Utah Tech University OT/ICS Network Security Register free Email us Join waitlist
Free to enroll Self-paced Certificate of completion

OT/ICS Network Security The networking and security mental model every control‑system professional is now expected to have.

A complete, seven-module course built for OT and ICS engineers with little to no IT background. Understand your own network, hold your ground in a conversation with IT and security, and find the vulnerabilities sitting in your plant today.

No cost, no prerequisites, no lab hardware required.

Where the course lives Purdue Model · Levels 0–5
The Purdue reference model for industrial control networks A stack of six zones, from Enterprise IT at the top down to the process level at the bottom, with the IT/OT DMZ highlighted as the critical boundary between the business network and the control network. L5/4 Enterprise IT & Business Network ERP, email, internet — where the attacker usually lands first DMZ IT/OT DMZ Historian replica, jump host, brokered data only L3 Site Operations Historians, domain services, engineering workstations L2 Supervisory Control SCADA servers and HMIs L1 Basic Control PLCs, RTUs, IEDs — devices that crash when actively scanned L0 Physical Process Sensors, actuators, valves — the thing that actually moves

Module 4 walks this stack level by level — and shows the four ways real plants quietly bypass it.

53
Video lessons
7
Modules
$0
Cost to enroll
100%
Self-paced online

The situation

The air gap is gone. The responsibility landed on you.

Control networks were designed for uptime and determinism, not for adversaries. Then they got connected — to the business network, to vendors, to the internet — and the person who now has to answer for that is the person who knows the process best.

The flat network problem

One broadcast domain from the front office to the PLC rack. A single compromised laptop reaches every device on the plant floor, because nothing in between was ever configured to say no.

Protocols with no security model

Modbus, DNP3 and their neighbors were never designed to authenticate anything. Telnet, FTP and SNMPv1 are still running in plants right now, handing credentials to anyone listening.

Two teams, two languages

IT wants to patch on a schedule and scan the subnet. You know what an active scan does to a legacy PLC. Neither side is wrong — but the conversation only works if you can both speak in VLANs, ports and rules.

You can't protect what you can't see

Most sites cannot produce an accurate list of what is on their control network. The drawing on the wall is five years old, and three devices got added last quarter that nobody documented.

Firewalls that permit everything

There is a firewall between IT and OT. It has a rule at the top that says any / any / allow, added during a commissioning weekend in 2019 and never removed. This is the single most common finding in OT assessments.

Consequences that aren't data

An IT breach costs records. An OT breach costs pressure, flow, voltage and, in the worst case, people. Stuxnet and Colonial Pipeline are the case studies, and they are on the syllabus.

What you walk away with

Skills you can apply the week you finish

This is not an awareness course. Every module ends somewhere concrete — a diagram you can draw, a rule you can read, a command you can safely run on a live network.

  • Read your own network Trace a packet from an HMI to a PLC and name every device, address and protocol it touches on the way.
  • Segment without a capital project Use VLANs and subnetting to build real security zones on the switches you already own.
  • Place a DMZ correctly Apply the Purdue model to your site and explain why nothing should cross from Level 4 to Level 3 in one hop.
  • Audit a firewall rule set Read rules in order, spot the implicit allow, and apply default deny and least connectivity without breaking the process.
  • Discover hosts without causing an outage Know exactly why active scanning drops legacy devices, and what passive monitoring and careful CLI work do instead.
  • Retire the dangerous legacy services Identify Telnet, FTP and SNMPv1 exposure on your network and make the case for replacing them.
  • Secure remote access properly Evaluate VPNs, jump hosts and MFA for vendor and on-call access — and recognize an exposed RDP port for what it is.
  • Troubleshoot layer by layer Work a structured OSI-model process instead of guessing, and produce network documentation others can actually use.

The syllabus

Seven modules. Fifty-three lessons. In order.

The course builds from “what is a network” to full attack-path analysis. Nothing assumes prior IT knowledge, and nothing is skipped. Expand any module to see every lesson.

