Cyber Security of Industrial Control Systems
EEL4276 — Cyber Security of Industrial Control Systems
← Course Modules
Course Description
Cyber Security of Industrial Control Systems is used to teach and share in-depth defense strategies and up-to-date information on cyber threats and mitigations for vulnerabilities, with the goal of improving cyber security preparedness in the industrial control systems community. It provides an overview of operations security for industrial control systems and prepares students for the risks and threats associated with electric grids and other centralized and distributed control systems. It is offered concurrently with EEL5277, with graduate students assigned additional work.
Within the SCNS taxonomy, EEL is the Electrical Engineering prefix. The University of West Florida publishes this at 3 semester hours through the Department of Electrical and Computer Engineering, College of Science and Engineering. It is offered at approximately 2 Florida institutions.
⚠⚠ The SCNS title for this number is "Smart-Grid and Cyber Physical Security"; UWF publishes it as "Cyber Security of Industrial Control System." The local title is broader in one direction and narrower in another: UWF's scope is industrial control systems generally — the electric grid is the leading example rather than the boundary — and water treatment, manufacturing, pipelines, and building systems fall inside it. Students transferring credit should carry a syllabus, since the titles diverge substantially.
The reason this course exists as a distinct subject is that securing an industrial control system is not securing an office network with different equipment. The priorities invert: in enterprise IT the classic ordering is confidentiality, integrity, availability, while in a control system availability and integrity come first, because the system is holding a physical process in a safe state. A control network cannot be taken down for patching on a Tuesday, its equipment has a thirty-year service life, and the protocols it runs were designed when physical isolation was assumed. Every standard IT security practice has to be re-derived against those constraints, and some of them simply do not transfer.
⚠ The contact-hour figure is derived — the University of West Florida publishes none
UWF's catalog publishes a credit value in semester hours, the college and department, prerequisites, and a description. It does not publish contact hours, a lecture and laboratory split, or terms of offering for any course. It does publish a material and supply fee notice on the minority of courses that carry one — and maintains a separate Material & Supply and Equipment Fees section of the catalog — so the absence of a fee notice on this entry is meaningful, while the fee amount is not published here. Every contact-hour value in a UWF guide in this repository is therefore derived. The figure here applies the standard lecture convention of 15 contact hours per credit, giving 45 hours for a 3-semester-hour course. Confirm the meeting schedule with the department.
Learning Outcomes
Required Outcomes
- Describe industrial control system architecture and its components.
- Distinguish SCADA, distributed control systems, and programmable logic controllers.
- Explain how operational technology differs from information technology in priorities and constraints.
- Describe the Purdue reference model and network segmentation.
- Describe industrial protocols and their inherent security weaknesses.
- Describe the threat landscape and categorise threat actors by capability and motive.
- Describe documented attacks on industrial control systems and what each demonstrated.
- Apply a structured risk assessment method to a control system.
- Identify common vulnerabilities in control system deployments.
- Describe attack surfaces introduced by remote access and vendor connectivity.
- Describe defence-in-depth architecture for control systems.
- Describe network segmentation, demilitarised zones, and data diodes.
- Describe access control and authentication in operational environments.
- Describe patch and configuration management under availability constraints.
- Describe monitoring, intrusion detection, and anomaly detection for control networks.
- Describe incident response and recovery planning for operational systems.
- Describe the relationship between safety systems and security.
- Describe applicable standards and regulatory requirements.
- Evaluate the security posture of a described control system.
Optional Outcomes
- Describe supply chain risk in control system components.
- Describe security for distributed energy resources and smart meters.
- Describe threat modelling methodologies applied to a control system.
- Analyse control system network traffic for anomalies.
- Describe security testing approaches appropriate to operational environments.
- Describe cyber-physical attack modelling and consequence analysis.
Major Topics
Required Topics
- Industrial control system architecture
- SCADA, DCS, PLCs, RTUs, and HMIs
- Operational technology versus information technology
- The Purdue model and zone segmentation
- Industrial protocols and their weaknesses
- Threat actors and the threat landscape
- Documented control system attacks
- Risk assessment methods
- Common vulnerabilities in deployments
- Remote access and vendor connectivity
- Defence in depth
- Segmentation, DMZs, and data diodes
- Access control and authentication
- Patch and configuration management
- Monitoring and intrusion detection
- Incident response and recovery
- Safety instrumented systems and security
- Standards and regulation
Optional Topics
- Supply chain risk
- Distributed energy resource and metering security
- Threat modelling
- Traffic analysis for control networks
- Security testing in operational environments
- Cyber-physical consequence analysis
Resources & Tools
- NIST SP 800-82, Guide to Operational Technology Security — free, and the single most important document in this field. If a student reads one thing, this is it.
