Getting Started in OT/ICS Cybersecurity 2026 (Part 2): What is OT/ICS Cybersecurity?

Getting Started in OT/ICS Cybersecurity 2026 (Part 2): What is OT/ICS Cybersecurity?

🎙 Mike Holcomb 👥 27K 📅 July 2, 2026 ⏱ 119 min 👁 3K 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OTICSSCADAPurdue ModelCybersecurity

Summary

This video is a comprehensive tutorial on OT/ICS cybersecurity, aimed at beginners. It begins by defining OT and ICS, emphasizing that safety is the top priority in these environments, unlike traditional IT. The instructor explains the differences between IT and OT, highlighting the importance of deterministic traffic and the Purdue Model for network segmentation. He covers key concepts such as the IT/OT DMZ, the distinction between ICS and SCADA, and the roles of asset owners and operators. The video includes a historical overview of major OT cyber incidents, from Maroochy Sewage and Stuxnet to the Colonial Pipeline and recent Ukraine heating attacks, illustrating the evolution of threats. Practical demonstrations show PLC hardware and attack simulations, and the instructor discusses how AI tools can be used for both offensive and defensive purposes. He emphasizes the need for collaboration between IT and OT teams and outlines basic security controls. The video concludes with a preview of upcoming labs and resources for further learning.

161 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides substantial value by demystifying OT/ICS cybersecurity for newcomers, using clear explanations and real-world examples. The argumentation is solid, grounded in the instructor’s extensive experience and documented incidents. He effectively argues that safety is paramount and that IT and OT must collaborate to secure critical infrastructure. The demonstrations and case studies strengthen the credibility of the claims, though some points could benefit from more rigorous sourcing.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is high for an introductory tutorial. The instructor references well-known incidents and frameworks (e.g., Stuxnet, Purdue Model) and provides practical demonstrations. However, he does not cite formal academic sources, relying instead on industry knowledge and personal experience. The title accurately reflects the content, which is a foundational overview. The video’s structure is logical, and the technical details are accurate, though simplified for accessibility.

149 words

Title / Content Match

The title accurately reflects the content, which serves as an introductory tutorial on OT/ICS cybersecurity.

Quality & Reliability

8/10

The video provides a comprehensive and technically accurate overview of OT/ICS cybersecurity, grounded in real-world incidents and practical demonstrations. The author demonstrates deep expertise and references reputable sources (e.g., Dragos, Stuxnet). Minor limitations include a lack of formal citations and some oversimplifications for educational purposes.

Key Moments

Cited Sources

  • Course Materials — Access to course materials including labs and resources.
  • Mike Holcomb LinkedIn — Instructor's professional profile for further connection.
  • Newsletter Signup — Join the instructor's newsletter for updates and resources.
  • Live Training Schedule — Information on live training sessions offered by the instructor.

Concurring Sources

  • Dragos Threat Intelligence — The instructor references Dragos for information on the Ukraine heating attack, aligning with industry threat reports.

Contribution & Novelties

This video provides a comprehensive and accessible introduction to OT/ICS cybersecurity, filling a gap for beginners. It uniquely combines theoretical concepts with practical demonstrations and real-world case studies, making it a valuable starting point. The instructor’s emphasis on safety as the primary driver and the use of AI in both attack and defense are particularly timely.

Pour aller plus loin :

  • Purdue Model — The foundational reference model for IT/OT network segmentation.
  • Stuxnet — A landmark cyberweapon targeting industrial control systems, essential for understanding OT threats.
  • NIST SP 800-82 — Guide to Industrial Control Systems (ICS) Security, providing detailed security guidance.

101 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, with a moderate technical level and good reliability. This indicates a well-rounded educational resource that is both informative and trustworthy, though it may not delve deeply into advanced technical details.

Reliability 8/10