Getting Started in OT/ICS Cybersecurity 2026 (Part 1): Defending Critical Infrastructure from Attack

Getting Started in OT/ICS Cybersecurity 2026 (Part 1): Defending Critical Infrastructure from Attack

🎙 Mike Holcomb 👥 27K 📅 June 1, 2026 ⏱ 53 min 👁 8K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OTICScybersecuritycritical infrastructureISA/IEC 62443

Summary

This video is the first part of a course on OT/ICS cybersecurity, presented by Mike Holcomb, an experienced professional in the field. It aims to educate viewers on the fundamentals of securing operational technology and industrial control systems, which are critical to modern infrastructure such as power grids, water treatment, and manufacturing. The instructor begins by highlighting the potential consequences of cyber attacks on these systems, emphasizing safety and availability. He then introduces himself, sharing his background and credentials, and discusses the importance of IT and OT convergence, noting that most OT environments are connected to IT networks, creating vulnerabilities. A real-world case study of the Jaguar Land Rover ransomware incident illustrates how attacks on IT can disrupt OT operations. The video also addresses the rise of AI in industrial hacking, demonstrating how AI can interpret HMI screens and assist attackers, lowering the barrier to entry. The course structure is outlined, covering 13 modules that will delve into control systems, protocols, asset management, and defense strategies. The instructor provides an overview of certification paths, including ISA/IEC 62443, SANS courses, and the new CompTIA SecOT+, and offers a career roadmap. The video concludes with information on accessing free labs, scripts, and review materials. Throughout, the emphasis is on raising awareness and education as the primary defense against cyber threats to critical infrastructure.

221 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable introductory information for individuals new to OT/ICS cybersecurity, bridging the gap between IT and OT perspectives. The instructor’s argumentation is solid, grounded in real-world examples and industry frameworks. He effectively communicates the urgency of securing critical infrastructure and the evolving threat landscape, particularly with AI. The argument that awareness and education are the number one problem is compelling and well-supported by examples like the Jaguar Land Rover incident. The course structure is logical, and the inclusion of labs and resources adds practical value. However, the content is introductory and does not delve deeply into technical details, which is appropriate for the target audience but limits its depth for advanced practitioners.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates scientific rigor by referencing established standards and frameworks such as ISA/IEC 62443, SANS courses, and CompTIA SecOT+. The instructor cites real incidents (e.g., Colonial Pipeline, Jaguar Land Rover) to support his points, though he does not provide specific citations or URLs within the video. The title accurately reflects the content, which is a beginner’s guide to OT/ICS security. The instructor includes a legal disclaimer and emphasizes ethical use, adding to the credibility. The video is well-structured with clear chapters, and the instructor’s credentials lend authority. However, the lack of explicit source citations in the video itself may be a minor limitation for viewers seeking to verify claims independently.

240 words

Title / Content Match

The title accurately reflects the content: a beginner-friendly introduction to OT/ICS cybersecurity, focusing on defending critical infrastructure.

Quality & Reliability

8/10

The content is presented by an experienced OT/ICS cybersecurity professional with 15 years in the field and relevant certifications. The video provides a structured introduction to OT/ICS security, referencing established frameworks (ISA/IEC 62443, SANS, CompTIA SecOT+) and real-world incidents. While it is primarily educational and opinion-based, the information aligns with industry best practices and is delivered with appropriate disclaimers about ethical use and authorization.

Chapters

Cited Sources

  • Course Materials (Google Drive) — Referenced as the location for course materials, including cheat sheets, infographics, and review questions.
  • Newsletter Signup — Mentioned as a way to join the instructor's newsletter for more OT/ICS cybersecurity resources.
  • Mike Holcomb on LinkedIn — Provided as a means to connect with the instructor and access his daily content on OT/ICS security.
  • Live Training Schedule — Referenced for information on live training sessions offered by the instructor.

Concurring Sources

  • ISA/IEC 62443 Series — The video references this as the gold-standard framework for OT/ICS security, which is widely recognized in the industry.
  • SANS ICS Security Courses — The video mentions SANS courses (GICSP, GRID, GCIP) as a certification path, which are well-established in the field.
  • CompTIA SecOT+ — The video highlights this new certification as a path for OT security, which is indeed a recent addition to the certification landscape.

Contribution & Novelties

This video provides a comprehensive, accessible introduction to OT/ICS cybersecurity, specifically tailored for 2026, incorporating recent developments such as the rise of AI in industrial hacking and the introduction of the CompTIA SecOT+ certification. It bridges the gap between IT and OT perspectives, emphasizing the need for collaboration. The instructor’s practical approach, including labs and real-world case studies, adds value for beginners. The course structure is well-organized, offering a roadmap for career development.

Pour aller plus loin :

  • ISA/IEC 62443 — The gold-standard framework for industrial automation and control systems security.
  • SANS ICS Security — SANS offers specialized courses like GICSP, GRID, and GCIP for OT/ICS security.
  • CompTIA SecOT+ — The new certification specifically for OT security professionals.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, a key reference.
  • MITRE ATT&CK for ICS — A knowledge base of adversary tactics and techniques specific to ICS.

148 words

Radar Profile

The radar profile shows high scores in information quantity and quality, reflecting the video's comprehensive coverage of OT/ICS basics. The technical level is moderate, suitable for beginners, while reliability is strong due to the instructor's expertise and use of established frameworks. Overall, the video is a solid introductory resource.

Reliability 8/10