Earn your next certification, guaranteed!

SCADA/ICS Security Training Boot Camp

Learn the best practices for securing SCADA networks and systems. This boot camp teaches you how to defend against both internal and external attackers to provide holistic security for critical industrial automation systems.

Earn your CSSA, guaranteed!

Boot camp overview

From the power grid to water treatment facilities, SCADA controls our nation’s mission critical infrastructure. Infosec’s ICS/SCADA Boot Camp builds your homeland security skills by teaching you how to assess and secure SCADA systems — and you’ll gain hands-on experience on the latest threats via our SCADA Cyber Range.

You’ll learn everything from field-based attacks to automated vulnerability assessments for SCADA networks. The boot camp also prepares you to pass the CSSA certification exam and become a Certified SCADA Security Architect.

Skill up and get certified, guaranteed

Exam Pass Guarantee

If you don’t pass your exam on the first attempt, get a second attempt for free. Includes the ability to re-sit the course for free for up to one year.

100% Satisfaction Guarantee

If you’re not 100% satisfied with your training at the end of the first day, you may withdraw and enroll in a different Flex Pro or Flex Classroom course.

Knowledge Transfer Guarantee

If an employee leaves within three months of obtaining certification, Infosec will train a different employee at the same organization tuition-free for up to one year.

What's included

93% pass rate — the best in the industry

  • Five days of training with an expert instructor
  • Infosec digital courseware (physical textbooks available to purchase)
  • Certified SCADA Security Architect (CSSA) exam voucher
  • 90-day access to SCADA Cyber Range (Flex Pro)
  • 90-day access to course replays (Flex Pro)
  • Curated videos from other top-rated instructors (add-on)
  • 100% Satisfaction Guarantee
  • Exam Pass Guarantee (Flex Pro)

Hands-on labs

Dozens of exercises in the SCADA Cyber Range bring you up to speed with the latest threats. Take the knowledge you learn and apply it to real-world scenarios to build your SCADA security skills.

Award-winning training that you can trust

Rising Star

Partner Award

G2 Crowd Leader

Technical Skills Development Software

Gold Winner

Best Cybersecurity Education Provider

Publisher's Choice

Security Training for Infosec Professionals

Top 20 Company

IT Training

Who should attend?

  • SCADA system operators
  • SCADA analysts
  • Control systems engineers
  • ICS and SCADA consultants
  • IT and security professionals with a desire to learn how to protect critical infrastructure

Prerequisites

  • Understanding of computer hardware and operating systems
  • Basic knowledge of SCADA systems

Why choose Infosec

Your flexible learning experience

Infosec Flex makes expert, live instruction convenient with online and in-person formats tailored to how, when and where you learn best.

Public training boot camps held nationwide

  • Pre-study course materials
  • Live instruction
  • Digital courseware
  • Daily reinforcement materials
  • Catered lunches
  • Infosec community forum access
  • 100% Satisfaction Guarantee
  • Knowledge Transfer Guarantee

Most Popular

Immersive, live-streamed instruction

  • Pre-study course materials
  • Live instruction
  • Digital courseware
  • Daily reinforcement materials
  • Detailed performance reporting
  • Video replays
  • 90-day extended access to materials
  • Infosec community forum access
  • Exam Pass Guarantee
  • 100% Satisfaction Guarantee

Tailored team training at your location

  • Pre-study course materials
  • Live, customized instruction at your location
  • Digital courseware
  • Daily reinforcement materials
  • Detailed team performance reporting
  • Video replays
  • 90-day extended access to materials
  • Infosec community forum access
  • Exam Pass Guarantee
  • 100% Satisfaction Guarantee
  • Knowledge Transfer Guarantee

Course objectives

This boot camp prepares you to properly secure the SCADA systems used in a variety of industries, including power transmission, oil and gas and water treatment. You’ll build your knowledge and skills needed to successfully pass the CSSA exam, including:

  • SCADA security policy development
  • SCADA security standards and best practices
  • Access control
  • SCADA protocol security issues
  • Securing field communications
  • User authentication and authorization
  • Detecting cyber-attacks on SCADA systems
  • Vulnerability assessment

Industry-leading exam pass rates

We don’t just have great instructors, our instructors have years of industry experience and are recognized as experts. Over the past 15 years, we’ve helped tens of thousands of students get certified and advance their careers.

