Participants will explore real-world cyber threats across IT, OT, IoT, cloud, connected vehicles, suppliers, and digital manufacturing systems.
Through hands-on exercises, live cybersecurity tools, case studies, simulations, and risk assessments, participants will learn to identify and respond to cyber risks.
The program emphasizes practical workplace implementation, enabling participants to strengthen cybersecurity within their own work areas.
Participants will leave with actionable checklists, risk matrices, response cards, and a 30/60/90-day roadmap to build a stronger cyber-resilient organization.ISO/IEC 27032:2012 vs ISO/IEC
27032:2023
2-Day Practical Programme
ISO/IEC 27032:2023 – Securing the Connected Automotive Manufacturing World
Learning philosophy
Understand → Identify → Assess → Decide → Act → Implement
Every module follows:
Real Case → Discussion → Hands-on Activity → Workplace Tool → Key Takeaway
ISO/IEC 27032:2023 –
Cybersecurity – Guidelines for Internet Security
Global Cybersecurity – Securing
the Connected Automotive World
Duration: 2 Days
Mode: Classroom / Hybrid / Online
Recommended Participants: IT + OT + Engineering + Production +
Cybersecurity + Digital + Supply Chain + Management
1. PROGRAM OVERVIEW
Modern automobile manufacturing
organizations are no longer isolated factories.
A typical automotive organization
is a highly interconnected digital ecosystem involving:
Corporate IT
↓
Engineering & R&D
↓
Cloud Platforms
↓
Digital Manufacturing
↓
Plant IT
↓
OT / Industrial Networks
↓
Machines / PLCs / SCADA
↓
IoT / IIoT Devices
↓
Suppliers
↓
Logistics Partners
↓
Dealers / Service Ecosystem
↓
Connected Vehicles / Digital
Services
This connectivity creates enormous
business value, but it also creates an expanded cyber-attack surface.
A compromised employee account can
potentially expose business information. A compromised supplier connection can
introduce risk into the enterprise. A poorly secured remote-access mechanism
can expose a manufacturing environment. A compromised cloud service can affect
engineering or business operations. A cyber incident originating through an
Internet-connected system can potentially escalate into operational disruption.
ISO/IEC 27032:2023 provides
guidance for organizations that use the Internet and specifically addresses the
relationship between Internet security, web security, network security and
cybersecurity. It also identifies relevant interested parties and their
roles and provides high-level guidance for common Internet-security issues. (ISO)
For an automobile manufacturing
giant, the value of this program lies in translating those concepts into the
organization's real operating environment:
People
Employees | Contractors | Vendors
| Administrators
↓
Information
Engineering Data | IP | Customer
Data | Business Data
↓
Technology
IT | Cloud | Applications |
Networks | IoT | IIoT
↓
Operations
Plant IT | OT | Machines |
Production Systems
↓
Ecosystem
Suppliers | Logistics | Service
Providers | Connected Products
The two-day program is therefore
designed as an applied cybersecurity program, not simply a
standard-awareness lecture.
Participants will learn to:
Identify → Understand → Assess
→ Protect → Detect → Respond → Recover → Improve
The training will use automotive
case studies, attack-path mapping, cyber-risk worksheets, IT/OT scenarios,
supplier-risk exercises, phishing simulations, remote-access scenarios,
connected-factory simulations and daily cybersecurity checklists.
2. PROGRAM OBJECTIVES
By the end of the program,
participants will be able to:
Understanding
- Understand the purpose and scope of ISO/IEC
27032:2023.
- Understand the current terminology and principles
associated with Internet security.
- Understand the relationship between Internet
security, web security, network security and cybersecurity.
- Understand the role of different stakeholders in a
connected ecosystem.
- Understand why cybersecurity is a business and
operational responsibility rather than only an IT responsibility.
Risk Awareness
- Identify Internet-facing assets.
- Identify digital attack surfaces.
- Identify common cybersecurity threats.
- Understand risks associated with cloud services.
- Understand web application and API risks at a
conceptual level.
- Understand remote-access risks.
- Understand IoT and IIoT risks.
- Understand IT/OT convergence risks.
- Identify third-party and supply-chain cybersecurity
exposure.
Protection
- Understand identity and access-control principles.
- Apply least-privilege thinking.
- Understand MFA and secure authentication.
- Understand network segmentation.
- Understand endpoint security.
- Understand secure remote access.
- Understand data protection.
- Understand backup and recovery principles.
- Understand secure configuration and
vulnerability-management principles.
