|
Cybersecurity Risk Management for Engineers: Protecting Critical Infrastructure, Industrial Control Systems, Operational Technology, and Engineering Assets in Texas |
||||||||||||||||||||||||||
|
|
||||||||||||||||||||||||||
|
Course Description: Cybersecurity has become a critical engineering risk management issue affecting virtually every sector of modern infrastructure. Water systems, electric utilities, transportation networks, manufacturing facilities, petrochemical plants, pipelines, industrial operations, and municipal infrastructure increasingly depend upon interconnected digital technologies to support monitoring, control, automation, communications, asset management, and operational decision-making. While these technologies provide substantial benefits, they also create new vulnerabilities that can expose critical infrastructure to cyber threats with significant operational, financial, environmental, regulatory, and public safety consequences. Cybersecurity Risk Management for Engineers examines cybersecurity from an engineering perspective rather than a purely information technology perspective. The course focuses on the relationship between cybersecurity, operational technology, industrial control systems, infrastructure resilience, process safety, engineering governance, and professional responsibility. Participants will learn how cybersecurity risks affect the design, operation, maintenance, modernization, and management of critical infrastructure systems and how engineers can contribute to protecting essential services and public welfare. The course begins by establishing a foundation in cybersecurity principles and terminology relevant to engineering practice. Participants examine how cyber threats have evolved from traditional information technology concerns into infrastructure risks capable of affecting physical systems, operational reliability, and public safety. The course explores the growing convergence between information technology and operational technology environments and explains how cybersecurity considerations increasingly influence engineering decision-making. Participants then examine the architecture and operation of information technology systems, operational technology environments, industrial control systems, Supervisory Control and Data Acquisition systems, Distributed Control Systems, Programmable Logic Controllers, Human Machine Interfaces, and other technologies commonly deployed throughout critical infrastructure sectors. The course emphasizes the unique cybersecurity challenges associated with operational technology environments and explains how these systems differ from traditional information technology networks. A comprehensive review of cyber threats and vulnerabilities follows, including ransomware, malware, phishing campaigns, credential compromise, insider threats, supply chain attacks, remote access vulnerabilities, legacy infrastructure exposures, and Industrial Internet of Things risks. The course explains how threat actors target infrastructure environments and how vulnerabilities emerge throughout the lifecycle of engineering systems, infrastructure assets, and operational technologies. Cybersecurity risk assessment methodologies are examined using principles familiar to engineers, including threat identification, vulnerability assessment, consequence analysis, likelihood evaluation, risk prioritization, defense-in-depth strategies, and resilience planning. Participants learn how cybersecurity risk management aligns with established engineering disciplines such as safety engineering, reliability engineering, process hazard analysis, asset management, and enterprise risk management. The course provides detailed coverage of cybersecurity controls used to protect critical infrastructure and industrial operations. Topics include network segmentation, access control systems, multi-factor authentication, asset inventories, secure configuration management, patch management, continuous monitoring, backup and recovery strategies, physical security measures, cybersecurity-by-design principles, and operational technology security architectures. Participants learn how these controls work together to reduce risk while supporting operational reliability and resilience. The relationship between cybersecurity, process safety, infrastructure resilience, operational continuity, and emergency response planning receives significant attention throughout the course. Participants examine how cyber incidents can affect safety systems, industrial operations, utility services, transportation networks, and public welfare. Resilience engineering concepts such as redundancy, diversity, business continuity planning, disaster recovery, incident response, and recovery validation are explored as essential components of modern cybersecurity programs. The course also examines cybersecurity governance frameworks and regulatory considerations affecting infrastructure operators. Participants review the National Institute of Standards and Technology Cybersecurity Framework, the NIST Risk Management Framework, NIST Special Publication 800-82, ISA/IEC 62443 industrial cybersecurity standards, North American Electric Reliability Corporation Critical Infrastructure Protection requirements, water