Training

Level up your team's OT capabilities.

Seven modules. Six Purdue layers. 100% hands-on labs. Full IT-to-OT kill chain. Built on the methodology from Hacking OT Networks: A Practical Guide to Pentesting Industrial Networks, this training mirrors the progression of a real-world OT assessment — from enterprise foothold through process impact demonstration. Every engagement is customized to your team's environment and objectives.

Curriculum

The full OT penetration test, start to finish.

OT fundamentals and engagement planning

OT vs. enterprise assessment differences. Risk considerations, safety requirements, the Purdue Model, scoping, rules of engagement, and stakeholder coordination. Sets the operational framework for every module that follows.

Enterprise exploitation through OT boundary

Assumed-breach starting position. Host, domain, and network enumeration. Privilege escalation and credential discovery. Then crossing the IT/OT boundary through remote access architectures, jump hosts, and OT DMZ entry points while minimizing operational risk.

OT DMZ through control network

Low-footprint enumeration inside the OT DMZ. Identifying pivot points to the Process Control Network. Then breaching Purdue Level 3 — targeting engineering workstations, OPC servers, domain controllers, and asset management platforms under heightened safety constraints.

Process impact and reporting

Demonstrating real-world impact on Crown Jewel assets: PLCs, HMIs, and engineering workstations. PLC logic manipulation, HMI value modification, and process disruption scenarios. Compiling findings into reports tailored for technical teams, OT stakeholders, and executive leadership.

Audience

Who this training is for.

Penetration testers

Experienced IT pentesters expanding into OT/ICS assessments. The training bridges the gap between enterprise skills and industrial execution.

Red and purple team operators

Teams responsible for adversary simulation in environments with OT components. The curriculum covers the full IT-to-OT kill chain.

Security consultants

Professionals scoping, selling, or delivering OT assessments for clients. The methodology provides a repeatable, structured approach.

Government and military cyber operators

Personnel conducting or supporting offensive operations against critical infrastructure targets.

Your Instructor

Background in both worlds.

All sessions are delivered by Chris Nourrie, Co-Founder and CTO of Arsenal Unified Intelligence. His background spans offensive cyber operations for U.S. Cyber Command, senior red team leadership at a major U.S. utility, and extensive OT penetration testing across critical infrastructure.

  • Author of Hacking OT Networks: A Practical Guide to Pentesting Industrial Networks.
  • Air Force Tailored Access Operations supporting U.S. Cyber Command and the NSA.
  • Extensive OT penetration testing across electric power, mining, water treatment, pharmaceuticals, and oil and gas.
  • Regular industry and conference speaker at DEFCON, ICS security events, and national conferences.

Let's scope your training.

Available as a full series or individual modules. In-person at your facility or live virtual delivery. Same instructor-led experience, same hands-on labs. Every engagement starts with a conversation about your team and objectives.