Practical activities

1. Scenario-Based Simulation: OT Cyber Incidents
Objective: To provide participants with a hands-on experience of OT cybersecurity incidents through realistic scenarios that combine technical response, teamwork, and decision-making.
Learners analyze evolving events, identify priorities, and coordinate actions under pressure to strengthen their incident management and crisis-response skills.
Description: Participants are divided into small groups and presented with three simulated scenarios representing different types of OT cyber incidents:
- Scenario 1 – Ransomware Attack on Pump Control in OT network
A ransomware infection disrupts pump operations in an industrial network.
Participants receive a timeline of events (operators report anomalies, pumps stop, ransom note appears, network traffic spikes) and must decide:- What immediate actions to take
- Who to inform
- How to isolate affected components
- Which mitigation steps and containment measures to apply

- Scenario 2 – Insider Threat and PLC Manipulation
A PLC configuration is changed via a USB device, causing a production anomaly.
Learners investigate the sequence of events, verify unauthorized logic uploads, and discuss:- How to validate the change and contain the issue
- Which technical and procedural controls failed
- What long-term policies should be updated to prevent recurrence
- Scenario 3 – Crisis Response Role Play
Participants assume roles within a multidisciplinary team (OT Manager, IT Security Lead, Public Relations Officer).
The facility has been partially shut down following a cyberattack.
Each team must:- Identify key priorities (safety, data integrity, communication, reputation)
- Prepare a short (2-minute) response briefing
- Address two stakeholder questions posed by the facilitator
By completing the simulation, participants will:
- Experience how cyber incidents unfold in OT contexts.
- Apply incident response principles (isolation, containment, communication, recovery).
- Understand the importance of collaboration between technical and managerial roles.
- Reflect on policy, training, and governance improvements to strengthen resilience.
2. Open Questions and Brainstorming:
Objective: To encourage participants to reflect on real-world cybersecurity challenges in their own professional environments and to share practical experiences with peers.
Description: In this interactive session, participants are guided through a series of open questions designed to stimulate discussion and collective analysis. The facilitator invites learners to consider the cybersecurity challenges they face in their daily work and to identify recurring vulnerabilities or risks within their operational environments.
Guiding questions:
- What are the biggest cybersecurity challenges you’ve encountered in your work?
- How does your organization currently manage OT security?
- Are there any specific vulnerabilities you’ve seen repeatedly?
Participants exchange experiences in small groups, then share their conclusions in a joint discussion, allowing them to recognize common patterns and differences across industrial contexts.
Outcome:
By the end of the activity, learners will have a clearer understanding of how OT security challenges manifest in practice and will be able to identify improvement opportunities in their own organizations. The session also promotes peer learning, encouraging collaboration between professionals from different sectors.
3. Experience Sharing :
Objective: To promote peer learning through the exchange of real-life experiences related to cybersecurity incidents or near misses in Operational Technology (OT) environments.
Description:
Participants are invited to share a past incident or near-miss involving OT systems within their organization or professional experience. These may include malware infections, unauthorized access attempts, configuration errors, or accidental process disruptions.
Working in small groups or as part of a guided plenary discussion, learners reflect on three key questions:
- What happened, and what were the main contributing factors?
- What lessons were learned from this incident?
- How did your team respond or adapt procedures to prevent similar events in the future?
The facilitator supports the conversation by highlighting best practices and connecting shared experiences to the key principles of OT cybersecurity — such as network segmentation, access control, and continuous monitoring.
Outcome: Through this reflective exercise, participants will gain valuable insight into how theory translates into practice. They will recognize the importance of incident analysis and continuous improvement as core components of a strong cybersecurity culture.
4. Brainstorming Solutions
Objective: To encourage participants to propose practical and achievable measures for strengthening cybersecurity in Operational Technology (OT) environments.
Description:
Building on the reflections from the previous activities, participants work in small groups to brainstorm possible solutions to common OT cybersecurity challenges. The discussion focuses on identifying low-cost or high-impact improvements that can realistically be implemented within their organizations, even with limited resources.
Guiding questions could include:
- What low-cost or high-impact improvements can be made to OT security?
- How can collaboration and communication between IT and OT teams be improved?
- What kind of training or initiatives would help OT staff become more cyber-aware?
Groups summarize their proposals and share them in a plenary session, where ideas are compared, refined, and prioritized. The facilitator helps connect suggestions to key cybersecurity frameworks and best practices discussed throughout the module.
Outcome:
By the end of this session, participants will have developed a set of actionable recommendations to enhance OT cybersecurity in their specific work environments. The exercise reinforces creativity, teamwork, and the importance of aligning technical and organizational measures to achieve a robust security posture.