- ISA/IEC 62443 — the international standard series for industrial automation and control system security; check UWF Libraries for access, and note that ISA publishes useful free overview material.
- NERC CIP standards (nerc.com) — free; mandatory and enforceable for the bulk electric system, with financial penalties.
- CISA ICS advisories and alerts (cisa.gov) — free and current; real vulnerabilities in real products, updated continuously, and the best way to see the live threat picture.
- MITRE ATT&CK for ICS (attack.mitre.org) — free; the standard taxonomy of adversary techniques against control systems, and directly usable for threat modelling assignments.
- CISA ICS training — free virtual and in-person courses, including hands-on exercises, and open to students.
- Dragos and SANS ICS reports — largely free; annual threat reporting from practitioners.
- Wireshark with industrial protocol dissectors — free; Modbus and DNP3 traffic can be read directly, which makes the lack of authentication in these protocols vivid.
- Conpot or similar ICS honeypots — free; run in an isolated laboratory environment only.
- ⚠ Practise only on equipment you own or a laboratory expressly provided for it. See the note below.
Career Pathways
- Information security analysts — SOC 15-1212; ICS security is a specialism within it with an acute shortage of qualified people.
- Electrical engineers — SOC 17-2071; the engineering side of the same problem.
- ⚠⚠ The combination is the point: very few people understand both power systems and security. Candidates who do are scarce and are compensated accordingly.
- Utility cybersecurity and NERC CIP compliance — Florida Power & Light, Duke Energy Florida, TECO, JEA, OUC, Gulf Power; compliance is a mandatory, permanently staffed function.
- Water and wastewater utility security — a large number of Florida municipal systems, many with very limited security staffing; this is an under-resourced and genuinely consequential sector.
- Defence and critical infrastructure protection — NAS Pensacola, Eglin Air Force Base, and NSA Panama City are in UWF's region, and installation control systems are in scope.
- Manufacturing and process industry security.
- Specialist ICS security consultancies and product vendors.
- ⚠ UWF has an established cybersecurity presence, including a Center for Cybersecurity; ask about certificate options, scholarships, and research opportunities that pair with this course.
- ⚠ Most critical-infrastructure and defence roles require United States citizenship and clearance eligibility, which is worth knowing before the internship search.
Special Information
⚠ Offered concurrently with the graduate EEL5277
- UWF teaches this alongside EEL5277, with graduate students assigned additional work. The pattern is routine at UWF and, across the corpus so far, is confined to 4000-level courses.
- The effect on an undergraduate is a section with graduate students in it and reading pitched to work at both levels. Undergraduate requirements are lower by design — the differential is in the additional graduate work, not in the shared material.
- For a student considering graduate study it is a useful preview, and the instructor sees the student working next to the standard they would be held to.
⚠⚠ The asterisk in a UWF prerequisite means the course may be taken at the same time
- UWF's catalog marks a concurrent course with an asterisk, defined on the catalog's Course Information page as: "This course may be taken prior to or during the same term."
- ⚠ This is the single most useful piece of notation in the UWF engineering catalog, and it is easy to miss. A prerequisite written without an asterisk must be completed first; one written with an asterisk may be taken in the same term.
- The practical effect is on time to degree. Reading an asterisked prerequisite as a hard prerequisite adds a term to the sequence for no reason, and in a tightly chained major like electrical engineering that error compounds down the whole plan.
- Confirm with an advisor before relying on it, and note that the registration system, not the catalog text, is what actually enforces the rule.
⚠⚠ The prerequisite is a programming course, not a power course
- UWF publishes: EEL4834* OR COP2334* OR COP3014*. Only a programming course is required, and all three options are asterisked, so any of them may be taken prior to or during the same term.
- ⚠ This is one of the most accessible courses in the EEL prefix. No circuits, no power systems, and a concurrent-eligible prerequisite — it is genuinely open to students from computer science and cybersecurity as well as engineering.
- ⚠⚠ The light prerequisite does not mean light content. The course assumes students will pick up control system context as they go, and students with power or controls background will reason about consequences far more concretely than those without.
- Pairing with EEL4287 Future Energy Systems is a natural combination, and that course introduces the grid-side context this one assumes.
⚠⚠ Why IT security practice does not transfer directly
- The priority ordering inverts. Enterprise IT protects confidentiality first; a control system protects availability and integrity first, because it is holding a physical process safe. A security control that risks stopping the process may be worse than the threat.
- ⚠ Patching is not routine. Control systems run continuously, downtime is expensive or unsafe, vendor validation may be required, and some equipment cannot be patched at all. Compensating controls do the work instead.
