Getting Started in OT/ICS Cybersecurity 2026 (Module 4): What They Don't Say About OT Protocols

Getting Started in OT/ICS Cybersecurity 2026 (Module 4): What They Don't Say About OT Protocols

🎙 Mike Holcomb 👥 27K 📅 August 11, 2026 ⏱ 167 min 👁 1K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

ModbusSiemens S7WirelessHARTMQTTOPC UA

Summary

This module from Mike Holcomb’s OT/ICS cybersecurity course focuses on industrial network protocols, explaining their operation, security weaknesses, and practical implications. It begins with an overview of legacy serial protocols like Modbus RTU and DNP3, highlighting their lack of security and the risks introduced by serial-to-Ethernet gateways. The OSI model is explained as a framework for understanding network communication, and packet analysis with Wireshark is introduced. The module then delves into Modbus TCP, including a simulated attack on a conveyor belt system, and analyzes captured traffic. It covers the proprietary Siemens S7 protocol, discussing its security challenges. WirelessHART is presented for instrumentation, and the limitations of MQTT in field environments are examined, emphasizing the need for OPC UA or Sparkplug B for full functionality. The importance of securing OPC UA with certificates and encryption is stressed. Throughout, the focus is on how attackers can exploit protocol vulnerabilities and how to mitigate these risks.

153 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides substantial value by demystifying OT protocols and their security implications. It offers practical insights from the author’s experience, such as finding serial-to-Ethernet gateways with default passwords during penetration tests. The argumentation is solid, explaining why legacy protocols are insecure and how they are adapted to TCP/IP without adding security. The author effectively argues that the most critical vulnerabilities in OT environments stem from protocol design flaws rather than specific CVEs. The use of real-world examples, like the water treatment tank overflow scenario, strengthens the argument. However, some claims are anecdotal and not backed by external sources, but the overall reasoning is coherent and well-structured.

Scientific Rigor, Source Quality, Title Accuracy

The content demonstrates strong technical rigor, with accurate explanations of protocols and network concepts. The author cites his own experience and references industry-standard resources, but does not provide formal citations. The title accurately reflects the content, focusing on OT protocols and their security aspects. The video is well-organized with clear chapters, enhancing its educational value. The author’s credibility is established through his professional background, though the lack of external references limits the verifiability of some claims. Overall, the scientific rigor is high for a tutorial format, but it is not a peer-reviewed source.

215 words

Title / Content Match

The title accurately reflects the content, which focuses on OT protocols and their security implications, including aspects not commonly discussed.

Quality & Reliability

8/10

The content is technically accurate and based on the author's extensive experience in OT/ICS security. It covers fundamental protocols and security risks with practical examples. However, it is a tutorial and not peer-reviewed, and some claims (e.g., about specific attacks) are anecdotal.

Chapters

Cited Sources

Concurring Sources

  • Modbus Protocol — Confirms the lack of security in Modbus and its widespread use.
  • OPC UA — Supports the discussion on securing OPC UA with certificates and encryption.

Contribution & Novelties

This module provides a comprehensive and practical overview of OT protocols, emphasizing security implications that are often overlooked. It bridges the gap between legacy serial protocols and modern TCP/IP-based systems, offering actionable insights for engineers and cybersecurity professionals. The inclusion of real-world attack scenarios and packet analysis adds practical value.

Pour aller plus loin :

  • Modbus Protocol — Foundational reference for understanding Modbus variants and their security.
  • OPC UA — Overview of OPC Unified Architecture and its security features.
  • MQTT — Explanation of MQTT’s publish-subscribe model and its limitations in industrial settings.
  • Wireshark — Official site for the network protocol analyzer used in the video.
  • Siemens S7 Protocol — Background on the proprietary S7 protocol.

115 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and technical level, indicating a well-rounded and informative tutorial. The fiabilite_globale is also high, reflecting the author's expertise, though the lack of external citations slightly reduces the overall reliability score.

Reliability 8/10