sector cybersecurity guidance, transportation cybersecurity initiatives, vendor risk management practices, and cybersecurity governance responsibilities. The course emphasizes the role of engineers in supporting compliance, risk management, operational integrity, and infrastructure resilience. Emerging technologies and future cybersecurity challenges are examined through discussion of smart infrastructure, connected systems, cloud computing, artificial intelligence, Industrial Internet of Things technologies, digital twins, autonomous systems, advanced communications networks, and future infrastructure modernization initiatives. Participants learn how technological innovation creates both opportunities and cybersecurity challenges and how engineers can apply risk-informed decision-making to support secure and resilient infrastructure development. To reinforce practical application, the course includes three detailed engineering case studies based on realistic infrastructure cybersecurity scenarios. The first case study examines a ransomware attack affecting a Texas municipal water utility and explores the operational, engineering, public health, and resilience implications of a cyber incident affecting critical utility infrastructure. The second case study analyzes an industrial control system compromise at a Texas petrochemical facility and demonstrates the relationship between cybersecurity, process safety management, industrial operations, and engineering risk management. The third case study examines a cyber attack affecting an Intelligent Transportation System and regional traffic management network, highlighting cybersecurity challenges associated with smart infrastructure, connected transportation systems, and transportation resilience. Throughout the course, Professional Judgment Alerts are incorporated to emphasize areas where engineering judgment, professional responsibility, operational realities, safety considerations, and public welfare obligations influence cybersecurity decision-making. These alerts highlight situations where engineers must balance cybersecurity objectives against competing considerations such as operational continuity, infrastructure reliability, maintainability, regulatory compliance, safety system performance, and resilience requirements. By the conclusion of the course, participants will possess a practical understanding of cybersecurity risk management principles applicable to engineering environments and critical infrastructure systems. They will be better prepared to identify cyber risks, evaluate vulnerabilities, support resilience initiatives, participate in cybersecurity governance activities, contribute to incident response efforts, and integrate cybersecurity considerations into engineering design, operations, maintenance, modernization, and infrastructure lifecycle management decisions. |
||||||||||||||||||||||||||
|
|
|
|||||||||||||||||||||||||
|
Learning Objectives: Upon successful completion of this course, participants will be able to: 1. Explain how cybersecurity threats affect critical infrastructure, industrial operations, utility systems, transportation networks, and other engineering environments. 2. Differentiate between Information Technology (IT), Operational Technology (OT), Industrial Control Systems (ICS), and Supervisory Control and Data Acquisition (SCADA) environments and evaluate their unique cybersecurity considerations. 3. Identify common cyber threats, attack pathways, and vulnerabilities affecting engineering systems, including ransomware, phishing, credential compromise, supply chain risks, insider threats, remote access exposures, and legacy infrastructure vulnerabilities. 4. Apply cybersecurity risk assessment principles to engineering assets and infrastructure systems by evaluating threats, vulnerabilities, consequences, likelihoods, and risk priorities. 5. Evaluate cybersecurity controls and defense-in-depth strategies used to protect critical infrastructure, industrial facilities, utility operations, and operational technology environments. 6. Assess the relationship between cybersecurity, process safety, infrastructure resilience, operational continuity, emergency response, and public welfare. 7. Explain the purpose and application of cybersecurity governance frameworks, standards, and regulatory guidance, including the NIST Cybersecurity Framework, NIST Risk Management Framework, NIST Special Publication 800-82, and ISA/IEC 62443. 8. Evaluate cybersecurity risks associated with emerging technologies, including Industrial Internet of Things systems, cloud-connected infrastructure, artificial intelligence applications, digital twins, autonomous systems, and smart infrastructure platforms. 9. Analyze cybersecurity incidents affecting water utilities, industrial facilities, and transportation systems to identify root causes, operational impacts, engineering lessons learned, and resilience improvement opportunities. 10. Integrate cybersecurity risk management principles into engineering design, infrastructure modernization, asset management, operational decision-making, and lifecycle management activities to support safe, reliable, and resilient infrastructure systems. |
||||||||||||||||||||||||||
|
||||||||||||||||||||||||||