Human Behaviour
- Recognize phishing and social-engineering risks.
- Improve cybersecurity communication.
- Encourage employees to report suspicious activity.
- Develop stronger cybersecurity habits.
- Understand insider-risk scenarios.
Incident Management
- Recognize early indicators of a cyber incident.
- Understand incident escalation.
- Understand containment principles.
- Understand IT/OT coordination.
- Understand communication during cybersecurity
incidents.
- Participate in a cyber incident simulation.
Implementation
- Perform a basic connected-environment risk
assessment.
- Complete an Internet-exposure checklist.
- Conduct a remote-access review.
- Conduct a supplier-connectivity review.
- Identify cybersecurity improvement opportunities.
- Develop a department-level cybersecurity action
plan.
- Establish practical day-to-day cybersecurity
controls.
3. LEARNING ARCHITECTURE
The entire two-day program follows
this model:
DAY 1
UNDERSTAND THE CONNECTED WORLD
↓
IDENTIFY THE ATTACK SURFACE
↓
UNDERSTAND THE THREATS
↓
ASSESS THE RISK
↓
IDENTIFY THE CONTROLS
DAY 2
PROTECT
↓
DETECT
↓
RESPOND
↓
RECOVER
↓
IMPROVE
4. TWO-DAY PROGRAM OUTLINE
DAY 1 – Understanding the
Connected Automotive Cybersecurity Environment
|
Time |
Module |
Duration |
|
9:30–10:15 |
Module 1 – The Connected Automotive
Enterprise |
45 min |
|
10:15–11:15 |
Module 2 – ISO/IEC 27032:2023 &
Cybersecurity Ecosystem |
60 min |
|
11:15–11:25 |
Tea Break |
10 min |
|
11:25–12:20 |
Module 3 – Automotive Cyber Threat
Landscape |
55 min |
|
12:20–1:10 |
Module 4 – Cyber Attack Surface
& Asset Identification |
50 min |
|
1:10–1:55 |
Lunch |
45 min |
|
1:55–2:45 |
Module 5 – Internet, Network &
Communication Security |
50 min |
|
2:45–3:40 |
Module 6 – Cloud, Web Applications
& API Security |
55 min |
|
3:40–3:50 |
Tea Break |
10 min |
|
3:50–4:50 |
Module 7 – IT/OT Convergence &
Connected Manufacturing |
60 min |
|
4:50–5:30 |
Module 8 – Day-1 Integrated Case
Study |
40 min |
DAY 2 – Protection, Detection,
Response & Connected-Factory Resilience
|
Time |
Module |
Duration |
|
9:30–10:00 |
Day-1 Recap & Cybersecurity Quiz |
30 min |
|
10:00–10:55 |
Module 9 – Identity, Authentication
& Access Management |
55 min |
|
10:55–11:05 |
Tea Break |
10 min |
|
11:05–12:00 |
Module 10 – Endpoint, Network &
Data Protection |
55 min |
|
12:00–12:50 |
Module 11 – Human Cybersecurity,
Phishing & Social Engineering |
50 min |
|
12:50–1:35 |
Lunch |
45 min |
|
1:35–2:25 |
Module 12 – IoT, IIoT &
Connected Manufacturing Security |
50 min |
|
2:25–3:15 |
Module 13 – Supplier, Third-Party
& Supply-Chain Cybersecurity |
50 min |
|
3:15–3:25 |
Tea Break |
10 min |
|
3:25–4:15 |
Module 14 – Cybersecurity Monitoring
& Incident Response |
50 min |
|
4:15–5:05 |
Module 15 – Connected Factory Cyber
Incident Simulation |
50 min |
|
5:05–5:30 |
Module 16 – 30/60/90-Day
Cybersecurity Action Plan & Final Assessment |
25 min |
1. Executive comparison
|
Area |
ISO/IEC 27032:2012 |
ISO/IEC 27032:2023 |
Practical significance |
|
Edition |
1st edition |
2nd edition |
2023 is the current version |
|
Publication |
July 2012 |
June 2023 |
11-year revision cycle |
|
Status |
Withdrawn |
Published/current |
Use 2023 for current programmes |
|
Pages |
50 |
28 |
Much more concise |
|
Original title |
Information technology — Security
techniques — Guidelines for cybersecurity |
Cybersecurity — Guidelines for Internet
security |
Focus has shifted |
|
Primary concept |
Cybersecurity / cyberspace |
Internet security |
Narrower, more focused scope |
|
Risk treatment |
General cybersecurity risk assessment |
Dedicated Internet-security risk
assessment and treatment |
More explicit risk methodology |
|
Threats |
Threats, threat agents,
vulnerabilities, attack mechanisms |
Threats, vulnerabilities and attack
vectors |
More Internet-attack-oriented |
|
Stakeholders |
Consumers and providers |
Interested parties with defined
categories |
Terminology and stakeholder model
changed |
|
Controls |
Separate cybersecurity controls chapter |
Consolidated Internet-security
guidelines |
More operational |
|
Social engineering |
Explicit control subsection |
Incorporated into broader
Internet-security guidance |
Less standalone treatment |
