Course Weighs Attackers' View of Cyber-Physical Systems
SecurityWeek and MTSI repeat hands-on CAM training at the 25th ICS Cyber Security Conference.
For defenders of industrial control systems, the gap between knowing an attack is possible and understanding how one actually unfolds can be wide. A hands-on course returning to this year's ICS Cybersecurity Conference aims to close that gap by putting students in the attacker's position.
Hands-on Training Returns
SecurityWeek, in partnership with MTSI, will offer the Cyber Attack Methods (CAM) course for the second consecutive year as part of the 25th Anniversary Industrial Control Systems (ICS) Cybersecurity Conference. The multi-day, hands-on course is scheduled for October 6-8 at the W Nashville, running alongside the special anniversary edition of the conference.
Understanding how adversaries compromise cyber-physical systems requires more than reading threat reports or reviewing lists of attack techniques, the course's organizers argue. Defenders must understand how attackers examine a system, identify opportunities, and connect individual weaknesses to achieve a larger operational objective.
Learning to Think Like an Attacker
Cyber-physical systems connect digital components with equipment and processes in the physical world. A successful attack against these environments can extend far beyond the loss of data or temporary system downtime, potentially affecting safety, mission readiness, productivity, revenue, and the availability of essential services.
CAM is designed to help participants understand how those attacks unfold by placing them directly in the role of an adversary. Working inside an intentionally vulnerable virtual cyber-physical environment, students will progress through system discovery, vulnerability exploitation, and the execution of mission-focused attacks. Rather than discussing adversary behavior only in theory, participants will work through the attack process with their hands on the keyboard.
Practical Understanding, Not Hacker Training
The objective is not to turn students into hackers. It is to give the people responsible for designing, building, testing, and protecting cyber-physical systems a practical understanding of how attackers think and operate. Participants will learn how adversaries enumerate systems, identify and exploit weaknesses, and combine individual actions to create meaningful operational consequences.
They will also evaluate possible mitigations and consider how architecture, development, and security decisions can reduce attack surfaces and make systems more resilient.
Built for More Than Cybersecurity Teams
While security practitioners can benefit from the course, CAM is particularly relevant for the broader community responsible for cyber-physical systems—including systems engineers, security engineers, programmers, developers, designers, and testers.
That broader audience is important because many decisions that ultimately determine whether a system can withstand an attack are made before it enters production. Engineers and developers who understand adversary methods are better positioned to recognize risky assumptions, anticipate unexpected attack paths, and incorporate security into system design and testing.
No Prior Experience Required
No previous cybersecurity experience is required. The guided course is intended to make the material accessible to participants from different technical backgrounds, although familiarity with the Linux command line and some programming experience will help students get the most from the exercises.
MTSI's cyber-physical systems team brings experience in hacking, reverse engineering, and penetration testing across mission-critical aviation, maritime, weapons, and defense systems. Team members also conduct cyber-physical security research and have competed successfully in prominent hacking competitions, including DEF CON's ICS Village and Biohacking Village capture-the-flag events.
Training and Conference in One Registration
The CAM course begins with a full day of instruction on Tuesday, October 6, followed by half-day sessions on Wednesday and Thursday. The schedule allows participants to attend sessions from the broader ICS Cybersecurity Conference when training is not underway.
The $3,995 registration fee includes the complete training course, a self-contained virtual machine with the simulation and exercises, a certificate of completion, and access to conference sessions, meals, networking events, and social functions.
- The complete Cyber Attack Methods training course
- A self-contained virtual machine containing the CAM simulation, exercises and lesson content
- A certificate of course completion
- Access to ICS Cybersecurity Conference sessions
- Conference meals, networking events and social functions — full conference pass.
Students may retain the course virtual machine after the event, allowing them to revisit the exercises and continue learning beyond the classroom.
Logistics and Requirements
Participants must bring an Intel-based laptop capable of running the required virtual machine. ARM-based MacBooks are not supported. The course is available exclusively to United States citizens.
Seats for this immersive training are limited. Engineers, developers, testers, and security professionals who want to move beyond abstract descriptions of cyber-physical attacks and experience the attack process for themselves are encouraged to register as soon as possible.
Why It Matters
This training suggests a growing recognition that defending cyber-physical systems requires more than theoretical knowledge. By giving engineers and developers hands-on exposure to attack methods, the course could help organizations build systems that are more resilient from the start, rather than retrofitting security after an incident. For critical infrastructure operators, investing in such training may be a practical step toward reducing the risk of attacks that could disrupt essential services.
Sources
- SecurityWeek Original source
Continue Reading
Zimbra attacks breach 270+ servers
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
WhatsApp Tightens Account Security With Passkeys, Stronger 2SV
WhatsApp expands passkey support, upgrades 2SV to full passwords, and tests caller context for Android.
Memory Poisoning: The New AI Attack Frontier
InjecMEM lets attackers plant persistent instructions in AI agents' memory with a single prompt.