Cybersecurity 路 Free

OT Security Assessment: Testing a Plant Without Stopping It

The assessment half of OT security, for engineers who have to do it on a plant that is running. Rules of engagement first, then passive capture, careful enumeration, what an attacker does with a protocol that has no authentication, the Windows machines nobody mentions, the logging that would have caught it, and a report written in the language of consequence.

12 modules 8h 50m of video English 路 self-paced

Inside the course

OT Security Assessment: Testing a Plant Without Stopping It: Syllabus at a glanceOT Security Assessment: Testing a Plant Without Stopping It: What you will be able to doOT Security Assessment: Testing a Plant Without Stopping It: Tools and credits

From the lessons

  • Attacker Methodology | SANS ICS Concepts

    Rules of Engagement: Assessing a Plant That Is Running

    SANS ICS Security

  • 6 Things Not to Do In the Field | SANS ICS Concepts

    Field Rules and the Ground You Are Assessing: Architecture and Segmentation

    SANS ICS Security

  • Modbus Traffic Analysis | SANS ICS Concepts

    Reading the Traffic Before You Send Any

    SANS ICS Security

  • Modbus Enumeration | SANS ICS Concepts

    Enumeration, Carefully

    SANS ICS Security

  • Modbus Man-In-The-Middle | SANS ICS Concepts

    What the Attacker Does Next

    SANS ICS Security

  • MITRE ATT&CK Navigator Overview | SANS ICS Concepts

    Naming What You Found: ATT&CK for ICS

    SANS ICS Security

Lesson frames belong to the creators named in the Credits below and are shown from YouTube.

What you will learn

Write rules of engagement for assessing a system that cannot be stopped; draw and test the zone boundaries that are supposed to exist; capture and read ICS traffic before sending any; enumerate a Modbus endpoint knowing the cost of every request; explain a man-in-the-middle and a forever-day vulnerability and choose compensating controls for a device that will never be patched; assess the engineering workstation and the service accounts on it; leave behind logging and an integrity baseline; decide whether deception is worth its operational cost; review PLC code against the Top 20 Secure PLC Coding Practices; and write a two-page report ordered by consequence that says what you did not test and why.

  • Write rules of engagement with a window, a named owner and an abort condition, for a plant that cannot stop
  • Draw the zones yourself and test each conduit from the side it is meant to protect
  • Capture and read ICS traffic in Wireshark, tshark and Zeek before sending a single packet
  • Enumerate a Modbus device knowing what every request will do, and say when it is not worth the risk
  • Explain a Modbus man-in-the-middle and choose compensating controls for a device nobody will ever patch
  • Map findings to ATT&CK for ICS honestly, and read a real incident as a chain of techniques
  • Assess an engineering workstation: local accounts, services, shares and who can reach it
  • Leave behind Windows logging and an integrity baseline on a host that must never be rebooted
  • Review PLC code against the Top 20 Secure PLC Coding Practices and raise a finding engineering will accept
  • Write the two-page report: scope, method, findings by consequence, and what you deliberately did not test

For you

Taking OT Security Assessment: Testing a Plant Without Stopping It from the United States

The course project 路 about 16 hours

Passive OT security assessment of a running cement plant: DCS, packing PLCs and weighbridges, without a single active scan

Assess the security of a cement plant that cannot be stopped: write the rules of engagement, build the asset inventory from documents, interviews and a mirror-port capture, read the DCS and packing-plant traffic in Wireshark, run CHAPS on the Windows machines with the owner present, review the packing PLC program against the Top 20 Secure PLC Coding Practices, name every finding in ATT&CK for ICS, and write the report ordered by consequence with a 30/90/365-day roadmap. You deliver your own plan, inventory, evidence register, risk register and report. The sample pack shows what an assessor hands to a plant head who has never read one.

Sample document pack, 7 documents, filled in for the scenario

  • PlanAssessment Plan and Rules of Engagement: Beni Suef Plant OT Security Assessment
  • Asset inventoryOT Asset Inventory: Beni Suef Plant, as Found
  • RegisterInterview and Evidence Register
  • Risk registerRisk Register: Cyber Risks on the Plant's HSE Matrix
  • ReportOT Security Assessment Report: Findings by Consequence, Beni Suef Plant
  • PlanRemediation Roadmap: 30, 90 and 365 Days
  • Training recordTraining Record: Running the Roadmap and Repeating the Assessment

Read inside the course and download as a workbook. The project is optional practice, marked when you submit it; the certificate needs only the modules and the final assessment.

Course content

12 modules 路 22 lessons 路 8h 50m

In order, at whatever pace suits you. Each module ends with a practice task that builds on the last.

