OT training

In Partnership With:

Academic Excellence. Practical Capability. Professional Confidence.

Developed and delivered by Hacktonics and independently accredited by The Cyber Scheme, this specialist training programme combines world-class academic expertise with practical, hands-on learning designed for real operational environments.

Founded by leading cyber security academics from the University of Bristol, Hacktonics has built a reputation for delivering immersive training that develops genuine technical capability. Through The Cyber Scheme’s accreditation framework, delegates can be confident that the course has been independently reviewed against recognised standards for quality, relevance and professional practice.

Whether you are developing specialist expertise, strengthening organisational capability, or investing in workforce resilience, this programme has been designed to deliver knowledge that can be applied in the real world.

Why This Course Is Different

Too often, cyber security training is either highly theoretical or heavily tool-focused.

This programme has been developed around a different principle: effective learning should combine technical depth, practical experience and professional credibility.

Hacktonics brings extensive experience in cyber security research, education and hands-on industrial cyber security training. The company was founded by academics from the University of Bristol and has gained national recognition for its innovative approach to developing cyber security capability.

The Cyber Scheme independently accredits the programme through its Training Centre Accreditation framework, providing additional assurance that course design, delivery and learning outcomes meet recognised expectations for professional development.

The result is a training experience that combines academic rigour, practical relevance and independent quality assurance.

About Hacktonics

Hacktonics specialises in hands-on cyber security training for industrial and operational technology environments. Its founders and instructors have spent decades developing cyber security education, test environments and specialist training programmes, helping organisations build capability in some of the most challenging areas of cyber security. The company was founded by academics from the University of Bristol and was recognised nationally after winning the Cyber Den competition at CYBERUK 2026.

Built by Experts Who Understand Both Research and Practice

One of Hacktonics’ greatest strengths is its ability to bridge the worlds of academic research and operational reality. The team has spent decades developing cyber security knowledge, training programmes and practical environments that help learners understand not only how attacks occur, but how systems can be protected in practice.

That experience is reflected throughout the course, from the structure of the learning programme to the exercises and scenarios delegates will encounter. Participants benefit from training informed by cutting-edge cyber security research while developing skills that are directly relevant to the challenges faced by organisations today. Combined with The Cyber Scheme’s independent accreditation framework, this creates a learning experience that is both technically rigorous and professionally relevant.

Train in a realistic industrial environment

Delegates gain hands-on experience using Hacktonics’ specialist Lab-in-a-Box Industrial Control System training equipment and LINICS operational technology security platform.
The training environment includes Programmable Logic Controllers (PLCs), Human Machine Interfaces (HMIs), industrial protocols and specialist OT security tools. Practical exercises enable delegates to explore asset discovery, vulnerability assessment, protocol analysis and attack impact within realistic industrial environments.

training pathway

A structured learning journey

The Hacktonics training pathway has been designed to develop capability progressively, from foundational understanding through to advanced operational technology security testing.

Together, these programmes provide a clear progression pathway for individuals and organisations seeking to build operational technology security capability. From foundational understanding through to advanced technical assessment, each course is designed to develop practical skills that can be applied directly within real-world environments.

Delivered by Hacktonics and independently accredited by The Cyber Scheme, the pathway combines academic expertise, hands-on technical learning and professional assurance, helping organisations build the specialist skills needed to protect critical infrastructure and industrial systems.

Each course combines technical content with practical exercises using LINICS and specialist industrial control system training environments, allowing participants to apply concepts in realistic scenarios.

OT Security Testing – Foundations Half-Day Course

The Foundations course provides an introduction to operational technology security for cyber security professionals looking to expand their knowledge beyond traditional IT environments. Designed for those with existing IT security experience, it introduces the technologies, systems and security challenges commonly encountered within industrial control systems.

Through a combination of expert instruction, demonstrations and practical exercises, participants gain an understanding of OT environments, how they differ from traditional IT networks, and the security risks organisations must address to protect critical operations. Hands-on sessions using Hacktonics’ specialist training environments enable learners to apply concepts immediately and gain confidence working within operational technology settings.

By the end of the course, delegates will have a clear understanding of operational technology security concepts, common vulnerabilities, security testing approaches and the practical impact cyber attacks can have on industrial systems.

Key topics include:

  • Introduction to Industrial Control Systems (ICS) and Operational Technology (OT)
  • OT security case studies and real-world challenges
  • Security testing methodologies for OT environments
  • Asset discovery techniques and tools
  • Protocol and device vulnerabilities
  • HMI exploitation demonstrations
  • Practical exercises using industrial protocols
  • Introduction to LINICS and Hacktonics ICS training boxes.

Pentesting Operational Technology (OT) Systems – Practitioner Two-Day Course

The Practitioner course builds on the Foundations programme and provides structured, hands-on training in the methodologies, techniques and processes used to assess the security of operational technology environments. Designed for security professionals seeking to move beyond theory and into practical assessment, the course provides a detailed understanding of how OT penetration tests are planned, executed and reported.

Delegates work through realistic assessment scenarios while gaining experience in asset discovery, vulnerability identification, security control analysis and attack investigation. Extensive laboratory exercises provide opportunities to apply the techniques being taught and develop the practical skills needed to conduct structured OT security assessments.

