Free reference
45 building blocks of industrial cybersecurity — the systems, protocols, threats, defenses, and frameworks — grouped so you can hold the whole picture at once. Search or filter, and follow any tile into a practice bank, lab, or reference.
The devices and software that run and supervise a physical process.
Programmable Logic Controller
The ruggedised computer that runs control logic on the plant floor. The crown jewels of an OT environment.
Human-Machine Interface
The operator's screen. Compromise it and you control what the humans believe is happening.
Supervisory Control & Data Acquisition
Supervises many distributed sites and aggregates their telemetry into one control view.
Distributed Control System
Like SCADA but for a single large plant, with control distributed across many nodes.
Remote Terminal Unit
A field controller that reads sensors and drives actuators at a remote site.
Engineering Workstation
Where PLC logic is written and downloaded. Owning it means you can reprogram the process.
Intelligent Electronic Device
Microprocessor-based controllers (e.g. protective relays) common in electric utilities.
Safety Instrumented System
The last-line controller that trips a process to a safe state. Attacking it is OT's red line.
Data Historian
Time-series database of process values. A prime target for reconnaissance and data manipulation.
The industrial protocols that carry the risk — most trust every peer by default.
Modbus / Modbus TCP
Simple, ubiquitous, and completely trusting: any peer can issue a write. No auth or encryption by default.
Distributed Network Protocol 3
Common in utilities. A secure-authentication variant exists but is frequently left unused.
EtherNet/IP
Industrial protocol built on standard Ethernet/IP; trusts network-layer reachability.
PROFINET
Real-time industrial Ethernet common in European automation.
Building Automation & Control
The staple protocol of building management systems (HVAC, lighting, access).
OPC Unified Architecture
The modern exception: designed with authentication and encryption — only as strong as its config.
Message Queuing Telemetry Transport
Lightweight pub/sub protocol widely used in IIoT telemetry.
IEC 61850
Substation automation protocol suite (GOOSE, MMS) for electric utilities.
Highway Addressable Remote Transducer
Carries digital data over legacy 4-20 mA analog field wiring.
The incidents and techniques that define OT threat modelling.
Stuxnet (2010)
Sabotaged centrifuges by altering PLC logic while showing operators normal readings. Proved cyber can destroy physical equipment.
Industroyer / CrashOverride
Purpose-built to speak grid protocols and trip substations; caused a power outage in Ukraine.
TRITON / TRISIS (2017)
Targeted safety instrumented systems directly — an attack aimed at the controls that prevent disasters.
PIPEDREAM / INCONTROLLER
Modular, reusable ICS attack framework — a shift from bespoke tools to industrial malware toolkits.
Ransomware in OT
Reaches the plant floor through flat networks, forcing shutdowns even when it never touches a PLC.
Advanced Persistent Threat
State-aligned actors conducting long-dwell intrusions into critical infrastructure.
Supply-Chain Compromise
Malicious or vulnerable firmware, updates, or integrators inheriting trust into the environment.
Insider Threat
Engineers and contractors with legitimate, high-impact access to the process.
Internet-Exposed Assets
OT devices reachable from the internet and indexed by scanners — the beachhead in most real intrusions.
How you actually reduce risk on systems you cannot take offline.
Segmentation & the Purdue Model
Layered zones from enterprise to process, with a DMZ between IT and OT. The load-bearing OT control.
Asset Inventory
You cannot protect what you cannot see. In brownfield OT, building the inventory is often year one.
Passive Network Monitoring
OT-aware IDS that baselines normal traffic without probing fragile devices.
Secure Remote Access
A monitored jump host with MFA in front of all OT management interfaces.
Least Privilege
Services and accounts run with the minimum rights needed — the difference between a foothold and a takeover.
Segmentation Testing
Actively verifying that zone and conduit boundaries are real, not just documented.
Backup & Recovery
Tested restoration of PLC logic and configs — the recovery path when prevention fails.
Honeypots & Deception
Decoy OT services that reveal reconnaissance and lateral movement early.
Tabletop Exercises
Rehearsing OT incident response with safety and operations at the table, before a real event.
The standards and regulations that govern — and fund — OT security.
IEC 62443
The dedicated ICS/OT standard: zones and conduits, and security levels SL 1-4. Learn this one first.
NIST SP 800-82 Rev. 3
The practical U.S. guide that translates NIST controls into OT reality.
NERC CIP
Mandatory, enforceable security standards for the North American bulk electric system.
ISA / ISA-99
The standards body behind the 62443 series and much of the OT security profession.
MITRE ATT&CK for ICS
A knowledge base of adversary tactics and techniques specific to industrial control systems.
EU NIS2 Directive
Raises baseline cybersecurity and incident-reporting duties for essential and important entities.
EU Cyber Resilience Act
Secure-by-design and vulnerability-handling requirements for products with digital elements.
ISO/IEC 27001
The ISMS standard that OT programmes often extend to the plant floor.
Zones & Conduits
The 62443 modelling method: group assets by risk into zones, control the conduits between them.