Education

Getting Started in OT Cybersecurity: The Complete Career Roadmap

September 9, 20268 min readBy Beacon Security Team

Operational technology (OT) cybersecurity is the protection of the systems that monitor and control physical processes. NIST SP 800-82 Revision 3, Guide to Operational Technology (OT) Security, defines operational technology as:

"a broad range of programmable systems and devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems and devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events."

This guide lists what to learn, in order, with the resources to learn it from.

Operational technology cybersecurity protects the systems that control physical processes, where the consequence of failure is measured in equipment damage and personnel safety rather than in disclosed records

How OT Security Differs From IT Security

  • Priority order: IT ranks confidentiality, integrity, availability. OT ranks safety, availability, integrity, confidentiality.
  • Impact of failure: IT failure discloses or corrupts data. OT failure stops a process, damages equipment or injures people.
  • Patching: Applying a patch may void a vendor warranty, invalidate a safety certification or require a process shutdown. Outage windows on a continuous plant may occur once a year. See securing legacy OT systems without patching.
  • Scanning: Active network scanning can fault legacy controllers. Discovery uses passive traffic capture and configuration review instead.
  • Protocol security: Industrial protocols were specified without authentication or encryption. A malicious command is structurally identical to a legitimate one.
  • Asset lifetime: Enterprise hardware is replaced in three to five years. Control equipment remains in service for fifteen to thirty.

The Two Routes Into the Discipline

The two professional backgrounds practitioners enter from, the competence each already holds, and what each must acquire

Entering From an Information Technology Security Role

Typical origin roles: security operations centre (SOC) analyst, network security engineer, penetration tester, incident responder, governance, risk and compliance (GRC) analyst, systems administrator.

You hold the security knowledge. You must acquire:

  • OT equipment: PLC, RTU, DCS, SCADA, HMI, engineering workstation, safety instrumented system, intelligent electronic device, historian.
  • Industrial protocols: Modbus, DNP3, EtherNet/IP, PROFINET, IEC 61850, OPC UA.
  • Process context: what the plant produces, its hazards, interlocks, trips, setpoints, management of change.
  • OT assessment method: passive traffic capture, configuration review and interviews, because endpoint agents, credentialed scanning and automated exploitation are frequently unsupported on control equipment.

Entering From a Control and Instrumentation Engineering Role

Typical origin roles: control systems engineer, instrumentation and control (I&C) engineer, automation engineer, process control engineer, SCADA or DCS engineer, PLC programmer, electrical and instrumentation (E&I) technician.

You hold the process knowledge. You must acquire:

  • Networking: IP addressing and subnetting, VLANs, routing, access control lists, stateful firewalls, NAT, packet capture with Wireshark, and the redundancy protocols PRP and HSR under IEC 62439-3.
  • Security concepts: asset, threat, vulnerability and risk, attack surface, defence in depth, least privilege, CVE and CVSS, indicators of compromise, attacker tactics and techniques, MITRE ATT&CK for ICS.
  • IEC 62443 vocabulary: zones, conduits, system under consideration, the seven foundational requirements, security levels SL 1 to 4 as target, capability and achieved, and the Purdue model. See our IEC 62443 explainer.
  • Programme elements: asset inventory, risk assessment, incident response planning, backup and recovery testing, supplier security requirements.

The Constraints on Entry

The five structural constraints on entry to OT cybersecurity, and the realistic timescale to working competence

  • No test environment on demand: Controllers are capital equipment and vendor engineering software is licensed to registered customers only.
  • Facility access is granted, not acquired: Site entry requires employment or a contracted engagement, plus safety induction and background clearance.
  • The standards are licensed: IEC 62443 parts are purchased individually. CISA and ENISA material covers much of the same ground free.
  • Incompatible vocabularies: Interlock, trip, setpoint and permissive against control, alert, threshold and authorisation.
  • Few entry-level roles: Postings assume prior plant or prior security experience. The practical route is converting an adjacent position.

