If you are just starting your career in ICS/OT Cybersecurity, I would recommend you to gain the necessary knowledge first.

Luckily, the knowledge is free!!

Here is the detail of free training by Cybersecurity and Infrastructure Security Agency which I rate very highly compared to many paid trainings.

I have briefed about those trainings here.

There is also a free certification along with training for the basics of cybersecurity by ISC2, the details can be found here.

After completing these trainings, you’ll be ready to start your certification journey!

We have two major certification and certificate body currently very widely recognized:

GIAC Certifications (previously Global Information Assurance Certification)

This is one of the widely popular certification bodies that Certifies your knowledge for a particular role. This certification body allows you to prepare by yourself and just opt of the examination. However, trainings are highly recommended as it has extensive hands-on activities and so many wonderful insights. But sadly, it isn’t affordable for the most of us. Here are popular certifications:

GICSP (Global Industrial Cyber Security Professional) - This certification covers following areas:
  • Industrial control system components, purposes, deployments, significant drivers, and constraints
  • Control system attack surfaces, methods, and tools
  • Control system approaches to system and network defence architectures and techniques
  • Incident-response skills in a control system environment
  • Governance models and resources for industrial cybersecurity professionals
GRID (GIAC Response and Industrial Defence) - This certification covers following areas:
  • Active Defence Concepts and Application, Detection and Analysis in an ICS environment
  • Discovery and Monitoring in an ICS environment, ICS-focused Digital Forensics, and ICS-focused Incident Response
  • Malware Analysis Techniques, Threat Analysis in an ICS environment, and Threat Intelligence Fundamentals

International Society of Automation (ISA)

This one of the most popular certificate course provider for ICS/OT Cybersecurity skills. Their training is totally based on IEC/ISA 62443 standard and has total Four certificates. A fundamental Specialist is must to pursue any of the three specialization certificate. If you complete all three specializations, you receive Cybersecurity expert certificate.

Here is a summary of what each certificate will cover:
Certificate 1: ISA/IEC 62443 Cybersecurity Fundamentals Specialist

This certificate training lays the foundation for the specialization. It starts with introduction to IEC/ISA 62443 and covers different terminologies, phases and fundamentals. It also explains OSI Layer, Cybersecurity management system, and the concept of Zones and Conduits.

Certificate 2: ISA/IEC 62443 Cybersecurity Risk Assessment Specialist

This certificate training build on Certificate 1 to prepare you for OT Cyversecurity risk assessment. It covers different methods of assessment, steps, phases and the activities to perform before, during and after the assessment of the Industrial control systems. This certificate helps you be job ready for the assessments.

Certificate 3: ISA/IEC 62443 Cybersecurity Design Specialist

This certificate covers in detail the design and implementation prospect of the cybersecurity. This part helps you understand risk responses, understand and design the countermeasures, OS hardening among others. This certificate helps you do your job in Design and Implementation of countermeasures.

Certificate 4: ISA/IEC 62443 Cybersecurity Maintenance Specialist

This certification focuses on Operation part of the cybersecurity. It covers ICS Cybersecurity Lifecycle, Security Management & Maintenance, Security Monitoring & Detection and IACS Incident Response & Recovery. This certification will be great for people managing plant security operations and incident response.

These are the ones that I thought should be shared with you. Do you know any good certifications that I have missed?