01 Networking Fundamentals The vocabulary and the physics — and why OT is a different problem 8 lessons
  1. What is a Network?
  2. LANs, WANs & How Packets Move
  3. Switches vs. Routers Explained
  4. WAPs, Modems, NICs & Why SCADA is Networked
  5. Copper vs. Fiber: Physical Layer & Security
  6. Serial Communications in OT: RS-232, RS-485, RS-422 & the Security Risk
  7. Why OT Network Security Is Different — and Why It’s Your Responsibility
  8. Stuxnet & Colonial Pipeline: Real OT Attacks and What They Teach Us
02 IP Addressing Fundamentals Addresses, masks and gateways — the language of segmentation 8 lessons
  1. IP Addresses: What They Are and Why They Matter
  2. IPv4 Address Format Explained
  3. Subnet Masks and Network Segmentation
  4. Private vs. Public IP Addresses
  5. DHCP vs. Static IP Addressing in OT Networks
  6. Default Gateways and the Danger of Flat Networks
  7. MAC Addresses and ARP
  8. DNS and Why It Matters for SCADA
03 Protocols and Ports How systems agree to talk — and which conversations to shut down 6 lessons
  1. Protocols: What They Are and Why They Matter
  2. The OSI Model Explained for OT Engineers
  3. TCP vs. UDP: Reliability vs. Speed in OT Networks
  4. Network Ports: What They Are and Why They Matter for OT Security
  5. OT Port Numbers You Need to Know
  6. Dangerous Legacy Protocols: Telnet, FTP, and SNMP
04 Network Architecture and Segmentation The core of the course — zones, the Purdue model, and the IT/OT DMZ 12 lessons
  1. The Flat OT Network Problem: Why It’s a Security Liability
  2. VLANs for OT Security: Creating Network Zones Without New Hardware
  3. How Segmentation Stops Attackers: Containment, Detection & Blast Radius
  4. IT/OT Convergence: Why the Air Gap Is Gone and What It Means for Security
  5. The Purdue Model Explained: Levels 0–3 and the OT Zone Structure
  6. The OT/IT DMZ Explained: Why It’s the Most Critical Architectural Element
  7. Data Diodes Explained: Hardware-Enforced One-Way Flow for High-Security OT
  8. How OT Network Segmentation Fails in Practice: The Most Common Gaps
  9. Wi-Fi Security in Industrial OT: Risks, Standards & Best Practices
  10. Principle of Least Connectivity: The Governing Rule for OT Firewall Rules
  11. OT Network Documentation: How to Read and Create Network Diagrams
  12. Backhaul for Remote SCADA: Microwave, Fiber, Cellular & Satellite
05 Firewalls From packet filtering to NGFW — reading rules and finding the gaps 8 lessons
  1. What Is a Firewall? OT Network Security Explained
  2. Packet Filtering Firewalls: How They Work & Where They Fall Short
  3. Stateful Inspection Firewalls Explained for OT Security
  4. Next-Gen Firewalls in OT Environments: Deep Packet Inspection & IPS
  5. How to Read Firewall Rules & Why Default Deny Matters in OT
  6. Top Firewall Misconfigurations Found in OT Security Assessments
  7. Secure Remote Access for OT Networks: VPNs, Jump Hosts & MFA
  8. Firewall Logging for OT Security: What to Log, What to Watch, and Why
06 Network Visibility Seeing your network safely, without knocking a PLC offline 6 lessons
  1. OT Network Visibility: Why You Can’t Protect What You Can’t See
  2. Why Active Scanning Can Crash OT Devices (And What to Do Instead)
  3. How to Use Ping in OT Networks for Security and Diagnostics
  4. Traceroute for OT Security: Mapping Network Paths and Finding Anomalies
  5. Host Discovery in OT: CLI Commands and Passive Monitoring Platforms
  6. Structured Network Troubleshooting for OT Engineers (Layer by Layer)
07 Bringing It All Together Real attack paths, defence in depth, and your audit checklist 5 lessons
  1. OT Network Security: How All 6 Modules Connect (Defense in Depth Explained)
  2. OT Cyberattack Walkthroughs: Phishing to PLC & Exposed RDP
  3. OT Attack Paths: Legacy Services & Supply Chain Access Scenarios
  4. OT Security Defensive Checklist: What to Audit in Your ICS Network
  5. Actions to Take This Week — Course Wrap-Up

Every module can also be taken on its own. Enroll once and work through the full sequence, or jump straight to segmentation or firewalls if that is what your site needs this quarter.

