Disclaimer: This writeup is based on a Capture The Flag (CTF) challenge hosted on TryHackMe and it is intended for educational purposes only.
Operational Technology (OT) is the use of computers to monitor and control physical equipment and processes in the real world.
Industrial Control Systems (ICT) are a specific type of OT system found in industrial environments.
Task 1 Introduction to OT/ICS Cyber Security
Let's get started!
No answer needed
Task 2 What is OT/ICS?
What does the 'O' in OT stand for?
Operational
What does the 'C' in ICS stand for?
Control
Task 3 How Does OT/ICS Work?
When a PLC needs to send a signal to turn off a motor in the real world, it sends a signal through what type of connection?
Output
What source provides the environmental data that inputs feed into a PLC?
Sensor
Task 4 What is OT/ICS Cyber Security?
What type of system is used by a human operator to interact with a PLC and control a physical process in the real world?
Human Machine Interface
Which 2021 incident marked a turning point for OT/ICS security, after which annual cyberattacks against these networks doubled?
Colonial Pipeline
Task 5 Differences Between OT & IT Cyber Security
What is the most important requirement for OT/ICS cyber security?
Safety
What do many OT environments not leverage?
Encryption
Task 6 What a Human Operator Sees in OT Environments
Based on a review of the HMI, what type of environment is this?
ICS
When you first look at the HMI, what is the current percentage level indicated by the tank level sensor?
65
Click on the START button to turn on the pump to bring more water into the tank. At what percentage level do you first receive an alert in a yellow warning banner?
85
Continue to allow water to flow into the tank. At what percentage level does the control system realize there is danger and shuts off the pump bringing water into the tank?
95
With the pump stopped, click OPEN on the valve on the outtake pipe. What happens to the water level in the tank? The water level <fill in the blank>.
Lowers
Task 7 Conclusion
Nice job completing the room!
No answer needed