Keeping the Lights On: A Training Course in Critical Infrastructure Cybersecurity
1Summary
When a cyberattack takes down a power grid, a water treatment plant, or a hospital's systems, the damage isn't measured in data loss alone — it's measured in disrupted lives. This Training Course from Arab British Fellowship Training Academy is built around that reality, giving professionals in energy, healthcare, transportation, and utilities the practical skills to defend the systems society depends on every day.
From industrial control systems and SCADA environments to national-level incident response, the course covers the full picture: how attacks on critical infrastructure unfold, the frameworks used to prevent them, and the governance structures that keep protection efforts coordinated across public and private sectors.
2Objectives and target group
Learning Outcomes
- Understand the cyber risks specific to critical infrastructure sectors and how they differ from conventional IT risk.
- Apply security measures tailored to Industrial Control Systems (ICS) and SCADA environments.
- Use recognized frameworks, including NIST, ISO 27001, and CIS, to structure a critical infrastructure security program.
- Build and test an incident response plan for large-scale attacks on essential systems.
- Understand the governance, legal, and public-private coordination required to sustain long-term protection.
Who Should Attend?
- Cybersecurity specialists working in the critical infrastructure sector.
- IT managers and professionals responsible for securing vital infrastructure.
- Security engineers and architects designing secure critical systems.
- Risk management professionals in energy, healthcare, utilities, and transportation.
- Policymakers involved in national infrastructure protection strategy.
3Course Content
Module 1: What Makes Critical Infrastructure Different
- Defining critical infrastructure sectors and why their interdependence raises the stakes.
- Historical examples of cyberattacks on infrastructure and their real-world impact.
- Core principles and governance frameworks for protection.
Module 2: The Threat Landscape Facing Essential Systems
- Advanced Persistent Threats (APTs), state-sponsored attacks, and insider risk.
- Cybersecurity challenges unique to Industrial Control Systems (ICS) and SCADA.
- Emerging and evolving attack vectors targeting operational technology (OT).
Module 3: Risk Management and Business Continuity
- Risk assessment and vulnerability management tailored to critical systems.
- Business continuity planning and disaster recovery for essential services.
- Building a structured cybersecurity risk management framework.
Module 4: Securing the Network and Controlling Access
- Network security, segmentation, and remote access protection for critical systems.
- Role-based access control (RBAC), multi-factor authentication, and privileged access management.
- Securing Industrial IoT (IIoT) devices and sensors within OT networks.
Module 5: Modern Defense Architectures
- Zero Trust Architecture (ZTA) applied to critical infrastructure.
- Using AI and machine learning to detect threats before they escalate.
- SIEM systems, incident detection, and building a resilient, fault-tolerant infrastructure.
Module 6: Standards, Regulation, and Working Across Sectors
- International standards, such as ISO 27001 and NIST, and sector-specific requirements.
- National policy, legal obligations, and the role of government and private-sector partnerships.
- Conducting cybersecurity audits and using them to drive continuous improvement.
Module 7: Planning for the Next Generation of Threats
- Aligning cybersecurity strategy with organizational goals and regulatory frameworks.
- The impact of 5G, smart cities, and connected infrastructure on future risk.
- Preparing governance and strategy for the cybersecurity demands of the next decade.