← All 186 courses
SEC-406 Security

OT/ICS Detection & Incident Response

Detection and response where you cannot reboot the asset and cannot stop the process. Learners build passive visibility in fragile networks, write protocol-aware detections for Modbus, DNP3 and OPC UA, map coverage against ATT&CK for ICS, and rehearse containment options that a plant manager will actually authorise. The course closes with a joint tabletop run against control engineers rather than against slides.

B4Professional
6modules
42skill atoms
2role journeys
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1Passive Asset Inventory7 skill atoms
tap & SPAN placementpassive discovery instead of active scanningdevices that fall over when probedvendor, model and firmware fingerprintingserial and Level 1 blind spotsbaselines from engineering project exportsreconciliation against plant records
2Protocol-Aware Detection7 skill atoms
Modbus function code baseliningDNP3 unsolicited response anomaliesOPC UA session and certificate monitoringlogic download and program upload detectionsetpoint and tag change alertingunauthorised master or new talker detectionprotocol allowlist rule design
3Telemetry Architecture7 skill atoms
ICS-aware sensorshistorian and HMI logsengineering workstation endpoint telemetryDMZ firewall flow logssyslog from relays and RTUsone-way transport out to the SOCretention under constrained bandwidth
4ATT&CK for ICS Mapping7 skill atoms
ICS matrix tacticsimpair process control and inhibit response function techniquesdetection coverage heatmap by zonemapping technique to plant consequencehypothesis-driven hunting in OT datapublic case reading such as Industroyer and Tritonclosing gaps by data source not by tool
5Containment Without Downtime7 skill atoms
you cannot pull the plugisolate at the conduit rather than the deviceengineering-authorised change windowsmanual and fallback operating modesevidence capture that does not disturb scan cyclesplant manager decision rightsrecovery using vendor-validated firmware
6Tabletop With Engineering7 skill atoms
joint SOC and plant scenario designsevere-but-plausible process impactescalation clocks and decision rightssafety system trip criterianotification to regulators and insurersconverting gaps into playbook backlogafter-action review with control engineers
Where it fits

SEC-406 in the role journeys.

This course appears in 2 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

SOC Analyst

Professional stage
SEC-209SEC-406SEC-407

OT / ICS Security Engineer

Professional stage
SEC-104SEC-406SEC-206

Roles this course serves

The capability ladder

This course is authored to band B4.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-406 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free