Practical CPS Workshops Resume at ICS Cybersecurity Conference

0
5

Key Takeaways

  • The Cyber Attack Methods (CAM) course returns for its second year at the 25th‑anniversary ICS Cybersecurity Conference in Nashville, running October 6‑8, 2025.
  • CAM is a hands‑on, multi‑day training that puts participants in the attacker’s role to understand how adversaries discover, exploit, and chain vulnerabilities in cyber‑physical systems.
  • While valuable for security teams, the course targets engineers, developers, testers, designers, and anyone involved in building or maintaining OT/IoT environments; no prior cybersecurity experience is required.
  • Instruction is led by MTSI’s cyber‑physical systems experts, who bring real‑world penetration‑testing, reverse‑engineering, and competition experience from aviation, maritime, weapons, and defense projects.
  • The $3,995 registration fee includes the full CAM curriculum, a self‑contained virtual machine for post‑course practice, a completion certificate, and full access to the ICS Cybersecurity Conference sessions, meals, and networking events.
  • Participants must bring an Intel‑based laptop (ARM‑based MacBooks are not supported) and be U.S. citizens; seats are limited, so early registration is advised.

Course Overview
SecurityWeek, in partnership with MTSI, will deliver the Cyber Attack Methods (CAM) course for the second consecutive year as a centerpiece of the 25th Anniversary Industrial Control Systems (ICS) Cybersecurity Conference. Scheduled for October 6‑8 at the W Nashville, the training runs alongside the main conference, allowing attendees to blend intensive skill‑building with broader industry insights. The program is designed to move defenders beyond theoretical threat reports by immersing them in the mindset and tactics of actual adversaries targeting cyber‑physical environments.


Learning to Think Like an Attacker
Cyber‑physical systems fuse digital controllers with physical processes, meaning a successful breach can jeopardize safety, mission readiness, productivity, revenue, and essential services—not just data confidentiality. CAM’s core philosophy is that understanding an attack requires experiencing it firsthand. By placing students in the attacker’s shoes, the course reveals how adversaries systematically enumerate assets, probe for weaknesses, and string together discrete exploits to achieve operational goals such as disrupting a power grid or sabotaging a manufacturing line.


Hands‑On, Virtual Environment
Participants work inside an intentionally vulnerable virtual cyber‑physical testbed that mirrors real‑world OT architectures. Over three days, they progress through phases of system discovery, vulnerability identification, exploitation, and the execution of mission‑focused attacks. Unlike lecture‑only formats, CAM demands active keyboard interaction: students run scripts, analyze network traffic, and adjust exploits in real time, thereby internalizing the iterative nature of offensive operations.


Course Objectives
The explicit aim of CAM is not to train hackers but to equip designers, builders, testers, and defenders with a practical grasp of attacker behavior. By the end of the program, attendees will be able to enumerate systems, identify and exploit weaknesses, chain individual actions into consequential operational effects, and evaluate mitigations. They will also learn how architectural choices, secure coding practices, and testing strategies can shrink attack surfaces and increase resilience against sophisticated threats.


Built for More Than Cybersecurity Teams
Although security practitioners benefit, CAM is deliberately crafted for the wider community that shapes cyber‑physical systems: systems engineers, security engineers, programmers, developers, designers, and testers. Many critical security decisions—such as component selection, communication protocols, and fault‑tolerance mechanisms—are made long before a system enters production. When these stakeholders understand adversary methodologies, they can spot risky assumptions, anticipate unconventional attack vectors, and embed security into the design and verification lifecycle.


Prerequisites and Accessibility
No prior cybersecurity background is mandatory; the course is structured to be approachable for diverse technical audiences. Familiarity with the Linux command line and basic programming concepts will help participants navigate the exercises more fluidly, but guided instruction ensures that even those newer to offensive security can keep pace. The curriculum balances foundational concepts with advanced tactics, scaling complexity as learners progress.


Instructors and Expertise
MTSI’s cyber‑physical systems team leads the instruction, drawing on extensive experience in hacking, reverse engineering, and penetration testing across high‑stakes domains such as aviation, maritime, weapons, and defense systems. Team members routinely conduct cyber‑physical security research and have proven their skills in elite capture‑the‑flag competitions, including DEF CON’s ICS Village and Biohacking Village. Their real‑world perspective bridges the gap between academic theory and the pragmatic challenges faced by OT defenders.


Registration, Logistics, and Value
The CAM course begins with a full day of instruction on Tuesday, October 6, followed by half‑day sessions on Wednesday and Thursday, leaving ample opportunity to attend complementary conference talks. The $3,995 fee encompasses the complete CAM training, a self‑contained virtual machine containing the simulation, exercises, and lesson content, a certificate of completion, and full access to the ICS Cybersecurity Conference—including meals, networking events, and social functions. Attendees may retain the virtual machine after the event, enabling continued practice and knowledge reinforcement. Participants must supply an Intel‑based laptop capable of running the supplied VM; ARM‑based MacBooks are not supported, and the course is open exclusively to U.S. citizens. Seats are limited, so early registration is encouraged for engineers, developers, testers, and security professionals eager to move beyond abstract attack descriptions and experience the adversary process firsthand.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here