SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsThis talk provides insights into designing and executing Tabletop Exercises (TTX) for Incident Response in Industrial Control Systems (ICS) and Operational Technology (OT) environments. It stresses the importance of testing plans, tailoring incident response strategies, and understanding the threat landscape. Key components of an ICS/OT IR plan, such as preparation, identification, containment, eradication, recovery, and lessons learned, are highlighted. Additionally, it emphasizes the significance of TTXs in testing IR capabilities, complying with regulations, and addressing specific challenges unique to ICS/OT environments. The talk covers participants, facilitation methods, scenario design considerations, and post-exercise evaluations to maximize the benefits of TTXs and enhance organizational resilience.
Michael Hoffman teaches ICS410 and ICS612 with a plant floor mindset, turning complex ICS/OT concepts into clear, repeatable practices. Students leave with practical skills that enable them to protect essential services without compromising safety or uptime.
Read more about Michael Hoffman