|
Information sharing |
Dedicated framework |
No equivalent standalone chapter |
Major structural change |
|
ISO/IEC 27002 relationship |
Not a dedicated cross-reference annex |
Annex A maps controls to ISO/IEC
27002 |
Stronger integration with 27002 |
|
Critical infrastructure |
More visible in original cybersecurity
context |
Not explicitly focused on critical
infrastructure/national security |
Important for manufacturing |
|
IT Information Technology/OT |
Not specifically an OT standard |
Still not an OT standard |
Need IEC 62443/other OT standards
alongside it |
|
Best use today |
Historical/reference understanding |
Current Internet-security guidance |
2023 should be your principal version |
ISO itself describes the 2012
edition as addressing cybersecurity and its dependencies on information
security, network security, Internet security and critical information
infrastructure protection. The 2023 edition instead explicitly explains the
relationship between Internet security, web security, network security and
cybersecurity, and provides high-level guidance for common
Internet-security issues.
2. Clause-by-clause structural
comparison
The following is the most useful
way to understand the transition.
Clause 1 — Scope
2012:
Scope was framed around improving the state of cybersecurity, with
emphasis on cyberspace and its stakeholders.
2023:
Scope is oriented toward Internet security, including its relationship
with web security, network security and cybersecurity.
What changed?
The conceptual centre moved:
2012
Cybersecurity → Cyberspace →
Stakeholders → Assets → Threats → Controls
2023
Internet Security → Relationship
with other security domains → Interested Parties → Risk → Security Guidelines
This is arguably the most
important change in the entire revision.
For an automobile manufacturer,
this means you should not present 27032:2023 as the complete cybersecurity
framework for the factory. Instead, position it as an Internet-security
guidance layer within the broader cybersecurity ecosystem.
3. Clause 2 — Applicability vs
Normative References
2012
Clause 2 was:
Applicability
with:
- 2.1 Audience
- 2.2 Limitations
This explicitly discussed who the
standard was intended for and its limitations.
2023
Clause 2 becomes:
Normative references
The audience/applicability
material is no longer structured as a separate clause in the same way.
Manufacturing implication
This is a move away from a long
introductory explanation toward a more conventional standards structure.
For training, don't spend
excessive time on the old 2012 "audience/limitations" structure.
4. Clause 3 — Normative
References → Terms and Definitions
2012
Clause 3:
Normative references
2023
Clause 3:
Terms and definitions
The 2023 structure moves
terminology earlier, which makes sense because the standard introduces a number
of related concepts.
Training activity
Ask participants:
"What is the difference
between cybersecurity, Internet security, network security and web
security?"
Then create this hierarchy:
Cybersecurity
↓
Internet Security
↓
Network Security / Web Security
This distinction is particularly
useful for IT managers and plant engineering teams.
5. Clause 4 — Terms and
Definitions → Abbreviated Terms
2012
Clause 4:
Terms and definitions
2023
Clause 4:
Abbreviated terms
This is largely a restructuring
change.
The terminology itself becomes
important because the 2023 standard deliberately distinguishes the security
domains rather than treating "cybersecurity" as one large
undifferentiated area.
6. Clause 5 — Abbreviated Terms
→ Security-Domain Relationships
This is a major conceptual
change.
2012
Clause 5:
Abbreviated terms
2023
Clause 5:
Relationship between Internet
security, web security, network security and cybersecurity
This is one of the most important
additions to your training.
Recommended training model
The 2023 edition explicitly
establishes this relationship. (PECB)
Automobile example
A connected vehicle may involve:
- vehicle cybersecurity
- Internet connectivity
- cloud services
- web applications
- APIs
- mobile applications
- supplier networks
- plant networks
- corporate IT
- OT networks
Therefore, one cyber incident can
cross several security domains.
