OT Cyber Tuesday (Ep. 4) - What Would I Do DIFFERENTLY in Starting in OT/ICS Cybersecurity Today?

OT Cyber Tuesday (Ep. 4) - What Would I Do DIFFERENTLY in Starting in OT/ICS Cybersecurity Today?

🎙 Mike Holcomb 👥 27K 📅 November 5, 2025 ⏱ 68 min 👁 665 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT/ICScybersecuritycareer adviceCISA coursescommunity

Summary

In this episode of OT Cyber Tuesday, Mike Holcomb shares his personal journey into OT/ICS cybersecurity, starting with his fascination with Stuxnet in 2010. He emphasizes the lack of resources at that time and the frustration he faced. He then outlines five key recommendations for those starting in the field today. First, he advises taking advantage of free courses, particularly those offered by CISA, which are available online and include hands-on training at Idaho National Labs. Second, he stresses the importance of joining the OT/ICS cybersecurity community, especially through LinkedIn and YouTube, to learn from others and accelerate career growth. Third, he recommends reading and researching widely, as the field is constantly evolving. Fourth, he suggests building practical skills through hands-on projects, such as using Raspberry Pi or Arduino, or more realistic PLCs like the Click PLC, and utilizing virtualized environments like LabShark and GRFICS. Finally, he emphasizes the importance of continuous learning and staying updated with industry trends. Throughout the session, he answers viewer questions about network security monitoring tools (Dragos, Claroty, Nozomi), active scanning risks, and course recommendations. He also mentions his own YouTube course and a SANS webinar he is conducting. The session is informal and interactive, with a focus on practical advice for newcomers.

208 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable, practical advice for individuals entering OT/ICS cybersecurity, drawing on the speaker’s extensive experience. The argumentation is based on personal anecdotes and industry knowledge, which adds credibility but lacks formal evidence. The speaker effectively explains the differences between IT and OT security, emphasizing the importance of understanding both. He also addresses common misconceptions, such as the over-reliance on CVEs without considering the operational context. The advice is actionable, with specific resources mentioned, such as CISA courses and virtualized environments. However, the discussion is somewhat unstructured, with frequent tangents and viewer questions, which may dilute the main points. Overall, the value lies in the practical, real-world insights shared, though the argumentation could be more systematic.

Scientific Rigor, Source Quality, Title Accuracy

The speaker demonstrates a good understanding of the subject, but the scientific rigor is moderate. He references reputable sources like CISA and SANS, but does not provide formal citations or links in the video. The title accurately reflects the content, as the speaker indeed shares what he would do differently. The video is an opinion piece rather than a research-based presentation, which limits its scientific rigor. However, the practical advice is grounded in the speaker’s experience and aligns with industry best practices. The adéquation between title and content is strong, and the speaker’s credibility adds to the overall reliability.

231 words

Title / Content Match

The title accurately reflects the content, as the speaker shares his personal journey and advice for newcomers in OT/ICS cybersecurity.

Quality & Reliability

7/10

The speaker is an experienced OT/ICS cybersecurity practitioner, providing practical advice and referencing reputable resources like CISA courses and SANS. However, the content is largely anecdotal and lacks formal citations or peer-reviewed sources.

Key Moments

Cited Sources

  • CISA Training — Mentioned as free courses for OT/ICS cybersecurity.
  • SANS ICS Security — Mentioned as a resource for courses and community.
  • AutomationDirect Click PLC — Recommended as a cost-effective PLC for hands-on learning.
  • LabShark — Mentioned as a virtualized environment for OT security practice.
  • GRFICS — Mentioned as a virtualized environment for OT security practice.

Concurring Sources

  • CISA's ICS Training — Aligns with the speaker's recommendation for free training.
  • SANS ICS Security — Supports the speaker's mention of SANS as a resource.

Contribution & Novelties

The video offers a personal perspective on entering OT/ICS cybersecurity, which is valuable for newcomers. It consolidates practical advice and resources in one place, making it a useful starting point. The speaker’s emphasis on community and continuous learning is particularly insightful. However, the content is not groundbreaking, as similar advice can be found in other forums. The main novelty is the speaker’s personal journey and the specific resources he recommends.

Pour aller plus loin :

  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, provides foundational knowledge.
  • Purdue Model — Reference architecture for ICS, useful for understanding network segmentation.
  • MITRE ATT&CK for ICS — Knowledge base of adversary tactics and techniques specific to ICS.

116 words

Radar Profile

The radar profile shows a balanced distribution across all dimensions, with slightly higher scores in information quality and reliability, reflecting the speaker's experience and practical advice. The lower score in technical depth suggests the content is more introductory than advanced.

Reliability 7/10

💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.