Skip to content

Programs

AI-guided Training for the people who already run operations.

Each program has built-in training environments for every layer of OT resilience.

Your operators work through it on the systems the company already has, and the data that layer needs is collected by them as they learn.

Start with how the plant actually runs.

Your people already know the plant. The programs build on that, and collect what is out there, how it connects, and what changed.

Your operators & systems

Judgment calls · Historians · PLCs & SCADA

What the programs train

What matters · What to isolate · What to escalate

What your operators collect

Asset & connection records · Change evidence · Incident timelines

Three layers of OT resilience.

Each layer is a training environment, and each is drawn as an asterism: a handful of units your operators work through, anchored on one bright star. Visibility is Taurus, whose eye is Aldebaran. Seeing comes first, and the other two follow it.

VISIBILITYTAURUSHARDENINGORIONRESPONSECANIS MAJOR

Layer 1 · Taurus · 6 units

Visibility

You can't secure what you can't see, and most OT networks were never mapped on purpose.

The Visibility program trains your operators to build that picture themselves: an inventory of assets, protocols and communication paths across the plant floor, checked against what engineering drawings and historians already say is out there, and recorded in the systems you already have.

Asset & network inventories · Protocol & traffic baselines · Finding shadow connections

Getting Started in ICS/OT Cyber Security

ICS/OT Cyber Security Overview

What does this plant actually control, and what happens if it stops?

Getting Started in ICS/OT Cyber Security

Control Systems & Industrial Protocols

Which controllers talk to which, and in what language?

Getting Started in ICS/OT Cyber Security

Asset Inventory & Asset Registers

What is actually out there, and who owns it?

Getting Started in ICS/OT Cyber Security

OSINT for Industrial Control Systems

What can an outsider already learn about your plant?

Why Is This Still Here? Judgment in Aging OT

What OT is, and why it isn't IT

Where does the process end and the network begin?

Why Is This Still Here? Judgment in Aging OT

Why is this connection still here?

Who needs this link, and what breaks if it goes?

Layer 2 · Orion · 6 units

Hardening

Patching a PLC on a running line is rarely realistic, so hardening has to work with the process, not against it.

The Hardening program trains the people who live with those constraints to judge segmentation, compensating controls and remote-access paths, so that when the hardening plan is made, it is made by people who know what the line can take.

Zones & conduits · Compensating controls for legacy assets · Remote access for vendors

Getting Started in ICS/OT Cyber Security

ICS/OT Attacks & Secure Architecture

Where would an attacker be stopped, and by what?

Getting Started in ICS/OT Cyber Security

Threat & Vulnerability Management

Which weaknesses matter when you can't patch the line?

Getting Started in ICS/OT Cyber Security

Securing Remote Access

Who gets in from outside, and through which door?

Getting Started in ICS/OT Cyber Security

Penetration Testing ICS/OT

How far can a test go without touching production?

Why Is This Still Here? Judgment in Aging OT

The Purdue model: levels, zones and conduits

Which levels are allowed to talk, and which links are hopping?

Why Is This Still Here? Judgment in Aging OT

Revisiting design motivations

Does the reason for this rule still exist?

Layer 3 · Canis Major · 5 units

Response

An alert nobody trusts is worse than no alert at all.

The Response program trains your operators to read the detection you already have, to run a playbook under pressure, and to rehearse it before the incident that actually needs them. Your operators already know what they check before a change, and how they decide something is safe to run. The programs build on that judgment, and the records your operators gather along the way stay in your systems.

Reading OT alerts · Incident response playbooks · Tabletop exercises with your team

Getting Started in ICS/OT Cyber Security

Incident Detection & Response in OT

Would you notice, and who acts first?

Getting Started in ICS/OT Cyber Security

Risk, Governance & Compliance

Which risks does the business accept, and who signed for them?

Getting Started in ICS/OT Cyber Security

Review & Your Path Forward

What do the next ninety days look like?

OT Cyber Prioritization Under Fire

Prioritization Under Fire

When everything changes at once, what comes first?

OT Cyber Prioritization Under Fire

Practitioner Q&A

How have others argued for this, and won?