Hands-On ICS/OT Cyber Defense Training with CyRenLAB

Real signals. Real devices. On site or delivered live to your team.

Most industrial security training hands you packet captures and virtual machines. This one hands you a working industrial process. You will watch 4–20 mA current loops carry a tank level, follow Modbus and IEC telemetry across serial and Ethernet, and learn what normal looks like on real controllers, drives, meters, and sensors.

Then you will attack it. Every exploit scenario runs live against that equipment while you build the detection logic and watch it alert.

[Book a Session]

At A Glance

Tweleve hands-on labs in three parts. Instructor led live on site or remotely. No prerequisites: Part 1 assumes no prior ICS experience. Every attendee receives a certificate of completion.

[Download Syllabus]

Why This is Different

You work at Levels 0 and 1

Most industrial processes are driven by analog current loops and serial buses at the lowest Purdue Levels, and most monitoring tools cannot see either. This training covers 4–20 mA analog, RS-232, RS-422 and RS-485 serial, and industrial Ethernet in one environment, so you learn the Levels your existing tools are blind to. Protocols covered: 4–20 mA analog instrumentation, Modbus RTU, IEC 60870-5-101, Modbus TCP, and IEC 60870-5-104.

Nothing is simulated

The transmitters, drives, meters, and controllers are real. Turn the inflow knob on the panel and the current in the wire changes; watch it arrive in the AnalytICS Engine a moment later. Sensors tap the signals passively, so nothing you do adds latency or risk to the control loop.

You investigate attacks, you do not just read about them

Each exploit runs live. You find the indicators in the captured traffic, write the detection rules, and prove they fire on the attack and stay silent on normal operation. Every rule is tagged with the MITRE ATT&CK for ICS technique it proves.

The Curriculum

Part 1 — Foundations: Industrial Communications

How industrial systems communicate when nothing is wrong, across Purdue Levels 0 to 3. You finish able to establish a baseline.

  • Lab 1: Introduction to Analog Signals. 4–20 mA instrumentation, process variables, and analog baselines.
  • Lab 2: Introduction to Serial Communications. Modbus RTU and IEC 60870-5-101 request and response behavior.
  • Lab 3: Introduction to TCP/IP Protocols. Modbus TCP and IEC 60870-5-104 over Ethernet.

Part 2 — Visibility: Assets and Network Behavior

Turning raw telemetry into a trustworthy picture of the environment. You finish with a curated inventory rather than a raw asset list.

  • Lab 4: Discover and Read the Asset Map. Passive discovery, VLAN groupings, and serial bus topology.
  • Lab 5: Investigate and Confirm. Identity, evidence, and confidence in the asset inventory.
  • Lab 6: Organize and Analyze. Merging duplicates, linking devices, and path tracing.
  • Lab 7: Network Map and Sankey Workflows. Communication paths, segmentation, and traffic concentration.

Part 3 — Exploit Investigation

Detecting and investigating cyber-physical attacks, each mapped to MITRE ATT&CK for ICS. You finish with working detection rules you wrote and validated yourself.

  • Lab 8: Tower Light Tampering. Unauthorized Modbus writes and illegal state values.
  • Lab 9: Motor Override. Speed forced out of band, command flood, and unauthorized start and stop.
  • Lab 10: Sensor Fault Injection. False analog values and ground-truth divergence on a 4–20 mA loop.
  • Lab 11: IEC 101 Spoofing. Rogue serial device and spoofed measured values on a telecontrol bus.
  • Lab 12: IEC 104 Takeover. Adversary-in-the-middle: ARP poisoning, TCP reset, and false telemetry.

Delivery

On site

We bring the environment to your facility. Your team trains on the same equipment classes they operate, in their own building, with no production system at risk.

Live remote

The lab stays with us and your team connects to it. The signals are still physical: an instructor turns a knob on the panel and the current changes on real wire, and you watch that change arrive in the AnalytICS Engine from anywhere in the world. This is not a simulator with a video feed. It is the same equipment, the same traffic, and the same exercises as the on-site course.

MITRE ATT&CK for ICS

Mapped at the rule level, not the brochure level

Most training claims ATT&CK alignment at the course level. Here every detection rule you build carries the technique it proves, in the alert body itself, so your alert output can be exported straight into ATT&CK Navigator. The exploits cover seven techniques across six ATT&CK for ICS tactics, from Initial Access through Impact.

ID Technique ATT&CK tactic Lab 8 Lab 9 Lab 10 Lab 11 Lab 12
T0848 Rogue Master Initial Access
T0830 Adversary-in-the-Middle Collection
T1692.001 Unauthorized Message: Command Message Evasion / Impair Process Control
T1692.002 Unauthorized Message: Reporting Message Evasion / Impair Process Control
T0836 Modify Parameter Impair Process Control
T0814 Denial of Service Inhibit Response Function
T0831 Manipulation of Control Impact
T0832 Manipulation of View Impact

Certificate and Continuing Education

Every attendee receives a certificate of completion listing the course, the dates, and the contact hours earned.

What You Train On

CyRenLAB

The courses run on CyRenLAB, our industrial research and training environment. It spans Purdue Levels 0 through 3 in one modular platform, with hardware-in-the-loop controllers, drives, meters, and sensors driving a water treatment process and an electrical substation demo. Teams that want a permanent environment of their own can purchase it.

[About CyRenLAB] [Download Product Sheet]

Who Should Attend

Anyone responsible for the security, reliability, or oversight of industrial systems. That includes SOC and NOC analysts, incident responders, control and automation engineers, OT and IT security teams, risk and compliance staff, and the managers, executives, and program owners who have to make decisions about all of it. Researchers and educators are welcome too.

No prior ICS experience is required. Part 1 begins with how industrial systems communicate when nothing is wrong, which makes it a practical starting point for technical and non-technical attendees alike. Teams often attend together, and the shared vocabulary that comes out of it is frequently the most useful result.

The material applies across every critical infrastructure sector, among them water and wastewater, electric utilities, oil and gas, manufacturing, chemical processing, building management, transportation, maritime, defense, and government. If your organization operates industrial systems, it applies to you.

Next Step

Tell us your team size and whether you want us on site or delivered remote, and we will send the syllabus and available dates.

Delivered in the Field

We have run this training for operators and security teams across three regions: in Riyadh and in Oman, both delivered in partnership with PwC, and in Ukraine.

[Book a Session] [Download Syllabus]