Your PLC has the security posture of a 1998 web server and the explosive potential of, well, an actual explosion. IT security protects data. OT security makes sure the thing that can boil, crush, electrocute or flood a city keeps doing exactly โ and only โ what you told it to. This is the speed-run from "what's a Modbus?" to "not getting a federal advisory named after my plant."
IT security ranks its priorities C-I-A: Confidentiality first (don't leak the data), then Integrity, then Availability. OT flips it to A-I-C โ and bolts Safety on top. Nobody dies if a spreadsheet leaks. People die if a turbine over-speeds or the chlorine dose triples. Tap a card to see the priorities.
๐ฉน You can't "Patch Tuesday" a blast furnace. Patching means a planned shutdown, sometimes a vendor flight and a 3-day revalidation. So OT runs ancient, unpatched software on purpose โ and compensates with isolation, not updates.
๐ฆ 20โ40 year lifespans. That controller was commissioned when "cyber" meant a chat room. It speaks protocols (Modbus, DNP3) with zero authentication โ they were designed for a trusted wire, not the internet.
The Purdue model stacks a plant into levels โ the messy internet at the top, the spinning/heating/flowing physical reality at the bottom. The golden rule: traffic moves between adjacent layers, never end-to-end, and a DMZ sits in the middle so IT and OT never talk directly. Click a layer โ see what lives there and what the attacker wants from it.
The Level 3.5 DMZ is the whole ballgame. Almost every real OT breach is a story of an attacker landing in IT (top) and finding a path all the way down to Level 1/0 โ because someone left a door propped open through the layers.
Forget Hollywood. OT attackers rarely need a Stuxnet-grade 0-day. They need a password that's still 1111 and an HMI that's googleable. Here's the real menu.
Real incidents, what went wrong, and the one lesson each burned into the industry. Notice how few involve genius hacking and how many involve a propped-open door.
You run a water-treatment plant. Somewhere out there, a bored hacktivist wants to dump lye into the supply (hi, Oldsmar). An attack is a chain โ break any link and it stops. Toggle your defenses, hit Launch attack, and watch how far they get. Defense-in-depth means you don't need every layer perfect โ you need the chain broken somewhere.
The simulator is the standard, dressed up. IEC 62443 โ the OT security bible โ says: carve the plant into zones of equal trust, allow traffic only through defined conduits between them, and assume any zone can be hostile. It's the Purdue model with a rulebook and an auditor.
๐งฑ Zones โ group assets of the same trust/risk (the SCADA zone, the safety zone, the DMZ). A breach in one shouldn't flood the others.
๐ Conduits โ the only sanctioned paths between zones, with a firewall/data-diode policing exactly which protocols may pass.
๐ข Security Levels (SL 1โ4) โ SL1 stops accidents; SL4 resists a nation-state with big resources. You target the SL each zone actually needs.
๐งญ The one-sentence version: an attacker who gets into one place should be able to do almost nothing from there. Every wall you saw in the sim โ no exposure, MFA, EDR, segmentation, OT monitoring, an independent safety system โ is just defense-in-depth refusing to put all its eggs in one firewall.
Tape these above the engineering workstation. Most breaches you just read about would have died on commandment 1, 2 or 4.
1111, admin/admin and 0000 are not passwords, they're invitations.Knowledge that closes with the browser tab isn't worth much. Here's the printable field kit: an IEC 62443-aligned hardening checklist (grouped by control family), the 10-commandments poster, and a one-page "we think we're breached" runbook. Tape them above the engineering workstation.
OT Security Field Kit
Hardening checklist ยท commandments poster ยท incident quick-reference. One click to print or save as PDF.
Ten questions, drawn from the whole lesson. Score 80% or higher to pass and unlock a personalised certificate of completion you can print or save as PDF. No peeking โ answers are revealed only after you submit.