This course walks security professionals and engineers through a single realistic incident, from both the attacker's and the defender's seat, built around the 2026 coordinated cyberattacks on American water utilities.
Students first use an internet-scanning tool to find and fingerprint an internet-exposed PLC (using OpenPLC as a stand-in for the real controllers targeted in the actual incident), connect to it with the vendor's own engineering software, and disrupt the physical process it controls, reproducing techniques mapped to MITRE ATT&CK for ICS (T0883, T0886, T0859, T0843, T0816, T0827/T0826).
Students then switch to defending: they trace and cut the unmanaged cellular connection that let the attacker in, restore the controller from a known-good backup, and rebuild remote access safely behind an authenticated, least-privilege VPN tunnel. Along the way the course covers why ICS equipment ends up exposed to the internet in the first place, how to respond safely and in the right order during a real incident, and the practical hazards of active network scanning on live OT systems, closing with a full crosswalk of the course content to NIST CSF 2.0, SP 800-53, and the NICE Framework.
Internet-Exposed PLCs: Lessons from the 2026 Water Attacks
Enrollment options
Hours: 1.5