New course helps against cyber attack

April will welcome the UK’s first ever hands-on InfoSec course designed specifically for IT professionals charged with securing critical national infrastructure and related industries. The new course from SANS Institute follows an increase in cyber attack aimed at delivering kinetic payloads.

SANS SEC562: CyberCity Hands-on Kinetic Cyber Range Exercise will make its European debut in London from April 27th to May 2nd. The 6 day course includes hands on digital representation of a city and commonly found real world systems used across a wide range of computers, networks, programmable logic controllers and underlying protocols that operate most of the physical infrastructure used by key UK utilities, oil and gas, military and industrial automation.
“There has been an assumption that cyber-attacks are all about targeting banks and retailers for monetary gain but for many years, critical national infrastructure has been under constant attack without generating the headlines or media hype,” explains Tim Medin, course co-author and certified SANS instructor.

“The motivations of the attackers are not so clear cut anymore – we are seeing a type of asymmetric warfare where actors including hacktavists, disgruntled employees and in some cases nation states that cannot mount a direct attack, instead aim to cause real-world damage without the spotlight of notoriety or risk of arrest.”
Medin points to incidents including a steel mill in Germany, a gas pipeline in Turkey and the infamous Stuxnet attack on nuclear facilities in Iran as examples of cyber-attacks that have led to severe kinetic damage. “Increasingly, organisations are using sophisticated IT to improve the efficiency of electrical grids, water treatment and even traffic lights but these interconnections can leave highly computerised nations vulnerable to attacks that cause an incredibly damaging ripple effect.”
Medin also highlights the challenges for the teams tasked with protecting these systems. “One of the fundamental problems for defenders is that these systems are complex and highly specialised and often in place for several decades.  The skill needed to design and implement best practice security in these environments is scarce and even making small changes to live systems is a daunting process.
There is an element of risk as the consequences of mistakes can literally turn-the-lights-out.”

The new course includes a 1:87 scale miniaturised physical city that features ICS-controlled electrical power distribution, as well as water, transportation, hospital, bank, retail, and residential infrastructures. The software systems used by these infrastructure models are real and the course is weighted towards hands on exercises to help students understand the processes attackers use to gain control, helping them to better defend these targets.
The course includes modules that focus on network reconnaissance, protocol manipulation, ICS switching and power grid manipulation. However, the course also looks at operator interface terminals and the human elements such as the targeting of key individuals through social networking and intelligence gathering. The course is rounded off by a red-team/blue-team mock cyber battle within the CyberCity to put theory into a practical arena for attack and defence scenarios.
“It may sound like overkill but the reality is that every year, more of our infrastructure is becoming connected and automated and if we fail to properly train the people who we ask to defend these systems, then eventually we will have a ‘Titanic moment’ and then it will be too late.”

“Part of the challenge is to change the mind-set away from complacency towards an active defence,” says Medin, “The debut of this course in Washington last year reached 100% capacity in days of registration and the attendees were a diverse mix of senior staff across the entire spectrum of infrastructure as well as military and governmental.”
“The feedback we had was amazing and this first UK session has also had a huge amount of forward interest and we urge that participants register as soon as possible to secure a place,” Medin adds.
SEC562: CyberCity Hands-on Kinetic Cyber Range Exercise will take part within SANS ICS London 2015. The annual event will also run the foundation ICS410: ICS/SCADA Security Essentials course and two hosted courses on “Assessing and Exploiting Control Systems” and “Critical Infrastructure and Control System Cybersecurity”. 
For more information, please visit: www.sans.org/ics-london-2015/  or email [email protected]

Georgina Turner image

Georgina Turner

Sales Manager

Read the Latest Issue

Follow us on X

Follow us on X

Click Here

Follow us on LinkedIn

Follow us on LinkedIn

Click Here

Advertise here

Reach decision makers and amplify your marketing

Advertise here

Click Here

Related News

Graphic displaying a lockdown solution

Netgenium debuts next gen display and touchscreen technologies

Power-over-Ethernet (PoE) solutions specialist Netgenium will be showcasing its new range of IP…

ICT® Launches New TSL Access Reader Series

Integrated Control Technology (ICT®), a leading manufacturer of intelligent access control and…
Image Provided by Paxton

Paxton Partners with Skills for Security

The security technology manufacturer Paxton is proud to announce a partnership with Skills for Security…
Image Provided by ICT

ICT and Ingram Micro sign distribution agreement MEA

Integrated Control Technology (ICT), award-winning global manufacturer of intelligent electronic access control and security solutions..
Image Provided by Toshiba

Toshiba launches new HDD Innovation Lab

Toshiba Electronics Europe GmbH (Toshiba) has inaugurated a new HDD Innovation Laboratory (HDD Innovation Lab) at its site in Düsseldorf..
Image Provided by Verkada

Verkada Doubles Down on the Channel with Strategic New Hire

Verkada, a leader in cloud-based physical security, today announced the appointment of Micah Deriso as Head of Global Channel…
Image Provided by IPSA

IPSA Appoint Frontline Hero as Ambassador

Abdullah, the courageous security officer praised for foiling a horrific knife attack at Leicester Square, has been appointed as…
Image Provided by Codelocks

New Surface Latch from Codelocks

Codelocks is expanding its Gate Solutions by Codelocks range with the introduction of the new Codelocks’ Surface Latch…
Image provided by Genetec

Nicholas Smith to Lead Genetec UK and Ireland Operations

Genetec, provider of enterprise physical security software, announced the appointment of Nicholas Smith as its new Regional Sales Director…
Scroll to Top