
CompTIA SecOT+
CompTIA SecOT+ (SOT-001) training prepares professionals to secure operational technology environments where cyber issues can affect safety, uptime, and equipment. Through instructor-led lessons, case studies, and lab-style scenarios , participants study ICS and SCADA components such as PLCs, HMIs, RTUs, and historians.
No sessions available
Check back later or contact a provider directly.
Description
CompTIA SecOT+ (SOT-001) training prepares professionals to secure operational technology environments where cyber issues can affect safety, uptime, and equipment.
Through instructor-led lessons, case studies, and lab-style scenarios, participants study ICS and SCADA components such as PLCs, HMIs, RTUs, and historians.
The course covers OT safety foundations, risk management, threat intelligence, secure architecture, security operations, and incident management, with reference to MITRE ATT&CK for ICS, NIST guidance, ISA/IEC 62443, and PICERL. After completion, learners can assess OT risk, support segmentation and monitoring plans, and prepare for the CompTIA SecOT+ SOT-001 exam.
CompTIA SecOT+ launches in December 2026.
What You Will Learn
CompTIA SecOT+ Course Content
Training follows the six CompTIA SecOT+ SOT-001 domains. Delivery combines short lectures, guided discussions, OT case studies, and hands-on lab activities focused on practical exam preparation and workplace use.
Module 1: OT Systems and Safety Foundations
ICS, SCADA, DCS, PLCs, HMIs, RTUs, sensors, actuators, historians, and safety instrumented systems.
OT protocols, including Modbus, DNP3, BACnet, Profinet, EtherNet/IP, OPC UA, serial, Ethernet, and wireless communications.
Control concepts such as set points, process variables, I/O, ladder logic, function block diagrams, and control loops.
Safety practices, including lockout/tagout, job safety analysis, PPE, hazard awareness, and safety briefings.
Module 2: OT Risk Management
Asset criticality, likelihood, impact, risk treatment, risk monitoring, change control, vendor access, and third-party risk.
Governance concepts aligned with NIST guidance and ISA/IEC 62443.
Module 3: OT Threat Intelligence
Threat actors, attack paths, indicators of compromise, and tactics used against ICS and critical infrastructure.
MITRE ATT&CK for ICS, ICS Cyber Kill Chain, Diamond Model, YARA, STIX, and threat intelligence workflows.
Case studies, including Stuxnet, TRISIS, Industroyer, BlackEnergy, and Colonial Pipeline.
Module 4: OT Cybersecurity Architecture, Design, and Engineering
Zones and conduits, network segmentation, least privilege, allowlisting, jump servers, MFA, PAM, and controlled remote access.
Secure design considerations for host, application, hardware, removable media, and physical security controls.
Module 5: OT Security Operations
Hands-on labs for asset inventory, passive monitoring, vulnerability review, log analysis, SIEM alerts, IDS tuning, and incident triage.
Module 6: OT Incident Management
PICERL and ICS4ICS activities, including containment, evidence handling, recovery, root cause analysis, reporting, and lessons learned.
After completion, participants should be able to support SecOT+ exam preparation, assess OT security posture, monitor industrial systems, and respond to incidents while considering safety and operational continuity.
Certification & Exam
This course prepares participants for the CompTIA SecOT+ certification exam, SOT-001, a vendor-neutral credential focused on securing operational technology (OT) environments. Participants who complete the course receive provider-issued course completion documentation, if offered by the training provider. The CompTIA certification is earned separately by registering for and passing the official SOT-001 exam through CompTIA’s approved testing process when registration is open. The exam is intended to validate knowledge of OT security risks, IT and OT differences, critical infrastructure protection, governance, compliance, safety considerations, and incident response in industrial environments such as manufacturing, utilities, and ICS/SCADA settings. For current exam status, requirements, objectives, and registration details, refer to the official CompTIA SecOT+ certification page.
What You Will Achieve
Apply OT safety principles when planning cybersecurity work, including controls that account for physical impact, production continuity, and safety-critical systems.
Analyze OT environments that include ICS, SCADA, PLCs, HMIs, sensors, actuators, engineering workstations, and industrial network components.
Assess OT cyber risk by reviewing asset criticality, exposure, likelihood, impact, governance requirements, and the differences between IT and OT risk priorities.
