← All 186 courses
SEC-105 Security

OT & ICS Security Foundations

Industrial estates explained for people who came from IT: what a PLC, HMI, SCADA master and historian actually do, and why a plant inverts the priorities you were trained on. Learners leave able to read a Purdue-model architecture, describe the safety case, hold a credible conversation with a control engineer, and place IEC 62443 zones and conduits on a real site diagram.

B2Foundation
6modules
41skill atoms
1role journey
Curriculum

What this course covers.

6 modules, 41 named skill atoms. Expand any module to see them.

1Industrial Estate Anatomy7 skill atoms
PLC scan cycleHMI & operator workstationSCADA masterprocess historianRTU & IED rolesengineering workstation as crown jewelvendor remote access reality
2Purdue Model in Practice7 skill atoms
levels 0 to 5cell and area zonesLevel 3 site operationsthe Level 3.5 industrial DMZjump host & data diode placementhow flat real plants actually areconduit definition between zones
3Safety Outranks Everything7 skill atoms
safety instrumented systemsSIL ratings & the safety caseavailability and safety above confidentialityfail-safe vs fail-operational designchange control under plant permitsconsequence-driven thinkingwhy active scanning is not free
4Protocols & Their Assumptions6 skill atoms
Modbus and DNP3 with no authentication by designDNP3 Secure Authentication under IEEE 1815 and why it is rarely switched onOPC UA as the counter-example with application certificates, signing and encryptionProfinet & EtherNet/IPserial-to-Ethernet gateway exposureplaintext engineering traffic
5The IT/OT Boundary7 skill atoms
DMZ segmentation patternsunidirectional gatewaysbrokered vendor remote accesspatch windows measured in yearsshared service traps such as AD and DNSasset ownership disputeshandover between plant staff and the SOC
6IEC 62443 Orientation7 skill atoms
zones & conduitssecurity levels SL1 to SL4seven foundational requirementsasset owner, integrator and product supplier roles62443-2-1 CSMS vs 62443-3-3 system requirementsNIST 800-82 alignmentmaturity vs capability levels
Where it fits

SEC-105 in a role journey.

This course appears in 1 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

OT / ICS Security Engineer

Foundation stage
SEC-101SEC-105SEC-104

Roles this course serves

The capability ladder

This course is authored to band B2.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-105 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free