- ⚠⚠ Equipment lifetimes are measured in decades. Devices still in service predate any security design assumption, run unsupported operating systems, and cannot be replaced casually because replacement means an outage.
- Industrial protocols largely lack authentication and encryption by design. Modbus and DNP3 in their original forms will accept a command from anyone who can reach the network — not a bug, but an artefact of being designed for physically isolated serial links.
- ⚠ The air gap is usually a myth. Networks believed isolated commonly have vendor remote access, engineering laptops, wireless links, or business-network connections. Assuming isolation is itself a vulnerability.
- Active scanning can crash control devices. Tools that are routine in IT can knock a PLC offline, which is why passive monitoring is the default in operational environments.
⚠⚠ The consequences are physical, and the ethics follow from that
- An attack on a control system can cause physical damage, environmental release, or loss of life. That is what distinguishes this field from data breach response, and it should shape how the material is treated.
- ⚠⚠ Attacks on grid, water, and industrial systems causing real physical effects are matters of public record, including documented incidents against electricity distribution and against water treatment. The threat is demonstrated, not speculative.
- ⚠ Safety instrumented systems are the last line of defence, and an attack that targets them removes the protection that would otherwise contain a process failure. This is the scenario the field takes most seriously.
- ⚠⚠ Practise only on systems you own or on laboratory equipment expressly provided for the purpose. Unauthorised access to a computer system is a felony under federal law and under Florida statute, and critical infrastructure carries enhanced penalties. Curiosity is not a defence, and there is no ambiguity here.
- Vulnerability disclosure has established norms. Coordinated disclosure through CISA or the vendor is the professional path; publishing a working exploit against live infrastructure is not.
- Defensive framing is the course's stated purpose — UWF's own description says the goal is improving cyber security preparedness. Learn attacks to defend against them.
Florida grid context worth carrying into this course
- Florida is close to an electrical peninsula. Its ties to the rest of the Eastern Interconnection run through a limited northern corridor, which constrains how much power can be imported during a shortfall and makes in-state generation and reserve margin unusually important.
- Summer and winter peaks are both air-conditioning and heating driven, and Florida's load shape is dominated by weather to a degree few states match.
- ⚠⚠ Hurricanes are a design condition here, not a contingency. Storm hardening, undergrounding, vegetation management, and mutual-aid restoration are ordinary parts of Florida utility engineering, and the restoration problem is a systems problem.
- Solar has grown very rapidly in Florida, and the state is now among the largest solar generators in the country — which puts the integration questions in these courses directly in front of in-state employers.
- The employers are named and local: Florida Power & Light (NextEra), Duke Energy Florida, TECO, JEA, OUC, and Gulf Power in UWF's own region, plus municipal and cooperative utilities across the state.
- ⚠ NERC reliability standards govern bulk power system operation, and compliance is a real job function — violations carry financial penalties.
Course format and position in the curriculum
- Lecture with reading, case analysis, and frequently a laboratory or project component.
- Taught with graduate students in the room; expect the level to reflect that.
- ⚠ The material dates quickly. Expect current advisories and reports rather than a fixed textbook; CISA's advisory feed is worth following during the term.
- Accessible to non-engineering majors given the prerequisite, which makes the discussion unusually cross-disciplinary.
- UWF publishes no contact hours, lecture and laboratory split, or terms of offering for any course, and no material and supply fee is noted on this entry. Confirm the offering pattern with the department — at approximately two Florida institutions this is a narrow offering.
FE exam relevance
The Fundamentals of Engineering (FE) exam is the first step toward Professional Engineer licensure, and in Florida it is administered under the Florida Board of Professional Engineers. Most students take the FE Electrical and Computer exam in their final year. Licensure matters less in electrical engineering than in civil — the industrial exemption means most electrical engineers in manufacturing and product work never need a PE — but it is required for consulting practice, for sealing designs, and for power and building-systems work, which is exactly where Florida's utility and infrastructure employment sits.
How Florida course levels affect transfer
The first digit of an SCNS number denotes the year of offering, not transferability. Courses at the 1000 and 2000 levels transfer transparently between Florida public institutions, and 3000 to 4000 is unproblematic since both are upper division. The boundary that actually matters is 2000 to 3000, where lower-division credit generally cannot satisfy an upper-division requirement. ⚠ For engineering specifically, ABET-accredited programmes commonly require that upper-division engineering coursework be taken in residence, so transferability of the credit and applicability to the degree are separate questions.
EEL4276 is 3 semester hours at the University of West Florida, offered concurrently with the graduate EEL5277. Because the SCNS title ("Smart-Grid and Cyber Physical Security") and the local title differ substantially in scope, students transferring credit should carry a syllabus.