyber incidents in OT environments, drawing lessons on risk assessment and security countermeasures.
• LO4: Analyse and apply relevant laws, regulations, and standards to develop robust OT security frameworks, incorporating the latest technological advancements such as AI, 5G, and IIoT.
• LO5: Develop comprehensive risk models and security measures tailored to OT environments, ensuring effective governance and continuous risk assessment.
• LO6: Assess the impact of human factors on OT security, identifying key vulnerabilities and synthesising remediation measures to strengthen the overall security posture.
Register your interestMaking Europe cyber-aware
Our digital world is under constant attack. Master the advanced skills to defend critical data and infrastructure. Become a sought-after expert in one of today’s most vital and in-demand career fields.
Download prospectusFAQs
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.