7. Clause 6 — Overview
2012
Clause 6:
Overview
with:
- 6.1 Introduction
- 6.2 Nature of Cyberspace
- 6.3 Nature of Cybersecurity
- 6.4 General Model
- 6.5 Approach
The 2012 edition spent significant
effort explaining cyberspace itself.
2023
Clause 6:
Overview of Internet security
The focus is much more directly on
Internet security.
Key transition
2012: "What is
cyberspace and what is cybersecurity?"
2023: "What is
Internet security and how should organizations address Internet-security
risks?"
This is a significant change in
philosophy.
8. Clause 7 — Stakeholders →
Interested Parties
2012
Clause 7:
Stakeholders in the Cyberspace
including:
- Consumers
- Providers
2023
Clause 7:
Interested parties
with categories including:
- Users
- Coordinator and standardization organizations
- Government authorities
- Law enforcement agencies
- Internet service providers
The structural comparison is
documented by PECB. (PECB)
Why this matters
The 2012 standard looked at stakeholders
operating within cyberspace.
The 2023 standard looks more
specifically at parties involved in Internet security.
Automotive example
Your stakeholder map could
therefore include:
|
Interested party |
Automotive example |
|
Users |
Employees, dealers, customers |
|
Organization |
OEM |
|
ISP |
Internet connectivity provider |
|
Suppliers |
Tier 1/Tier 2 suppliers |
|
Government |
CERT-In / regulatory authorities |
|
Law enforcement |
Cybercrime authorities |
|
Standardization bodies |
ISO/IEC, industry bodies |
|
Service providers |
Cloud/SaaS providers |
9. Clause 8 — Assets → Internet
Security Risk Assessment
This is another major change.
2012
Clause 8:
Assets in the Cyberspace
with:
- Personal assets
- Organizational assets
2023
Clause 8:
Internet security risk
assessment and treatment
with:
- 8.1 General
- 8.2 Threats
- 8.3 Vulnerabilities
- 8.4 Attack vectors
This represents a substantial
shift.
Manufacturing activity
Give each team a connected-factory
scenario:
MES (Manufacturing Execution System) server → Production network →
PLC → Machine → Quality database
Ask:
- What is the asset?
- What is the threat?
- What vulnerability exists?
- What is the attack vector?
- What would be the business impact?
- What treatment should be applied?
Threat = What can happen / who or what can cause harm?
Vulnerability = What weakness allows it to happen?
Attack Vector = How does the threat exploit the weakness?
Impact = What happens to the business?
Treatment = What will we do about the risk?
This directly translates the 2023
structure into manufacturing practice.
10. Clause 9 — Threats →
Internet Security Guidelines
This is arguably the largest
structural transformation.
2012
Clause 9:
Threats against the security of
the Cyberspace
including:
- 9.1 Threats
- 9.2 Threat agents
- 9.3 Vulnerabilities
- 9.4 Attack mechanisms
2023
Clause 9:
Security guidelines for the
Internet
with a broad set of operational
areas.
The 2023 structure includes:
- General
- Policies for Internet security
- Access control
- Education, awareness and training
- Security incident management
- Asset management
- Supplier management
- Business continuity over the Internet
- Privacy protection over the Internet
- Vulnerability management
- Network management
- Protection against malware
- Change management
- Legislation and compliance
- Cryptography
- Application security for Internet-facing
applications
- Endpoint device management
- Monitoring
These changes are documented in
the detailed structural comparison. (PECB)
This is extremely relevant to
your training programme.
The 2023 standard essentially
takes you from:
"Understand cyber
threats"
to:
"What should the
organization actually do about Internet security?"
11. Clause 9.2.2 — Internet
Security Policies
This is particularly useful for
management.
For an automobile manufacturer,
translate this into:
Plant Internet Security Policy
Questions:
- Who can connect plant systems to the Internet?
- Who approves Internet-facing applications?
- Who approves remote access?
- Who owns Internet-connected assets?
- What constitutes unacceptable Internet use?
- How are exceptions approved?
- How are third-party connections controlled?
12. Clause 9.2.3 — Access
Control
This should become a major
workshop topic.
Manufacturing examples
- Employee login
- Privileged administrator accounts
- Vendor remote access
- Engineering workstation access
- PLC programming access
- MES access
- VPN access
- Cloud dashboards
- Dealer portals
Practical rule
No person + no device + no
application should receive more Internet-connected access than required for the
job.
13. Clause 9.2.4 — Education,
Awareness and Training
This is especially relevant to
your role as a trainer.
