Group Purchasing
Group Purchasing

Build Stronger Cyber Defences for CIIOs with SANS Training, Supported by CSA

CSA Singapore

With the support of Cyber Security Agency of Singapore (CSA), Critical Information Infrastructure Owners (CIIOs) can access world-class SANS training designed to strengthen cybersecurity capabilities across critical digital and operational environments. Choose from specialised IT Track and OT Track pathways to build the expertise needed to defend against evolving cyber threats and enhance organisational resilience.

In line with the Cybersecurity Code of Practice’s emphasis on ensuring that employees who operate and manage CII systems have the necessary cybersecurity competencies to perform their roles effectively, CSA is working with training providers to strengthen the capabilities of CII cybersecurity practitioners. This training equips cybersecurity practitioners with the skills to effectively secure CII systems. 

Courses and Certifications

Course Overview:

Sophisticated attackers know how to blend their activity into normal enterprise operations, making a compromise difficult to uncover through conventional monitoring alone. Evidence of an intrusion may be spread across endpoints, memory, event logs, file systems, authentication activity, and other data sources. Effective investigation requires more than finding individual indicators, it requires the ability to connect these traces, understand attacker behavior, reconstruct the intrusion, and determine the true extent of the compromise. This course provides a comprehensive, hands-on approach to Digital Forensics, Incident Response, and Threat Hunting across enterprise environments. Beginning with threat actor behavior, attack chains, Cyber Threat Intelligence, and MITRE ATT&CK, the six-day course progresses through malware persistence, evidence of execution, event log analysis, lateral movement, memory forensics, and timeline analysis. You will learn to connect individual artifacts, identify attacker techniques, reconstruct intrusions, and determine the scope and impact of a compromise.

Bringing these capabilities together, the course focuses on enterprise-wide threat hunting and intelligence-driven investigations. You will assess preventive and detective controls, develop threat hunts based on adversary behavior, investigate advanced malware and forensic evidence, and apply structured incident response techniques from initial discovery through recovery. AI-assisted approaches are also introduced to support investigative and response workflows. By the end of the course, you will have a practical methodology for hunting, investigating, and responding to sophisticated intrusions, and for turning lessons from each incident into stronger detection, better defenses, and more effective response. 

This course also equips participants with the knowledge and practical skills needed to prepare for GIAC Certified Forensic Analyst (GCFA).

Download the course brochure

Course Fee: SGD $11,100*

  • SGD $5,550.00* - For Singapore Citizens and Permanent Residents after SkillsFuture Subsidy
  • SGD $5,100.00* - For Singapore Citizens >= 40 years old after SkillsFuture Mid-Career Enhanced Subsidy
  • SGD $5,100.00* - Enhanced Training Support for SMEs for Singapore Citizens and Permanent Residents

*Fees stated are exclusive of GST. Please note that payable fees will be subjected to 9% GST.

Locations and Dates:

  • Grand Copthorne Waterfront Hotel, Singapore | 5-10 Oct, 2026

This Course Will Help You To:

  • Analyse APT groups, understanding their geopolitical motivations, sector targeting, and campaign histories.

  • Apply the MITRE ATT&CK framework to identify and map APT and other adversary tactics, techniques, and procedures.

  • Execute hypothesis-driven threat hunting methodologies to proactively search for indicators of compromise.

  • Design and evaluate secure network architectures using network segmentation, zero trust principles, and defence-in-depth strategies.

  • Understand key preventive and detective controls and cyber hygiene for detecting and defeating advanced adversaries

  • Develop incident response procedures for organisations, including maintaining business continuity.

  • Apply forensics techniques including memory analysis, log examination, and network traffic analysis.

  • Establish IT recovery procedures prioritising critical business systems, and implement preventive hardening measures.

Course Overview:

Industrial Control Systems (ICS) and Operational Technology (OT) environments are facing increasingly sophisticated cyber threats that can disrupt critical operations and impact safety, reliability, and business continuity. Securing these environments requires cybersecurity professionals with a strong understanding of industrial systems, emerging threats, and effective defence strategies. This course provides participants with the essential knowledge and practical skills to protect ICS/OT environments, from establishing foundational security principles and maintaining operational resilience to gaining network visibility, detecting threats, responding to incidents, and applying intelligence-driven approaches to cyber defence. Participants will develop the capabilities needed to safeguard industrial operations against current and evolving cyber threats while supporting a safer and more resilient operational environment.

This course also equips participants with the knowledge and practical skills needed to prepare for GIAC Response and Industrial Defense (GRID).

Download the course brochure

Course Fee: SGD $11,700*

  • SGD $5,850.00* - For Singapore Citizens and Permanent Residents after SkillsFuture Subsidy
  • SGD $5,700.00* - For Singapore Citizens >= 40 years old after SkillsFuture Mid-Career Enhanced Subsidy
  • SGD $5,700.00* - Enhanced Training Support for SME's for Singapore Citizens and Permanent Residents

*Fees stated are exclusive of GST. Please note that payable fees will be subjected to 9% GST.