  1. 01Rules of Engagement: Assessing a Plant That Is Running14m
  2. 02Field Rules and the Ground You Are Assessing: Architecture and Segmentation1h 29m
  3. 03Reading the Traffic Before You Send Any39m
  4. 04Enumeration, Carefully49m
  5. 05What the Attacker Does Next53m
  6. 06Naming What You Found: ATT&CK for ICS24m
  7. 07The Windows Machines Nobody Mentions53m
  8. 08Seeing It Happen: Windows Logging and Integrity Baselines1h 3m

Requirements

Who it is for
Intermediate. You should already know what a PLC, an HMI and a SCADA system are, and how they sit on a network. ICS Security Foundations covers that in five hours if you do not. No penetration testing background is assumed.
Software
Wireshark, a Linux virtual machine, a Modbus simulator or a lab PLC, and CHAPS. All free downloads. Nothing in this course requires a licence or a paid lab. What to download, and how
Hardware
None required. A spare PLC or a Raspberry Pi running a Modbus simulator makes the enumeration and capture work more real, and every exercise is written to work without one.

Software you need

What to download, where from, what it costs and how to install it. Every link goes to the maker's own site, never a mirror.

For a Modbus target, pymodbus runs a simulated Modbus server on the Linux virtual machine, or use a spare lab PLC. Nothing in this course needs a licence or a paid lab.

Required

  1. 01

    Wireshark

    Wireshark Foundation

    Free
    Runs on
    Windows 11 or 10 64-bit (x64 or Arm64), Windows Server 2016 or later, macOS (Universal disk image), Linux
    Account
    None needed

    Free, open source software. No licence fee for any use.

  2. 02

    Oracle VirtualBox

    Oracle

    Free
    Runs on
    Windows, macOS (Intel and Apple Silicon), Linux and Solaris hosts
    Account
    None needed

    The VirtualBox platform packages are free and open source under GPL version 3. The separate Extension Pack is free only for personal and educational use (PUEL licence); business use of the Extension Pack needs a commercial licence from Oracle.

  3. 03

    Ubuntu Desktop

    Canonical

    Free
    Runs on
    64-bit PC (Intel or AMD) or ARM 64-bit. Recommended: 2 GHz dual-core processor, 6 GB RAM, 25 GB free disk space.
    Account
    None needed
    Size
    About 5.9 GB ISO (Intel or AMD 64-bit, current LTS)

    Free to download and use. LTS releases get five years of free security updates, which Ubuntu Pro can extend.

    Alternatives

  4. 04

    CHAPS (Configuration Hardening Assessment PowerShell Script)

    Cutaway Security

    Free
    Runs on
    Windows. chaps_PSv3.ps1 for Windows 8 / Server 2012 and later; chaps_PSv2.ps1 for Windows 7 / Server 2008 R2; chaps.bat when PowerShell is not available.
    Account
    None needed

    Free under the GNU GPL v3; a commercial licence is offered for use inside proprietary products. Reports you generate are not derivative works.

Optional

Useful, not needed to finish the course.

  1. 05

    PyModbus

    pymodbus-dev (open source project), a Python or npm package

    Free
    Runs on
    Windows, macOS and Linux with Python 3.10 or later
    Account
    None needed

    Free, open source under the BSD 3-Clause licence.

Checked against each maker's own page on 27 September 2026. Trial lengths and editions change; the maker's page is the final word.

OT Security Assessment: Testing a Plant Without Stopping It at a glance

OT Security Assessment: Testing a Plant Without Stopping It is a free, self-paced online course from EDWartens for automation, OT and IT engineers responsible for security. It has 12 modules and 8h 50m of video lessons by SANS ICS Security, with written notes and worked problems, a practical project with a document pack and a 15-question final assessment (pass mark 60%). Learning is free with an account; an optional certificate with a public verification code is issued when you pass. Last updated 27 September 2026.

All course facts
Price
Free, for good. No trial, no card. The only paid item is the optional certificate, a small one-off fee.
Who it is for
Automation, OT and IT engineers responsible for security
Format
12 self-paced modules, 8h 50m of video, written notes, a practice task per module and one final assessment.
Level
Intermediate. Intermediate. You should already know what a PLC, an HMI and a SCADA system are, and how they sit on a network. ICS Security Foundations covers that in five hours if you do not. No penetration testing background is assumed.
Brand
Vendor-neutral
Software
Wireshark, a Linux virtual machine, a Modbus simulator or a lab PLC, and CHAPS. All free downloads. Nothing in this course requires a licence or a paid lab.
Hardware
None required. A spare PLC or a Raspberry Pi running a Modbus simulator makes the enumeration and capture work more real, and every exercise is written to work without one.
Certificate
Optional EDWartens Certificate of Completion, verifiable by code. Not a vendor credential.
Video lessons by
SANS ICS Security (independent creators, credited below)
Language
English
Last updated
27 September 2026

A shareable EDWartens certificate

Finish every module and pass the final assessment, and the optional EDWartens certificate is yours. It carries a unique verification code on a public page anyone can check, so it stands up when a recruiter looks it up. See it below.