Our industry-leading curriculum and expert instructors have led to the highest pass rates in the industry. More than 93% of Infosec students pass their certification exams on their first attempt.

Can’t get away for a week?

Learn SCADA on-demand.

Get the cybersecurity training you need at a pace that fits your schedule with a subscription to Infosec Skills. Includes unlimited access to hundreds of additional on-demand courses — plus cloud-hosted cyber ranges where you can practice and apply knowledge in real-world scenarios — all for just $34 a month!

  • 400+ courses
  • 4 cyber range environments
  • 100+ hands-on labs
  • Certification practice exams
  • 50+ learning paths

You're in good company.

"I’ve taken five boot camps with Infosec and all my instructors have been great."

Jeffrey Coa

Information Security Systems Officer

"The course not only met my expectations, but exceeded them. It was the most engaging online training I’ve ever had."

Val Vask

Commercial Technical Lead

"I knew Infosec could tell me what to expect on the exam and what topics to focus on most."

Julian Tang

Chief Information Officer

Our clients

FedEx
Microsoft
Bank of America
Defense Information Systems Agency
Symantec

Find your boot camp

SCADA/ICS Security Boot Camp details

Part 1
SCADA/ICS Overview

  • Introduction to CSSA
  • Industrial Control Systems (ICS)
  • Types of ICS
  • ICS components
  • BPCS & SIS
  • Control system strengths and weaknesses
  • ICS PCN & protocols
  • PCN evolution
  • Modbus / DNP3 / HART
  • Lab: Modbus PLC
  • IT vs. ICS
  • RS-232 and RS-485
  • TASE 2.0 / ICCP
  • CIP
  • PROFIBUS / PROFINET
  • FOUNDATION fieldbus
  • Open vs. proprietary protocols
  • HMI applications
  • HMI/OIT implementations
  • OPC and OPC UA
  • Data historians
  • Integration software (ERP/MES)

Part 2
SCADA security governance

  • Threat to SCADA
  • SCADA attacks and threats case studies
  • Lab: Attacking the infrastructure
  • SCADA security challenge
  • Security frameworks, strategy, policies
  • Standards, procedures and guidelines
  • SCADA security standards bodies (NIST / ISA / CFATS / NERC CIP)
  • Risk management process
  • Lab: “Theoretical” assessment with CSET
  • SCADA security assessment methodology
  • NESCOR guide to vulnerability assessment

Part 3
Pentesting SCADA systems

  • Security assessment strategy
  • Pentesting steps
  • Safety and security considerations
  • Information gathering
  • Architecture analysis
  • Host, application and platform fingerprinting
  • DNS and SNMP recon
  • Lab: SNMP recon
  • Host and port scanning
  • Security considerations
  • Scanning tools and techniques
  • Lab: Scanning ICS/SCADA networks
  • Network communications capture and analysis
  • RF signal capture
  • Sniffing network traffic
  • Device functionality analysis
  • Lab: Datasheet analysis
  • Vulnerability identification
  • Common SCADA vulnerabilities
  • Finding vulnerabilities
  • Physical access
  • Vulnerability scanning
  • Server OS testing
  • Patch levels
  • Default and insecure configurations
  • Authentication and remote access
  • Firmware analysis
  • Attacking ICS
  • Attacking standard services (HTTP, FTP)
  • Attacking server OS
  • Lab: Exploiting OS-level vulnerabilities (Shellshock exploit)
  • Attacking ISC Protocols
  • Lab: Capturing and manipulating protocol data
  • Attacking wireless communications
  • Lab: Recovering ZigBee network keys
  • Lab: WEP/WPA2 password cracking

Part 4
SCADA security controls

  • Categorization of system controls
  • Physical security & safety
  • Identification, Authentication & Authorization (IA&A)
  • IA&A and access control
  • Remote access security
  • Encryption
  • Logical security
  • Lab: Firewall rule design
  • Monitoring, detection and protection
  • Secure SCADA architecture
  • Lab: Security architecture (group discussion)
  • IDS/IPS (Introduction to Snort)
  • Log monitoring and management
  • Lab: SCADA honeypot (Conpot)
  • Lab: Snort SCADA rules (Quickdraw)
  • Incident response
  • Anti-malware
  • Application whitelisting
  • Patch management
  • Active Directory and group policy
  • Summary of good security practices