Pre-DEFCON Session: Getting Started in OT/ICS Cybersecurity

Pre-DEFCON Session: Getting Started in OT/ICS Cybersecurity

🎙 Mike Holcomb 👥 27K 📅 August 1, 2026 ⏱ 46 min 👁 544 📄 tutorial 🧭 2026-08-16
Available in: English (current) Français

Keywords

OTICSSCADAPLCcybersecurity

Summary

This session, presented by Mike Holcomb, is a pre-DEFCON talk aimed at individuals interested in starting a career in OT/ICS cybersecurity. The speaker begins by explaining what OT/ICS is, using the FrostyGoop incident as a motivating example, where a Russian state group disrupted heating for 600 apartment buildings in Ukraine. He then contrasts OT with IT, emphasizing the safety-critical nature of OT environments. The talk covers fundamental concepts such as PLCs, HMIs, and the control loop, and discusses how attackers can exploit these systems, including via IT-OT connections and simple attacks like flooding fake sensor data. Holcomb highlights the importance of safety over availability, integrity, and confidentiality in OT. He provides guidance for career changers: IT professionals should learn to think like engineers, while engineers should learn IT networking and cybersecurity basics. He recommends resources such as his own free YouTube courses, Idaho National Labs training, and standards like NIST 800-82 and ISA/IEC 62443. He also suggests gaining hands-on experience through platforms like LabShock and networking with the community on LinkedIn. The session concludes with advice to stay current and a list of thought leaders to follow.

187 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for beginners, as it provides a clear overview of OT/ICS cybersecurity, including real-world examples and practical career advice. The speaker’s argumentation is solid, supported by his extensive experience and references to well-known incidents and standards. However, the talk is introductory and promotional, lacking deep technical detail. The argumentation is persuasive but relies heavily on anecdotal evidence and the speaker’s own authority.

77 words

Title / Content Match

The title accurately reflects the content: a session aimed at beginners in OT/ICS cybersecurity, covering foundational concepts and career advice.

Quality & Reliability

8/10

The speaker is an experienced OT/ICS cybersecurity professional with 20 years in IT security and over 60 hours of free training content. The session provides practical guidance and references established frameworks (NIST 800-82, ISA/IEC 62443) and real-world incidents (FrostyGoop, Colonial Pipeline, Triton). However, it is a promotional and introductory talk, not a peer-reviewed source, and some claims (e.g., ChatGPT creating attack tools in seconds) are anecdotal.

Key Moments

Cited Sources

  • NIST SP 800-82 — Mentioned as a key standard for OT security.
  • ISA/IEC 62443 — Described as the gold standard for building OT security programs.
  • Mike Holcomb's website — Referenced as a resource hub for infographics, courses, and links.
  • Mike Holcomb's YouTube channel — Mentioned as hosting over 60 hours of free training content.

Concurring Sources

  • NIST SP 800-82 — Provides guidelines for securing industrial control systems, aligning with the speaker's recommendations.
  • ISA/IEC 62443 — The international standard for OT security, consistent with the speaker's emphasis.

Contribution & Novelties

The session provides a practical, beginner-friendly introduction to OT/ICS cybersecurity, emphasizing the safety-first mindset and the importance of understanding the differences between IT and OT. It offers concrete career advice and resources, making it valuable for those transitioning from IT. The talk also highlights recent incidents and the evolving threat landscape, including AI-enabled attacks.

Pour aller plus loin :

  • NIST SP 800-82 — The primary standard for securing industrial control systems.
  • ISA/IEC 62443 — The international standard for OT security.
  • LabShock — An open-source platform for hands-on OT security training.
  • Dragos — A leading OT security firm that provides threat intelligence and incident reports.
  • SANS ICS — Offers specialized training and certifications in ICS security.

115 words

Radar Profile

The radar profile shows high scores in information quality and reliability, reflecting the speaker's expertise and use of established standards. The technical level is moderate, suitable for beginners, and the quantity of information is substantial for a 46-minute talk. The overall profile indicates a well-rounded introductory resource.

Reliability 8/10

💬 No comments were provided for analysis.