Skip to main content

Industrial Cybersecurity: Governance, Risks and OT systems

Key information

  • Application opening date: July 27, 2026
  • Next application deadline: September 25, 2026
  • Next course starts: October 6, 2026
  • Format: Online synchronous
  • Course duration: 12 weeks (module 1 & 2 in parallel)
  • Language: English
  • Awarding Institution: Politecnico di Milano
  • Delivered by: Politecnico di Milano, CEFRIEL, University of Brescia
  • Certified by: Politecnico di Milano
  • ECTS: 18 ECTS (5+5+8)
  • Fees: €1400

Learning objectives

Upon completion of the course, participants will have acquired the following competencies: in-depth knowledge of national and European regulatory frameworks in cybersecurity, with particular reference to industrial systems and critical infrastructures; ability to analyze and assess security risks in cyber-physical systems using established methodologies and specialized tools; technical skills for identifying, preventing and mitigating threats to OT systems and operational technologies; capabilities in designing and implementing security governance policies and compliance procedures; mastery of ethical and professional principles applicable to cybersecurity practice; ability to integrate legal, technical and organizational aspects in defining effective and sustainable security strategies for complex industrial contexts.

The module is designed to fit around professional and personal commitments. All core content is available asynchronously for self-paced study, complemented by optional live sessions offered throughout the module.

Week 1: Legal Foundations of Cybersecurity

An introduction to key legal instruments, foundational concepts, and essential terminology in cybersecurity law.

Week 2: Regulatory and Legal Aspects of Cybersecurity Strategy and Operations (I)

An overview of relevant laws, acts, and regulations at the EU level, including NIS2, DORA, and the Cyber Resilience Act.

Week 3: Regulatory and Legal Aspects of Cybersecurity Strategy and Operations (II)

Examination of the European regulatory landscape for the Digital Decade, with a focus on cybersecurity-related laws such as the AI Act, Data Act, DSA, and DMA.

Week 4: Data Protection and Privacy

In-depth analysis of GDPR principles, key concepts, and the roles and responsibilities of various stakeholders.

Week 5: Cross-Border Data Protection

Exploration of the Law Enforcement Directive, ePrivacy Directive, and regulations governing cookies, as well as issues surrounding international data flows.

Week 6: Accountability and Compliance Management

Discussion of accountability mechanisms and compliance management strategies within organizations, with a focus on specific sectors.

Week 7: Legal Frameworks and Compliance

A detailed study of how legislation underpins cybersecurity and data protection, emphasizing EU laws and corporate compliance mechanisms.

Week 8: Standards and Certifications

Analysis of prominent EU cybersecurity standards and certifications, their enforceability, and the consequences of non-compliance.

Week 9: Governance in Cybersecurity

Examination of the integration of cybersecurity within broader IT governance frameworks and the role of policies in shaping organizational strategies.

Week 10: Ethical Considerations and Policy-Making

Exploration of the ethical dimensions of cybersecurity decisions and policy-making, with attention to the impact of emerging technologies like AI.

Week 11: Workplace Surveillance and Cybersecurity

A study of the balance between surveillance for security monitoring and the protection of employee privacy, analyzing surveillance technologies, legal frameworks, and ethical considerations to inform policy development.

Week 12: Diversity and Inclusion in Cybersecurity

Evaluation of the role of inclusive practices in enhancing cybersecurity efforts, and the impact of cyber-attacks on personnel, including psychological effects on response teams.

Lecture Content

1. The overlapping and differences between IT and OT security 1/2 The module introduces the basic concepts of OT security. Gartner defines Operational Technology (OT) as “hardware and software that detects or causes a change, through the direct monitoring and/or control of industrial equipment, assets, processes and events”. OT differs from IT in terms of functionalities, the culture of operators, and threats. OT is a novel and rapidly expanding area for cybercrime and industry. The number of attacks against OT infrastructures is increasing; the pandemic and the geopolitical crisis played a considerable role because of the acceleration of digital transformation. For example, the reduction of on-site staff put a strain on OT systems and the already limited resources and required increased external connectivity. However, from a cybersecurity point of view, IT and OT need specific competence and sensibility. The primary need is an integrated approach that includes cybersecurity, physical and cyber-physical security, integrated cyberrisk estimation, and governance models spanning IT and OT domains.

2. The overlapping and differences between IT and OT security 2/2

3. OT Threat Landscape This module aims to increase comprehension of the OT threat landscape and its differences from the IT world. OT security is not an extension of IT security and requires a unique set of competencies. Nonetheless, threat actors use different Tactics and Procedures. Background knowledge, such as the ATT&CK framework, is presented.

4. Tactics, techniques and procedures of the cybercrime and their evolutions ½ In the deep analysis of the tactics, techniques and procedures used by threat actors in the context of attacks against OT and cyber-physical systems. The specialised framework for industrial systems of the ATT&CK framework is used. The module also aims to perform reverse code engineering of the most prominent cases. According to the attendance, basic elements of reverse code engineering will be presented as a prerequisite to the malware analysis module. This module is intended for managerial profiles and not for technical profiles.

5. Tactics, techniques and procedures of the cybercrime and their evolutions 2/2

6. Analysis of recent and paradigmatic attack cases and lessons learnt – flipped classroom 1/2 In this module, we’ll look at different real-life examples, some of which come from students’ homework. Students must study a piece of harmful software or a cyber-attack related to OT security. Then, students will share what they have learned with the rest of the class and the teachers in a flipped classroom approach.