The programme is aimed at practitioners who already possess a foundational understanding of industrial control systems and want to develop the capability to evaluate the security posture of operational technology environments in a safe, systematic and professional manner.

By the end of the course, participants will understand the stages of an OT penetration test, how to establish and assess security baselines, how attacks exploit vulnerabilities within industrial systems, and how security controls can be implemented to improve resilience.

Key topics include:

  • Anatomy of an OT penetration test
  • Scope definition and rules of engagement
  • OT-specific reporting and best practice
  • Asset discovery and vulnerability scanning
  • Open-source intelligence sources including Shodan
  • Establishing and evaluating security baselines
  • Security control assessment
  • Industrial protocol exploitation
  • PLC attack techniques and defensive considerations.

Operational Technology Security Testing – Advanced Three-Day Course

The Advanced course is designed for experienced OT security practitioners who want to deepen their technical knowledge and develop expertise in advanced operational technology security testing. Building on the concepts introduced at Practitioner level, the programme explores the architectures, protocols, devices and attack techniques that underpin modern OT security assessments.

The course takes a deeper technical look at how vulnerabilities emerge within industrial systems and how security testing can be used to identify weaknesses that may affect safety, reliability and operational continuity. Delegates gain practical experience investigating sophisticated attack techniques, assessing their impact and exploring security architecture approaches that can be used to reduce organisational risk.

In addition to advanced testing methodologies, the programme examines how operational technology security aligns with broader regulatory and industry expectations, helping participants understand both the technical and strategic considerations involved in protecting critical infrastructure environments.

By the end of the course, delegates will have developed a deeper understanding of OT security protocols, industrial devices, end-to-end attack scenarios, security architecture principles and the techniques required to identify and mitigate complex security risks within operational technology environments.

Key topics include:

  • Advanced OT protocol analysis
  • Security weaknesses within OT protocol stacks
  • Deep dives into Modbus, S7Comm, OPC UA and related technologies
  • PLC architectures and advanced attack techniques
  • HMI architectures and associated vulnerabilities
  • End-to-end OT attack modelling
  • Safety and operational impact assessment
  • Security architecture design
  • NIS/NIS2 requirements
  • NCSC Cyber Assessment Framework
  • ISO/IEC 62443 principles and implementation considerations.

MEET THE INSTRUCTORS

Professor Awais Rashid

Professor Awais Rashid has more than 40 years’ experience in cyber security and extensive expertise in Industrial Control Systems security, research and training.

He has led cyber security research and development programmes exceeding £50 million, established specialist MSc programmes at Lancaster University and the University of Bristol, developed industrial control system testbeds and currently serves as Editor-in-Chief of the Cyber Security Body of Knowledge (CyBOK).

Dr Joe Gardiner FHEA

Dr Joe Gardiner specialises in Industrial Control Systems security research and teaching. He leads development of the University of Bristol’s ICS security testbed and has experience delivering practical ICS security education and vulnerability research in collaboration with industry.

Joe is a Fellow of Advance HE, recognising attainment against the UK Professional Standards Framework for teaching and learning support in higher education.

"This partnership brings together the research excellence of one of the UK's leading cyber security academic teams and the independent assurance of The Cyber Scheme to deliver training that is academically rigorous, practically relevant, and professionally recognised."

Please note: These courses are not intended for complete beginners with no prior cyber security experience.

These courses are designed for:

  • Penetration testers
  • Security consultants
  • Security engineers
  • Critical infrastructure security professionals
  • Technical cyber security practitioners seeking to develop OT capability.

 

Participants should have:

  • Experience in IT security
  • Familiarity with Linux command line
  • Working knowledge of Python
  • Foundational knowledge of networking concepts.

FAQs

This training has been independently reviewed through The Cyber Scheme’s Training Accreditation framework. Accreditation reviews course structure, delivery approach, learning outcomes and relevance to professional practice. 

LINICS® is a Linux-based platform developed specifically for Industrial Control Systems security professionals. It combines specialist OT security tools, including tools developed by Hacktonics, alongside selected general-purpose cyber security tools.

Tools are mapped to MITRE ATT&CK for ICS, helping delegates understand attack techniques and operational impacts within industrial environments.

No. The Foundations course is designed for cyber security professionals with IT security experience who are new to Operational Technology. Practitioner and Advanced courses assume increasing levels of OT knowledge or equivalent experience.

Not necessarily. Delegates may enter at Practitioner or Advanced level if they can demonstrate equivalent knowledge and experience.

No specialist equipment is required. Laptops and software are provided.

The training takes place in a fully equipped training centre at The Cyber Scheme, Eagle Tower, Montpellier Drive, Cheltenham, Gloucestershire GL50 1TA.

Yes. Organisations interested in multiple places should contact The Cyber Scheme to discuss team bookings. This is consistent with the campaign positioning around organisational capability building.  

Yes. Please contact The Cyber Scheme before the course so that any access requirements or reasonable adjustments can be discussed.

Training rooms are accessible via lift. Accessible parking can be arranged for Blue Badge holders.