Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference

Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville.

Hands on ICS Training

This October, SecurityWeek, in partnership with MTSI, will offer the Cyber Attack Methods (CAM) course for the second consecutive year as part of the 25th Anniversary Industrial Control Systems (ICS) Cybersecurity Conference.

Understanding how adversaries compromise cyber-physical systems requires more than reading threat reports or reviewing lists of attack techniques. Defenders must understand how attackers examine a system, identify opportunities and connect individual weaknesses to achieve a larger operational objective.

The multi-day, hands-on course will take place October 6–8 at the W Nashville alongside the special 25th anniversary edition of the ICS Cybersecurity Conference.

Learning to Think Like an Attacker

Cyber-physical systems connect digital components with equipment and processes in the physical world. A successful attack against these environments can extend far beyond the loss of data or temporary system downtime, potentially affecting safety, mission readiness, productivity, revenue and the availability of essential services.

CAM is designed to help participants understand how those attacks unfold by placing them directly in the role of an adversary.

Working inside an intentionally vulnerable virtual cyber-physical environment, students will progress through system discovery, vulnerability exploitation and the execution of mission-focused attacks. Rather than discussing adversary behavior only in theory, participants will work through the attack process with their hands on the keyboard.

Advertisement. Scroll to continue reading.

The objective is not to turn students into hackers. It is to give the people responsible for designing, building, testing and protecting cyber-physical systems a practical understanding of how attackers think and operate.

Participants will learn how adversaries enumerate systems, identify and exploit weaknesses, and combine individual actions to create meaningful operational consequences. They will also evaluate possible mitigations and consider how architecture, development and security decisions can reduce attack surfaces and make systems more resilient.

Built for More Than Cybersecurity Teams

While security practitioners can benefit from the course, CAM is particularly relevant for the broader community responsible for cyber-physical systems—including systems engineers, security engineers, programmers, developers, designers and testers.

That broader audience is important because many decisions that ultimately determine whether a system can withstand an attack are made before it enters production. Engineers and developers who understand adversary methods are better positioned to recognize risky assumptions, anticipate unexpected attack paths and incorporate security into system design and testing.

No previous cybersecurity experience is required. The guided course is intended to make the material accessible to participants from different technical backgrounds, although familiarity with the Linux command line and some programming experience will help students get the most from the exercises.

MTSI’s cyber-physical systems team brings experience in hacking, reverse engineering and penetration testing across mission-critical aviation, maritime, weapons and defense systems. Team members also conduct cyber-physical security research and have competed successfully in prominent hacking competitions, including DEF CON’s ICS Village and Biohacking Village capture-the-flag events.

Training and Conference Access in One Registration

The CAM course begins with a full day of instruction on Tuesday, October 6, followed by half-day sessions on Wednesday and Thursday. The schedule allows participants to attend sessions from the broader ICS Cybersecurity Conference when training is not underway.

The $3,995 registration fee includes:

  • The complete Cyber Attack Methods training course
  • A self-contained virtual machine containing the CAM simulation, exercises and lesson content
  • A certificate of course completion
  • Access to ICS Cybersecurity Conference sessions
  • Conference meals, networking events and social functions — full conference pass.

Students may retain the course virtual machine after the event, allowing them to revisit the exercises and continue learning beyond the classroom.

Participants must bring an Intel-based laptop capable of running the required virtual machine. ARM-based MacBooks are not supported. The course is available exclusively to United States citizens.

Seats for this immersive training are limited. Engineers, developers, testers and security professionals who want to move beyond abstract descriptions of cyber-physical attacks and experience the attack process for themselves are encouraged to register as soon as possible.

The 2026 ICS Cybersecurity Conference takes place October 6-8 at the W Nashville, bringing together operations and control engineers, IT and OT security professionals, government representatives, researchers, vendors and critical infrastructure operators for SecurityWeek’s 25th anniversary industrial cybersecurity event.

Written By

For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is founder and director of several leading cybersecurity industry conferences around the world.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.

Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer.

Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.