Most industrial incidents begin with a person: an email, a USB drive or borrowed access. We train everyone who interacts with the plant—from management to the night shift—in language suited to their role and using real examples.
On-site awareness session · a steel mill
Our approach
Ti School is our training programme. It is not a generic cybersecurity talk repackaged for industry: the examples come from the ethical hacking exercises we conduct in real plants, and practical work is performed on real control equipment in the Ti Lab laboratory.
Each profile is addressed separately. An executive does not need the same things as an automation engineer, nor does an IT administrator need the same things as the operator in front of the SCADA. That is why the catalogue begins by defining who is being trained.
Who we train
Six audiences, six languages
The same threat is explained differently depending on the audience. We divide learners into six groups and adapt the content, duration and technical depth to each one.
Training audiences
Group
Who they are · what they need
Group 1
Management Legal accountability (NIS2), resource decisions and a top-down security culture.
Group 2
Business staff Everyone who handles information and email, even if they do not interact with a control system.
Group 3
IT staff Administrators and technicians who are now also inheriting industrial systems.
Group 4
IT/OT cybersecurity managers Those responsible for designing, specifying and auditing security across both networks.
Group 5
OT, maintenance and engineering managers Those making decisions about the plant and its automation projects.
Group 6
OT operations and maintenance Those in front of the process on every shift: the real front line.
Catalogue · sessions
Awareness and training sessions
Instructor-led sessions with no practical exercises for learners. They are delivered on site or by video conference, in groups of 10 to 45 people depending on the course.
Groups 1–6 · 45–55 min · foundation level
User awareness
A highly practical session using real-life examples from our own ethical hacking exercises: exposed passwords, phishing emails, malicious USB devices (Rubber Ducky, BadUSB) and Wi-Fi and mobile risks. Learners see it happen rather than simply hearing about it.
Groups 2–6 · 120 min · foundation level
ICS Cybersecurity Kill Chain simulation
The instructor demonstrates live, on a simulated plant, how an attacker enters through IT—a USB drive, an email or a vulnerable application—and reaches OT to alter a production process. The attacker journey, seen from the inside.
Group 1 · 45–55 min · foundation level
Security for management
The NIS2 Directive and its impact, management duties and personal accountability, resource allocation and real OT cybersecurity incidents and their consequences.
Groups 2–6 · 120–150 min · foundation level
Secure use of IT resources
What every user needs day to day: the threat landscape, passwords, social engineering, the importance of patching, web browsing, email, Wi-Fi and BYOD, and use of the corporate VPN.
Groups 4–6 · 120–150 min · intermediate level
Secure use of OT resources
Plant-specific risk: trends and attacker profiles, the anatomy of an ICS attack (including a demonstration using an industrial protocol), defence in depth and its mechanisms, and good and bad operating practices.
Catalogue · technical courses
Hands-on laboratory courses
Here, learners practise. Small groups of 3 to 6 work in a laboratory environment with virtual machines, programmable controllers and a real control-system rig accessed through a VPN.
Introduction to control-system hacking (ICS)
Groups 3–4 · 16–24 h · advanced level · 3–6 people
From zero to interfering with a process. The course begins by explaining ICSs (DCS, SCADA, PLC, RTU) and their protocols, then progresses through real exercises: basic programming of a Siemens S7-1200 PLC, device discovery with Shodan, Modbus analysis with Wireshark, command injection, CPU start/stop and pivoting between IT and OT networks. It ends with a challenge: alter the operation of the supplied rig.
Cybersecurity applied to industrial networks
Groups 3–5 · 24 h · advanced level · 3–6 people
Control networks from the inside: topologies, protocols, managed switches, VLANs, IT/OT convergence, industrial wireless and monitoring. The ISA/IEC 62443 standard is connected to plant reality through an assessment, and key countermeasures are applied in a laboratory using practical offensive and defensive security scenarios.
The portable industrial control rig attacked during the courses
Remote and continuous
Online awareness platform
To reach the entire workforce and sustain good habits over time, beyond a one-off session. Online training with interactive, game-based modules and scheduled campaigns in Spanish, English and Portuguese.
Campaigns that are not forgotten after a week
Training modules and regular newsletters.
Teaching moments: short modules on a specific risk.
Simulated phishing and ransomware campaigns using credible lures.
Tests and surveys that provide genuine measurement.
And provide evidence
They assess actual user behaviour, not what users say they know.
They identify the highest-risk individuals so support can be focused where needed.
They enable investment to be compared with results throughout the year.
They provide evidence of training for audits (NIS2, ISO 27001).
Delivery options
Courses are delivered at the client premises—a classroom with a projector and internet access for the instructor is enough—or remotely by video conference. Technical courses can also be followed online, with VPN access to the laboratory.
Practical work is supported by the Ti Lab laboratory: virtual machines, controllers and a real control-system rig where attacks and defences can be practised without touching a production plant.
The programme is sized to your organisation: from a single session to an annual plan combining classroom sessions, technical courses and the awareness platform. Ask us for the programme you need.
The rig HMI: the process learners practise attacking and protecting