Enroll and start Module 1

Fit check

Built for the people who keep the process running

This is for you if…

  • You are a control systems, automation, SCADA, instrumentation or plant engineer.
  • You can configure a PLC or an HMI, but a subnet mask has never fully made sense.
  • You are the de facto OT security owner at your site, whether or not it says so on your badge.
  • You are an IT or security professional who has just inherited a plant network.
  • You have an audit, an insurance questionnaire or a regulator asking questions you cannot yet answer.
  • You lead a maintenance or engineering team and want everyone working from one vocabulary.

It is probably not for you if…

  • You are already a network engineer looking for CCNP-level routing and switching depth.
  • You want hands-on offensive tooling or exploit development against ICS protocols.
  • You need vendor-specific configuration training for one particular firewall or PLC platform.
  • You are looking for a compliance-only walkthrough of a single standard rather than the underlying engineering.

Getting started

Three steps, and the first one is free

The course is delivered entirely through the Utah Tech learning platform. Register once and your progress is saved between sessions.

Step one

Create your account

Register at learning.cs.utahtech.edu. It takes a couple of minutes and costs nothing — no purchase, no procurement request, no corporate approval.

Step two

Work through the modules

Fifty-three short lessons, sequenced from fundamentals to attack paths. Watch at your own pace, on your own schedule, on any device. Your place is saved as you go.

Step three

Earn your certificate

Finish the course and receive a certificate of completion from Utah Tech University — something you can put in front of a manager, an auditor or a hiring committee.

Who teaches it

Who teaches this course

Most OT engineers were never taught networking — and are now expected to defend one. This course closes that gap without pretending the plant floor works like an office.

Taught by Utah Tech University faculty

  • Written for OT, not adapted from IT Every concept lands on control-system ground: PLCs that crash under a scan, protocols that cannot authenticate, uptime that outranks patching.
  • Vendor-neutral throughout The principles transfer to whatever hardware is already in your cabinet. Nothing here is a product pitch.
  • Grounded in real incidents Stuxnet, Colonial Pipeline, phishing-to-PLC and exposed RDP are dissected as attack paths — not as headlines.
  • Backed by a university Delivered on Utah Tech University’s learning platform, with a certificate of completion that carries the institution’s name.

Questions

Before you register

What does the course cost?
Nothing. Registration is free, all 53 lessons are free, and the certificate of completion is free. There is no upsell partway through.
Do I need an IT background?
No. The course is explicitly built for OT and ICS professionals with little to no IT background. Module 1 starts at “what is a network” and assumes nothing beyond your existing knowledge of the process side.
How long does it take?
It is fully self-paced across 53 short video lessons. Most learners complete a module in one or two sittings and the full course over a few weeks of ordinary work time. Your progress is saved, so you can stop and pick it back up.
Do I need lab equipment or software?
No. Nothing needs to be installed and no hardware is required. Where the course covers commands like ping and traceroute, it also covers exactly when it is and is not safe to run them on a live control network.
Is it tied to a particular vendor?
No. The material is vendor-neutral. Firewalls, switches, protocols and architecture are taught as concepts you can apply to Rockwell, Siemens, Schneider, Cisco, Fortinet or anything else already installed at your site.
What do I get at the end?
A certificate of completion from Utah Tech University, plus a defensive audit checklist you can take straight back to your own ICS network.
Can I enroll my whole team?
Yes. Registration is individual and free, so each team member can create their own account at learning.cs.utahtech.edu and track their own progress. Working through the same modules gives a maintenance or engineering group one shared vocabulary for talking to IT.
Do I have to take all seven modules?
The sequence is designed to build on itself, and taking it in order is the best way to get the full mental model. That said, the modules stand alone well enough that you can go directly to segmentation or firewalls if that is the pressing problem at your site.