Participants should learn:
- phishing recognition
- password hygiene
- MFA
- suspicious USB/device handling
- social engineering
- reporting procedures
- remote-access risks
- data sharing
- safe browsing
- incident escalation
Manufacturing activity
"One Minute Cyber
Decision"
Give workers 10 scenarios:
Unknown USB found near
workstation.
Vendor asks for temporary VPN
access.
Manager requests password through
WhatsApp.
Unexpected software update
appears.
Participants answer:
STOP / PROCEED / REPORT
14. Clause 9.2.5 — Security
Incident Management - Video Link - Hindi - Tamil
TAMIL - VIDEO
This is much more directly
operational than simply talking about threats.
Create a simple plant response
model:
IDENTIFY
↓
VERIFY
↓
REPORT
↓
CONTAIN
↓
INVESTIGATE
↓
RECOVER
↓
LEARN
For manufacturing, add:
"Protect production safety
before restoring IT connectivity."
15. Clause 9.2.6 — Asset
Management
This connects directly with your
earlier competency/risk work.
Create an:
Internet-Connected Asset
Register
|
Asset |
Owner |
Location |
Internet exposure |
Criticality |
Risk |
|
MES |
IT |
Plant |
Yes |
Critical |
High |
|
Engineering workstation |
Engineering |
Line 2 |
Limited |
High |
High |
|
PLC |
OT |
Assembly |
Indirect |
Critical |
Critical |
|
Vendor laptop |
Supplier |
Plant |
Temporary |
High |
High |
|
HR system |
HR |
Corporate |
Yes |
Medium |
Medium |
16. Clause 9.2.7 — Supplier
Management
This is highly relevant to
automobile manufacturing.
A modern OEM has hundreds or
thousands of external relationships.
Potential access includes:
- supplier portals
- VPN
- remote maintenance
- cloud platforms
- software updates
- engineering data
- production equipment
- diagnostic systems
Supplier Cybersecurity
Checklist
Before granting access:
☐ Business justification
☐ Named individual
☐ Named device
☐ Defined access period
☐ MFA
☐ Least privilege
☐ Approval
☐ Logging
☐ Monitoring
☐ Access removal after completion
17. Clause 9.2.8 — Business
Continuity over the Internet
The 2012 version had broader
cybersecurity continuity concepts.
The 2023 version explicitly brings
business continuity over the Internet into its security guidelines.
Manufacturing scenario
Suppose:
Internet connectivity to the plant
is unavailable for 6 hours.
Ask:
- Can production continue?
- Can MES operate?
- Can suppliers communicate?
- Can logistics operate?
- Can quality systems operate?
- Can remote support operate?
- What becomes manual?
This produces a Cyber Business
Continuity Exercise.
18. Clause 9.2.9 — Privacy
Protection over the Internet
This is another area that deserves
more attention in today's connected environment.
Automotive organizations may
process:
- employee information
- customer information
- dealer information
- vehicle data
- telemetry
- location information
- video/CCTV
- biometric/access information
The security discussion therefore
extends beyond protecting corporate files.
19. Clause 9.2.10 —
Vulnerability Management
This is an important evolution
from simply identifying vulnerabilities.
Manufacturing vulnerability
cycle
For legacy OT systems where
patching may be dangerous:
Identify → Assess →
Compensating Controls → Monitor → Planned Remediation
20. Clause 9.2.11 — Network
Management
This becomes particularly
important for your automobile manufacturing audience.
21. Clause 9.2.12 — Protection
Against Malware
This encompasses:
- ransomware
- trojans
- spyware
- malicious downloads
- infected removable media
- malicious attachments
- compromised software
Manufacturing scenario
A supplier technician connects an
infected laptop to an engineering workstation.
Ask:
What happens next?
Teams identify:
Entry → Propagation → Detection
→ Isolation → Recovery
22. Clause 9.2.13 — Change
Management
This is often underestimated in
manufacturing.
Cybersecurity can be compromised
through legitimate changes.
Examples:
- PLC firmware update
- firewall configuration
- Windows update
- new application
- new IoT sensor
- network change
- vendor software installation
- cloud integration
Rule - Every technological
change can create a cybersecurity change.
23. Clause 9.2.14 — Legislation
and Compliance
The organization needs to identify
applicable:
- cybersecurity requirements
- privacy requirements
- contractual requirements
- regulatory requirements
- industry requirements
For an Indian automotive
organization, this should be connected to the organization's legal/compliance
function rather than treated purely as an IT responsibility.