Working competence is measured in one to two years of study alongside practical exposure.

The Learning Path

One resource per stage. Finish each one before starting the next.

Five stages, one resource each: the full CISA and INL catalogue, Cisco CCNA, Mike Holcomb's course, LabShock, then IEC 62443

Stage One: CISA and INL Training

All of it, in order. Free. Register on the Virtual Learning Portal with a corporate, government, military or educational email address.

On demand, available as soon as the account exists:

  • 100W: Operational Security (OPSEC) for Control Systems, one hour.
  • 210W series: Eleven modules of ninety minutes covering ICS deployments and components, the influence of common IT components, cybersecurity within the IT and ICS domains, cybersecurity risk, current threat and vulnerability trends, incident impact, attack methodologies in IT and ICS, and mapping IT defence in depth solutions to ICS.

Instructor-led. CISA states these "are instructor led and usually begin the first Monday of the month", that "students have three weeks to complete the training", and that there are no tuition costs:

  • ICS300: Industrial Control Systems Cybersecurity
  • ICS310: Foundations of ICS Threat Detection in OT Environment
  • ICS401: Industrial Control Systems Evaluation

Stage Two: Cisco CCNA

Examined as 200-301. Covers addressing, subnetting, switching, VLANs, routing, ACLs and network services. Build the topologies in a simulator. Sitting the exam is optional; the knowledge is not.

Stage Three: Mike Holcomb's Course

Getting Started with OT/ICS Cybersecurity, free on YouTube, 2026 revision. A single sequenced course covering the discipline end to end.

Stage Four: LabShock

LabShock is an isolated industrial environment with supervisory interfaces, controller logic, industrial protocol traffic and network segmentation. Exercises to complete:

  • Write controller logic and download it to the device.
  • Capture traffic between the HMI and the controller, and identify the function codes.
  • Change a setpoint, then locate that change in the capture.
  • Repeat from an attacker position and record what a defender would have seen.

A free alternative is OpenPLC and ScadaBR on virtual machines.

Stage Five: IEC 62443

The international series for industrial automation and control system security. Start with the concepts and the free introductory material, then buy individual parts as required.

Where a national framework applies, read it alongside the standard: Saudi Arabia's OTCC, India's CEA regulations for the power sector. The framework sets what is legally required; the standard sets how it is engineered.

Certification: CompTIA SecOT+

  • Exam code: SOT-001
  • Launch: December 2026
  • Retirement: Estimated three years after launch
  • Recommended experience: Three or more years of hands-on OT work and two or more years implementing OT security
  • Domains: OT systems and safety foundations, risk management, threat intelligence, architecture and engineering, security operations, incident management

It is the first vendor-neutral OT security certification. The experience recommendation makes it a target rather than a starting point, but the published objectives are a free syllabus for the whole discipline. Download them and measure your progress against them.

Staying Current: The Beacon Security Blog

Threat activity, disclosures and regulation move continuously, so a foundation built once needs maintaining. The Beacon Security blog covers:

  • Standards and regulation as issued: IEC 62443, OTCC, the CEA regulations, the EU Cyber Resilience Act.
  • Threat intelligence: ICS threat groups and industrial malware families as they are documented.
  • Architecture and defence: Segmentation, monitoring, legacy systems, product security and sector-specific guidance.

The material is drawn from our own assessments, architecture reviews and penetration tests in operating plants, and every clause number, date and identifier is checked against the primary source before publication. Free, no registration. Shorter analysis appears on LinkedIn.

Industrial infrastructure
OT Cybersecurity Experts

Your OT Environment Deserves
Expert Protection

IT security tools were not built for Modbus, OPC, or safety-rated controllers. Get a dedicated OT cybersecurity team that understands industrial protocols, control system architecture, and the operational constraints of your environment.

IEC/ISA 62443 Aligned
NIST 800-82 Compliant
OTCC Ready
ECC Aligned
Zero Operational Disruption