Evaluate OT threat intelligence for industrial and critical infrastructure environments, including threat actors, attack paths, indicators of compromise, and common tactics against control systems.
Design OT security architectures that use segmentation, zones and conduits, secure remote access, least privilege, and controls suited to legacy and safety-sensitive systems.
Implement OT security operations practices, including asset visibility, log review, vulnerability handling, access control, monitoring, and alert analysis without disrupting operations.
Respond to OT cybersecurity incidents using structured incident management practices such as PICERL and ICS4ICS, with attention to containment, recovery, safety coordination, and lessons learned.
Training Providers
No providers available for this course yet.
FAQs
General Information
Prerequisites & Requirements
Certification & Exam
Get Custom In-house Training
Post once, get competitive offers from multiple providers. Choose the one that fits your team.
Similar Trainings
EC Council Certified Ethical Hacker Certification (CEH)
The Certified Ethical Hacker (CEH) course teaches participants how to identify and fix security vulnerabilities. Through hands-on labs and theory, learners use attacker tools to test and strengthen network security. The training covers networks , web applications , cloud , mobile , and IoT systems. Participants develop technical skills for security audits and vulnerability assessments. Upon completion, professionals can perform penetration testing and report security gaps to protect systems from exploitation.
EC-Council Certified Penetration Testing Professional (CPENT)
The Certified Penetration Testing Professional (CPENT ) program is the world’s most comprehensive guided penetration testing program. It offers a complete hands-on pentesting methodology and AI techniques mapped to all pentesting phases. CPENT enables you to master pentesting within an enterprise network environment, evaluating intrusion risks and compiling actionable, structured reports. Distinguish yourself with the CPENT , learning beyond technical knowledge, scoping engagements, understanding design, estimating effort, and presenting findings and thrive as a leader in offensive security with versatile skills. CPENT combines guided learning with hands-on practice while immersing you in diverse live scenarios involving IoT systems, segmented networks, and advanced defenses, with practical challenges mapped to each domain. Gain expertise in advanced skills necessary to create your tools, conduct advanced binary exploitation, double pivot, customize scripts, and write your exploits to penetrate the deepest pockets of the network. Hands-on course featuring CTFs, 110+ labs, live cyber ranges, and 50+ tools Practical exam tests skills on unique multi-disciplinary network ranges The only program to teach a complete pen testing methodology
EC-Council Computer Hacking Forensic Investigator (CHFI)
EC-Council’s CHFI program enabled cybersecurity professionals with the knowledge and skills to perform effective digital forensics investigations and accomplish forensic readiness. Master the methodological approach of forensics process, evidence handling procedures, chain-of-custody, acquisition, preservation, analysis, and reporting of digital evidence, legal procedures to ensure it is admissible in court. Build skills beyond traditional hardware and memory forensics and with cloud forensics, mobile and IoT, investigating web application attacks, and malware forensics. CHFI equips you with skills to validate/triage incidents and guide the incident response teams. Build job ready skills on immersive 68 forensic labs Earn globally recognized and demanded by employers Flexible learning options without quitting your current jobs
EC-Council Certified Network Defender (CND) Program
The CND course gives you a full introduction to network security from a defender’s perspective. You learn how to protect, monitor, detect and respond to threats in modern network environments. The training includes theory and hands-on labs , teaching you how to secure networks, configure firewalls and IDS/IPS, monitor traffic, and implement defensive strategies across devices, endpoints, cloud and IoT. The goal is to equip you to build and maintain secure networks for organisations.
EC-Council Certified Cloud Security Engineer (CCSE)
The CCSE course teaches you how to secure, manage and defend cloud environments. You learn both general cloud-security principles and specific skills for major providers such as AWS, Azure and GCP. The training includes hands-on labs, real-world scenarios, and guidance on cloud governance, compliance, monitoring and incident response. This course prepares you to build secure cloud infrastructures , protect data and services in multi-cloud settings , and respond to cloud-specific threats professionally.
EC-Council Certified DevSecOps Engineer (ECDE)
The ECDE course shows you how to combine development, operations and security in a modern workflow. You learn both cloud-native and on-prem security practices, secure coding, infrastructure hardening, automated security tools and continuous deployment pipelines. The training uses many hands-on labs to build real-world DevSecOps skills.