OT / ICS Security

This course bridges Orbix's established cybersecurity strength into operational technology. It is essential for plants and utilities where IT/OT convergence is accelerating. Participants learn how OT differs from IT, the industrial control-system threat landscape, how to segment networks, and how incident response works when the 'system' is a turbine or a line, not a server.

Operational technology security is not IT security applied to a plant, and the course is built around the differences: availability outranks confidentiality, patching windows may be annual, and equipment lifespans run to decades. Participants work through the architecture of a typical plant environment, the Purdue model and network segmentation, common industrial protocols and why most carry no authentication, and the realities of legacy systems that cannot be patched or scanned. Threats are covered with reference to documented incidents rather than hypotheticals. Practical defence focuses on what is achievable in a running plant: segmentation, monitoring, access control for vendors and remote support, and incident response that accounts for safety systems. Malaysian NCII obligations under the Cyber Security Act 2024 are covered where they apply.

HRD Corp Training Provider MalaysiaHRD Corp SBL-Khas Claimable

Programme Modules

01

IT vs OT Differences

Why patching, availability and safety priorities differ, and why classic IT security playbooks can break a plant.

02

ICS Threat Landscape

Common ICS attack paths, real-world cases (including ransomware on OT), and the assets attackers target.

03

Network Segmentation

Purdue-model zoning, DMZs, and practical segmentation that contains OT risk without stopping production.

04

Incident Response for OT

Detection, containment and recovery when safety and continuity are on the line, plus tabletop thinking for OT scenarios.

Key Outcomes

  • Explain the key differences between IT and OT security
  • Map the ICS threat landscape for your environment
  • Design sensible OT network segmentation
  • Run an OT-aware incident-response plan

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Duration   2 Days

Training Hours   9:00 AM to 5:00 PM

Level   Intermediate

Certificate   None, Orbix own course. It also bridges naturally into Orbix's existing cybersecurity certifications (e.g. CompTIA Security+, ISC2 CC) for those who want an external credential.

Frequently Asked Questions

Yes. OT / ICS Security is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

OT / ICS Security runs for 2 days, 9:00 AM to 5:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

None, Orbix own course. It also bridges naturally into Orbix's existing cybersecurity certifications (e.g. CompTIA Security+, ISC2 CC) for those who want an external credential. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.