The course itself stays free whether or not you ever buy one.

Stuck? Ask a practising engineer

A free course usually means a comment section and hope. This one does not. Every module has an Ask-your-trainer panel that reaches the same engineers who teach our paid programme: people who commission panels for a living, not moderators.

Pairs well with

More free courses: Free cyber security courses 路 Free OT and ICS security courses

Learner reviews

No reviews yet

Reviews here are written only by learners who have finished every module of OT Security Assessment: Testing a Plant Without Stopping It, and they are published exactly as written. Finish the course and yours will be the first.

Common questions

Is this a hacking course?

No. It is an assessment course, and the difference matters on a plant. It teaches you to evaluate systems you are authorised to evaluate, for the people who own them, and the first module is entirely about the permission, the window and the condition under which you stop. There is no exploit development here and nothing is aimed at systems you do not own. Where the course covers what an attacker does, such as a Modbus man-in-the-middle, it does so because you cannot defend or assess a protocol whose weaknesses you have not seen.

How is it different from the OT and ICS Cybersecurity course?

That course is the standards and programme side: ISA/IEC 62443 clause by clause, security levels, risk assessment, governance. It is forty-four hours. This one is the practical assessment: what you actually do in the four days you are on site, in the order that keeps the plant running. They complement each other and neither repeats the other. If you have done neither, ICS Security Foundations is the five-hour place to start.

Do I need a lab, or a real PLC?

No. Every exercise is written to work with a free Modbus simulator on a laptop and a Linux virtual machine. A spare PLC or a Raspberry Pi running a simulator makes the capture and enumeration work feel real, and several people find that worth the effort, but nothing in the course assumes you have one.

Do I need penetration testing experience?

No, and the course is deliberately not written for penetration testers moving into OT. It is written for automation engineers who already understand plants and are being asked to assess them, which is the more common situation on real plants and the one that is worse served.

Is this a SANS course, or does it lead to a GIAC certification?

No. Every video lesson is from the SANS ICS Security channel's free ICS Concepts series, credited on each module, and SANS is not affiliated with EDWartens. SANS run their own paid courses and GIAC issue their own certifications; this course is neither and does not count towards either. What EDWartens wrote is the study plan, the objectives, the practice tasks, the notes and the assessments.

What will I have at the end?

A two-page assessment report on a system you chose, with scope, method, findings ordered by consequence, and a section naming what you deliberately did not test. That report is the deliverable of the course and is the thing worth showing an employer, more than the certificate is.

Is the OT Security Assessment course really free?

Yes. Every module, every practice task and the final assessment. You create an account so your progress is saved and the assessment can be marked. The only paid item is the certificate, and only if you decide you want it.

What certificate does the OT Security Assessment course give?

An EDWartens Certificate of Completion, issued when you have worked through every module and passed the final assessment, with a unique number anyone can verify on our site. It is not a vendor or industry credential and we will never describe it as one.

What you walk away with

Your certificate for OT Security Assessment: Testing a Plant Without Stopping It

Finish the course, pass the final, and this is the document with your name on it.

Sample EDWartens Certificate of Completion for OT Security Assessment: Testing a Plant Without Stopping It
Sample. The issued certificate carries your name, admission number, a unique certificate number and its own QR code.
  • Verifiable by anyone

  • Adds to LinkedIn in one click

  • QR code on the certificate

  • Names what you can do

  • A permanent link

  • Earned, not attended

Learning is free. The certificate is optional.

Add it now and pay only when you have finished the course, or come back for it later. One-off, US$28.99, with a receipt.

Issued by EDWartens, the training division of Wartens, as a Certificate of Completion for this self-paced course. Sold by Wartens Ltd (England and Wales). It is not a vendor certification, a university award or a CPD-accredited activity, and it does not certify competence on live equipment. Delivered electronically; see the refund policy.

Credits

Who made the video lessons

The video lessons in this course were created by the people below, not by EDWartens. Every lesson streams from its creator's own YouTube channel; EDWartens neither hosts nor sells that footage, and the creators are not affiliated with EDWartens and do not endorse this course. What EDWartens wrote is the study plan, the notes, the practice tasks and the assessments.

  • SANS ICS Securitythe entire ICS Concepts series that this course is built from: attacker methodology, field practice, network architecture, Modbus traffic analysis, enumeration and man-in-the-middle, Zeek, ATT&CK Navigator, Windows hardening and logging, integrity baselining, honeypots, the Top 20 Secure PLC Coding Practices, CHAPS and cyber informed engineering

If you are one of these creators and would like a lesson removed or credited differently, write to info@wartens.com.