7. Analysis of recent and paradigmatic attack cases and lessons learnt – flipped classroom 2/2

8. This course is pivotal for understanding how to mitigate risks in integrated systems and protect against cyber and manmade threats. Even from a cyber risk modelling point of view, OT security is not an extension of IT security and re- quires a unique set of competencies. The module will analyse the differences among classic cyber risk modelling techniques and theory and modelling of cyber-physical systems, with particular attention to correlation among different types of risk and the cascading effects on non-cyber systems (e.g., risks of explosion, etc). The module also discussed the role of humans in human-related threats.

9. Standards, best practices and EU laws for cybersecurity in the context of OT cybersecurity 1/2 Having a comprehensive view of the EU cybersecurity law framework specifically applicable to industry, the student will be able to determine if their industry and activities are subject to a particular piece of cybersecurity legislation, assess the extent of this applicability, and understand the key concepts and requirements necessary for achieving compliance and demonstrating accountability. EU laws that could specifically impact the industry in the Cybersecurity domain, such as the NIS 2 Directive, the Cybersecurity Act, the Cyber Resilience Act, the Medical Device Regulation(s), the EU Machinery Directive, and ISO reference standards such as ISO-62443.

10. Standards, best practices and EU laws for cybersecurity in the context of OT cybersecurity 2/2

11. The impact of the new technologies 1/2 The field of OT is undergoing a phase of evolution where new solutions (e.g., AI, 5G, IIoT, Quantum Computing, Quantum Cryptography) are being developed. These new technologies particularly impact integrated IT and OT systems, where cyber risks could have cascading effects on non-cyber risks. The existing literature recognises the critical need for robust cybersecurity measures to safeguard against intentional threats and hybrid attacks. Traditional approaches often involve individually securing data flows, network layers, and software components, emphasising preventing unauthorised access and ensuring data integrity. The module will analyse and discuss the impact of these new technologies and present foreseen coming threats.

12. The impact of the new technologies 2/2

Industrial Cybersecurity: Governance, Risks and OT systems

  • Risk Management of Cyber-Physical Systems (5 ECTS)
  • Cybersecurity in Industry – Security of OT and Cyber-Physical Systems (5 ECTS)
  • Law, Compliance, Governance, Policy, and Ethics (8 ECTS)

Subjects covered

Lecture 1: Course introduction. Risk management concept and process. Risk-based technology selection and adoption.

Lecture 2: System safety engineering of cyber-physical systems. Risk Engineering methods: a) Failure Mode Effects and Criticality Analysis (FMECA); b) Fault Tree Analysis (FTA); c) Event Tree Analysis (ETA); d) Probabilistic Risk Analysis (PRA)

Lecture 3: Risk Analysis of Socio-Technical systems: Human and Organizational risk factors; Risk management of Organizational accidents; the High Reliability Organization theory. Critical incident analysis

Lecture 4: Cyber Risk modelling: a) Types of risks (Humans, IT, OT); b) Cyber risk models and principles (Cyber risk models, Cascading effects, Correlation among risks, Risks of intangible assets)

Lecture 5: Challenges and Advances in Industrial Cyber Risk

Assessment:

a) Information security Today;

b) Challenges in modern Security Governance;

c) Continuous risk assessment;

d) Principles of Social Engineering

Lecture 6: Cyber risk maturity models and management:

a) CMMs;

b) DevSecOps drill down (SCA, SBOM, Best practices);

c) EU Legislation framework;

d) US Legislation framework and comparison

Lecture 7: Case study by practitioners: Cybersecurity Threats, Strategy and Management

Lecture 8: Case study by practitioners: Cyber and Physical Risk Management

Lecture 9: Business Continuity Management:

a) BCM Fundamentals and business cases;

b) Business Impact Analysis;

c) Recovery strategies;

d) Collaborative BCM and SC resilience

Lecture 10/11: Business Continuity Management – serious game sessions

Lecture 12: Cybersecurity for Critical Infrastructure:

a) Importance of CIP-R;

b) Critical Infrastructure Resilience;

c) Interdependencies and cascading events;

d) Modelling and analysis of interdependent systems;

e) Cyber threats to CI;

f) Best practices and frameworks CIP-R

Register your interest

Module leaders

Risk Management of Cyber-Physical Systems:

Title: Prof.

Name: Paolo Trucco

Prof. Paolo Trucco

Law, Compliance, Governance, Policy, and Ethics:

Title: Prof.

Name: Giorgio Pedrazzi

Prof. Giorgio Pedrazzi

Cybersecurity in Industry – Security of OT and Cyber-Physical Systems:

Title: Dr.

Name: Enrico Frumento

 

newsletterStay ahead in cybersecurity

Subscribe to our newsletter for exclusive insights and breakthroughs from Digital4Security directly to your inbox

Applications open
Hybrid Master's
Application deadline:
Friday, 11th September 2026, 22:00 CET
Course starts:
Monday, 28th September 2026
Course duration:
2 years | Hybrid (online + in-person intensives)
Course delivery:
Hybrid program
Certification:
ARACIS (Romania)-accredited masters's degree (120 ECTS)
Language:
English
Apply now
Applications closed
Microcredentials
Application deadline:
Friday, 25th September, 12:00 CEST
Course starts:
From October 2026 (application opens Monday, 27th July)
Course duration:
6-12 weeks depending on chosen course
Course delivery:
Online
Certification:
Official recognition of your completed learning outcomes and awarded ECTS
Language:
English
Register your Interest
Apply now Toggle