SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis talk provides insights into designing and executing Tabletop Exercises (TTX) for Incident Response in Industrial Control Systems (ICS) and Operational Technology (OT) environments. It stresses the importance of testing plans, tailoring incident response strategies, and understanding the threat landscape. Key components of an ICS/OT IR plan, such as preparation, identification, containment, eradication, recovery, and lessons learned, are highlighted. Additionally, it emphasizes the significance of TTXs in testing IR capabilities, complying with regulations, and addressing specific challenges unique to ICS/OT environments. The talk covers participants, facilitation methods, scenario design considerations, and post-exercise evaluations to maximize the benefits of TTXs and enhance organizational resilience.
Mike is a SANS Technology Institute graduate, earning his master’s degree in information security engineering with an Industrial Control Systems focus. Besides his work at Dragos, Inc. he teaches ICS612: ICS Cybersecurity In-Depth at SANS.
Read more about Michael Hoffman