A Year In OT Security

Week 17: Prevent OT Compromise From Affecting Safety And Protection
If any of your failure scenarios from last week required isolating the safety and protection devices and systems from OT, then this week you will design your solution. Note: Even if you don’t need to isolate your safety and protection you should read this section. The...
Week 16: No High Consequence Events If (When?) OT Is Compromised
Last week you identified failure scenarios that could cause a high consequence event when OT is compromised. This week’s task is simple and important. For each failure scenario from Week 15, identify a solution that would prevent the high consequence event if OT were...
Week 15: Identify OT Cyber Incidents That Could Cause High Consequence Events
This week’s task builds on the information collected in the previous five weeks and provides a key output for your OT security program. It identifies the high consequence events that could be caused by a cyber incident if an attacker gains access to and control of OT....
April: High Consequence Event Risk Reduction
The tasks in April are the most important, and the most rarely done, tasks in OT security and cyber risk management. This should be clearer after March when you learned about your company and its risk management program. In a perfect world, systems would work 100% of...
Week 14: Understand Your Safety And Protection Systems
Last week you identified the high consequence events related to the industrial process being monitored and controlled in OT. This week you learn what is in place to prevent these high consequence events. The engineers who designed the process are again your primary...
Week 13: Identify “The Really Bad Things” That Could Happen In Operations?
Many industrial processes can go bad in ways that cause catastrophic events. Loss of life. Severe property damage. Environmental disasters. If something gets too hot, spins too fast, mixes with the wrong chemicals, vibrates too much … BOOM! Your task this week is to...
Week 12: Understand The Financial Impact Of An Outage
This week’s task requires a discussion with the Finance department. Cybersecurity people in OT and IT often overestimate the financial impact of an outage. In one way, this is a good thing. It means the individual and team will work hard to avoid an outage because...
Week 11: Identify And Understand Your Company’s Risk Management Process
Your company has been managing risk since its inception. OT cyber risk is not special. It’s one more risk, albeit often ignored until recently. One clear path to failure is to try to invent your own method for managing OT cyber risk that differs from your company’s...
Week 10: Understand What Success Means In Your Company
It’s critical to know what your organization is trying to achieve and how success is measured if you are going to meaningfully contribute to cyber risk management decisions. This week’s task is to identify your organization’s most important 3 to 5 key mission...
March: Know Your Company
Beginning in March we shift for the rest of this book from a focus on your career to a focus on your company’s OT security and cyber risk management program. A common mistake is to begin by selecting and deploying security controls. You find a standard or...
Week 9: Identify And Plan Your Career Growth Area
One last, but not least, task to complete your S4 month is to plan what area you will focus your career growth on over the next year. Hopefully your S4x25 experience and the tasks over the past two weeks have given you some insight on what both will inspire you and...
UPCOMING EVENTS
OTCEP ... 29 - 30 July 2025 in Singapore
One of the best OT Security events in Asia. Dale will be playing cowboy that week and will unfortunately miss it. Most of the rest of the OTCEP panel will be there on stage.
S4x26 ... 23 - 27 February 2026 in Miami South Beach
Save the date for S4x26. For the biggest and most future focused on ICS Security Event ... and likely our last time in Miami South Beach.