Locations and Dates:

  • Grand Copthorne Waterfront Hotel, Singapore | 30 Nov – 5 Dec 2026

This course will help you to:

  • Analyse APT groups, understanding their motivations, targets, and attack methods to better defend critical infrastructure.
  • Apply the MITRE ATT&CK framework to map APT and other attacker techniques.
  • Integrate Operational Technology (OT) threat intelligence with IT security operations.
  • Design secure network architectures using principles like network segmentation, zero trust, and layered defences.
  • Conduct OT asset inventories and map connections between IT and OT systems using the Purdue Model and understanding OT-specific systems.
  • Assess risks in OT environments, identifying vulnerabilities in industrial protocols and legacy systems commonly targeted by APT groups in critical infrastructure.
  • Implement security controls for OT environments, including network separation, data diodes, patch management for operational systems, and secure remote access.
  • Harden industrial control systems whilst maintaining operational availability against APT persistence techniques.
  • Configure OT monitoring tools in industrial protocols and identify APT threats.
  • Develop incident response plans for OT environments.
  • Investigate OT security incidents using structured techniques and map findings to the MITRE ATT&CK for ICS frameworks.
  • Establish procedures to safely restore OT systems after APT incidents.

Build Your Cybersecurity Skills Today

Take the next step in your cybersecurity journey with SANS training, supported by CSA. Contact us at singapore@sans.org to learn more about the two tracks and register with us today.

Register Interest

Q&A

Critical Information Infrastructure Owners (CIIOs) in Singapore face cyberattacks from state-sponsored threat actors. Understanding the risks and how to address them is critical to their mission and to Singapore’s national security. SANS, with the support of Cyber Security Agency of Singapore (CSA), has developed the Practitioner Technical Programme (SANS): Advanced Persistent Threat Detection and Response for IT Environment course to help CIIOs prepare. This course is based on the FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics curriculum, modified to address the unique challenges Singapore CIIOs face and support them in ensuring that employees who operate and manage CII attain the cybersecurity competencies necessary to perform their roles effectively, in line with CSA’s Cybersecurity Code of Practice for Critical Information Infrastructure 2026. The program consists of 3.5 days of FOR508 material and 2.5 days of custom material designed to CSA’s specifications, including a DFIR NetWars exercise to demonstrate participants’ hands-on defensive skills.

Attendees will learn to process cyber threat intelligence and implement intelligence-driven, advanced persistent defense of their IT networks. They will examine how threat actors target network appliances, hypervisors, fleet management systems, and endpoints, and the visibility challenges these attacks present. Effective approaches to detect, respond, and recover from cyberattacks are provided, with deep technical practice on responding to attacks within a Windows environment.

Participants will also receive access to the OnDemand version of the full FOR508 course materials as part of the IT track course. They may also choose to opt for the GIAC Certified Forensic Analyst (GCFA) certification exam, please contact us at Singapore@sans.org for more information.

Built on the ICS515: ICS Visibility, Detection, and Response curriculum, this course has been tailored to address the specific needs of Singapore CIIOs and support them in ensuring that employees who operate and manage CII attain the cybersecurity competencies necessary to perform their roles effectively, in line with CSA's Cybersecurity Code of Practice for Critical Information Infrastructure 2026. Across six days, participants will work through core ICS515 content, custom material developed to CSA's specifications, and close out the course with a GRID NetWars exercise to put their hands-on defensive skills to the test.

Where this course differs from the standard ICS515 is its emphasis on foundational operator knowledge before diving into detection and response. Attendees will first learn ICS processes, roles, and industries, including controllers and field devices, HMIs, historians, SCADA systems, and core networking concepts, along with the key differences between IT and ICS environments. From there, the course covers building an ICS security program, addressing frameworks such as the SANS 5 Critical Controls and IEC 62443, policy development and implementation, risk measurement, enforcement zone devices, cryptography, wireless defenses, and Windows/Unix/Linux defense strategies. This is reinforced through the participants building a Programmable Logic Controller and operating the process themselves, giving them direct, hands-on operational experience.

Participants will also receive access to the OnDemand version of the full ICS515 course materials as part of the OT track course. They may also choose to opt for the GIAC Response and Industrial Defense (GRID) certification exam, please contact us at Singapore@sans.org for more information.

Yes. The two tracks are separate programmes and you're welcome to take both. Taking both is a natural fit if your role spans converged IT and OT environments.

No. While the programme is supported by CSA with CII cybersecurity practitioners in mind, enrolment is open to anyone interested in the training. Practitioners from non-CIIO organisations are welcome to register.

You can opt for either self-sponsored or employer-sponsored under SkillsFuture funding. For more information on SkillsFuture funding, please refer to the following:

Only self-sponsored learners can use SkillsFuture Credit to offset the fees for the courses and GIAC certification attempt. Self-sponsored learners may use their own SkillsFuture Credit in addition to the SkillsFuture funding they receive, applying it against the remaining fee payable after funding/subsidy.

At the point of course registration, you should inform us that you intend to use your SkillsFuture Credit in part or in full for the qualifying course fee. You should then submit your claim on the MySkillsFuture Portal before the course start date. For more information on SkillsFuture Credit, refer here.

You can attend either In-Person or Live Online, subject to scheduling availability for the run you're registering for. Both tracks also include the OnDemand Bundle as part of the course.

IT/OT Track for CSA – Customized Course | SANS Institute