ICS.222 OT Incident Handling Essentials

 805,00

The training „ICS.222 OT Incident Handling Essentials“ provides participants with the necessary essentials to prepare for security incidents in an industrial environment. The most important technical and organizational preparations will be discussed along with some “dos and don‘ts”. This course is particularly interesting for plant operators, integrators and service providers who want to prepare for an emergency to be able to more easily prevent damage caused by virus attacks, ransomware or hacking.

SKU: N/A Category: Tags: , ,

Description

Duration

1 day

Costs/participants
€ 805,- plus VAT
Minimum number of participants
10 people

What you can expect from
ICS.222 OT Incident Handling Essentials

Focus on special topics with practical relevance

Whether incident handling, security assessments, or standards such as IEC 62443, Additions training courses focus on topics that often make a difference in professional practice.

Comprehensive knowledge – acquired in a single day

The training courses are deliberately kept compact and convey in-depth knowledge in a short period of time that can be immediately applied in everyday work.

Industry experience – directly from the experts

Our trainers bring real-life war stories, lessons learned, and best practices from OT projects to the table—for training that is not only theoretically convincing.

You are on the search for an individual In-house training for your team?

Take your OT security know-how to the next level.

What you will learn during this training course

Structured along the incident handling lifecycle

The training ICS.222 OT Incident Handling Essentials provides practical knowledge for the effective management of incidents in industrial control systems (OT). The content is based on the proven Incident Handling Lifecycle according to NIST SP 800-61 Rev. 2. This lifecycle is divided into four central phases, which are systematically covered in the training:

Source: Cichonski, P. et al, “NIST Special Publication 800-61 Revision 2 – Computer Security Incident Handling Guide”, NIST, August 2012, p. 21

Incident Handling Lifecycle

1. Preparation

  • Introduction to incident handling
  • Basics and terms
  • OT incident handling
  • Preventive measures
  • Incident Handling Policy & Plan
  • Incident Report Template

2. Detection & Analysis

  • Typical types of indicators (IoC & IoA)
  • Sources for alerts (e.g. firewalls, IDS/IPS, SIEM)
  • Use of MITRE ATT&CK in the OT context
  • Hands-on: Analysis of a realistic OT incident

3. Containment, Eradication & Recovery

  • Strategies for damage limitation
  • Techniques for removing malware and attackers
  • Recovery of affected systems
  • Securing evidence
  • Root Cause Analysis

4. Post-incident activities

  • Lessons Learned Meetings
  • Creation of an incident report
  • Derivation of metrics and improvement measures
  • Communication with stakeholders
  • Mapping to MITRE ATT&CK

After the training, the participants have

  • improved their ability to recognize security incidents in OT early
  • developed a clear understanding of the proper way to deal with incidents in the OT environment
  • gained knowledge of the preparatory measures required in their own OT operations for dealing with security incidents

What others say

Varied training and clearly presented. Pleasant atmosphere and helpful documents.

Awareness & Compliance Training

Relaxed atmosphere in the seminar and high competence of the trainers. Participants were well involved, which led to active discussions. The hands-on exercises worked smoothly and were well described. I will recommend Limes to others.

OT-Security Training

Topic was mega interesting and very informative. The presentation, overview, outline, lecture and speaker were very good and gave me a lot of insight into the topic. Clear delimitation of the topics and not focused on everything.

Product Security Training

Great presentation and speaker who conveyed the topic in a way that was easy to understand. The connection between MR/NIS2/CRA/IEC62443 is now clear to me. For me the walk through of IEC62443 was helpful so I don't have to read it myself but know which bullet points to look at. Good time management.

Product Security Training

The practical part included helpful case studies. Pleasant lecture style, good for following and listening as well as collaborating.

Awareness & Compliance Training

Sympathetic trainers who were helpful with questions, explained a lot using practical examples and gave pleasant explanations.

OT-Security Training

Overview of security requirements according to IEC 62443 was informative and the list of tools to find vulnerabilities in products with Ethernet interfaces was helpful. Good presentation of the topics and many questions were answered quickly.

Product Security Training

Training highlights of the
ICS.222 OT Incident Handling Essentials

In ICS.222 OT Incident Handling Essentials, you take on the role of an experienced investigator! Based on internationally recognized incident handling guidelines (NIST SP 800-61), you and your colleagues will uncover step by step what happened one night at the fictitious energy supply company Strööm Inc. Using indicators that are modeled on real malware campaigns, you will deepen the content of the incident handling phases “Preparation”, “Detection & Analysis”, “Containment, Eradication & Recovery” and “Post-Incident Activity” learned in the theoretical parts in a practical way.

Work as a team, discuss possible suspicious events and look at the affected systems from the perspective of an attacker – this is the only way to recognize and stop the attack on Strööm Inc. in time!

Get to know our
trainers

Get your TÜV® persons certificate now!

Our OT security training courses not only provide knowledge, but also official proof of your competence.

You may also like…

  • Preview image Limes Academy Awareness Training ICS201
    Select options This product has multiple variants. The options may be chosen on the product page Quick View

    ICS.201 OT Security Fundamentals

     346,00
  • vorschaubild zum Limes Academy COSP
    Select options This product has multiple variants. The options may be chosen on the product page Quick View

    ICS.205 Certified OT Security Practitioner (COSP)

     3.070,00
Share
This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.