Your control network is already connected.

Start understanding it this week. Fifty-three lessons, seven modules, no cost, and a certificate at the end.

learning.cs.utahtech.edu

On-site delivery Tailored curriculum Whole-team pricing

On-Prem OT/ICS Security Training The same course, brought to your site and built around your own network.

For sites that want their whole team trained together, in person, using examples pulled from their own control network instead of a generic one. We bring the course to you.

No published pricing — every engagement is scoped to your site, team size and schedule.

What's included Scoped per engagement
  • Instructor-led delivery, on-site at your facility
  • Curriculum can be customized
  • Examples and exercises drawn from your own network diagrams
  • Flexible format: single day, multi-day, or a recurring cadence
  • Certificate of completion for every attendee

Email with your team size, site location and timeline, and we’ll put together a plan.

Why on-site

The same curriculum, taught against your own network.

The self-paced course is built for one learner at a time. On-prem training is built for a team, a schedule and a site — with the instructor in the room.

Train the whole team at once

Instead of each engineer working through the course alone, get maintenance, controls and IT-liaison staff in the same room, working from the same material, at the same time.

Built around your architecture

We walk your actual Purdue model, your actual DMZ and your actual firewall rules — not a generic diagram that only half applies to your site.

Answers in the room

Bring the specific incident, the specific vendor connection or the specific firewall rule you’re not sure about, and get an answer from an instructor while it's still relevant.

Getting started

Three steps to get this on your site

There's no self-service checkout for on-prem training — every engagement starts with a conversation about your site and your team.

Step one

Tell us about your site

Email your team size, site location and what you want covered. There's no form to fill out and no procurement process to start yet — just a conversation.

Step two

We build the agenda

Full curriculum or a focused subset — segmentation, firewalls, visibility — mapped to what your site actually needs this quarter.

Step three

We deliver on-site

Instructor-led sessions at your facility, on your schedule, with a certificate of completion for every attendee.

Ready to bring this training on-site?

Tell us about your team and your site, and we’ll put together a plan built around your network.

joe.francom@utahtech.edu

Coming soon St. George, Utah Cohort-based

On-Campus OT/ICS Security Training Take the course in person at Utah Tech University — join the waitlist to be notified when dates are set.

For teams and individuals who’d rather learn in person, away from the plant, alongside other OT professionals. Sessions will be held on Utah Tech’s St. George campus.

No dates are scheduled yet — email to be notified as soon as a cohort is announced.

What to expect Details still forming
  • On-campus, instructor-led sessions
  • Same 7-module, 53-lesson curriculum as the online course
  • Learn alongside other OT/ICS professionals
  • Certificate of completion from Utah Tech University
  • Exact dates, length and cost still being finalized

Join the waitlist and we’ll reach out as soon as a cohort is scheduled.

Why on-campus

The same course, in a classroom instead of a browser tab.

Some people learn better away from the plant floor, in a room with an instructor and other people wrestling with the same problem.

Step away from the plant

A few uninterrupted days focused entirely on the material, without the pager going off or a shift schedule pulling you back to the floor.

Learn alongside peers

Compare notes with other OT/ICS professionals from different sites and industries who are facing the same architecture problems you are.

Same university rigor

Delivered on Utah Tech University’s campus, with the same curriculum and the same certificate of completion as the online course.

Want to be first in line?

We don’t have dates yet, but we’re building the waitlist now. Email us and we’ll reach out the moment a cohort is scheduled.

joe.francom@utahtech.edu

More trainings are in development. We’re building out additional courses beyond OT/ICS network security. Email us if you’d like to be notified when new trainings are released.

Notify me