24. Clause 9.2.15 —
Cryptography
This covers protection mechanisms
such as:
- encryption
- secure communications
- cryptographic controls
- key management
Automotive examples include:
- VPN
- TLS
- encrypted databases
- secure APIs
- encrypted remote access
- protected communications between systems
25. Clause 9.2.16 —
Internet-Facing Application Security
This is particularly important
because automotive organizations increasingly expose:
- supplier portals
- dealer portals
- customer applications
- APIs
- cloud applications
- e-commerce services
- employee portals
- connected-vehicle services
Activity
Attack Surface Mapping
Teams identify:
What applications does our
organization expose to the Internet?
Then ask:
- Who owns it?
- What data does it process?
- What authentication does it use?
- What happens if it is compromised?
- Is it monitored?
26. Clause 9.2.17 — Endpoint
Device Management
Endpoints can include:
- laptops
- desktops
- mobile phones
- tablets
- engineering workstations
- diagnostic devices
- remote-support systems
Daily checklist
☐ Screen locked
☐ Approved software only
☐ Antivirus/EDR active
☐ OS updated
☐ USB controlled
☐ MFA enabled
☐ Suspicious activity reported
27. Clause 9.2.18 — Monitoring
This is an important operational
element.
Organizations need visibility
into:
- unusual logins
- failed authentication
- abnormal network activity
- malware alerts
- suspicious remote access
- unusual data transfers
- unexpected configuration changes
Manufacturing principle
You cannot protect what you
cannot see.
28. What happened to 2012
Clause 10?
2012 Clause 10
Roles of stakeholders in
Cybersecurity
with:
- 10.1 Overview
- 10.2 Roles of consumers
- 10.3 Roles of providers
2023
This concept is reorganized under:
Clause 7 — Interested parties
and the security guidance in
Clause 9.
So the role-based philosophy
hasn't disappeared completely; it has been reorganized around
Internet-security interested parties and security guidance.
29. What happened to 2012
Clause 11?
2012
Guidelines for stakeholders
including:
- Risk assessment and treatment
- Guidelines for consumers
- Guidelines for organizations and service providers
2023
Risk assessment gets its own:
Clause 8 — Internet security
risk assessment and treatment
while practical security guidance
moves into:
Clause 9 — Security guidelines
for the Internet
This is an important improvement
in structure.
30. What happened to 2012
Clause 12?
2012
Cybersecurity controls
including:
- Application-level controls
- Server protection
- End-user controls
- Social engineering controls
- Cybersecurity readiness
- Other controls
2023
These are reorganized under:
9.2 Controls for Internet
security
with substantially broader
categories.
This is why I would describe the
2023 version as more operationally organized rather than simply
"new controls."
31. What happened to 2012
Clause 13?
This is a very important change.
2012
Clause 13:
Framework of information
sharing and coordination
including:
- Policies
- Methods and processes
- People and organizations
- Technical aspects
- Implementation guidance
2023
There is no equivalent
standalone Clause 13 framework.
Instead, coordination is reflected
through the interested-party model and the various Internet-security practices.
Training implication
Do not teach the old 2012
information-sharing framework as if it were a current mandatory clause.
Instead, teach:
Who needs to know? → What needs
to be reported? → When? → Through which channel?
32. Annexes — Major Change
2012 Annexes
Annex A: Cybersecurity
readiness
Annex B: Additional resources
Annex C: Examples of related documents
2023
Annex A: Cross-references
between ISO/IEC 27032:2023 controls and ISO/IEC 27002
This is strategically important.
The 2023 edition therefore makes
it easier to connect Internet-security guidance with an organization's broader
information-security control environment. PECB specifically identifies this
cross-reference as one of the significant changes. (PECB)
33. The biggest conceptual
difference
I would explain it to your
automobile manufacturing participants this way:
This reflects the restructuring documented by PECB and the scope descriptions published by ISO. (PECB)
34. Automobile manufacturing
mapping
For your 2-day automobile
manufacturing programme, I would map the standard like this:
|
ISO/IEC 27032:2023 |
Automobile manufacturing application |
|
Clause 5 |
IT / OT / Internet / Web security
relationship |
|
Clause 6 |
Connected factory cybersecurity |
|
Clause 7 |
Employees, suppliers, ISPs, government,
customers |
|
Clause 8 |
Cyber risk assessment |
|
8.2 |
Threat identification |
|
8.3 |
Vulnerability identification |
|
8.4 |
Attack-vector identification |
|
9.2.2 |
Plant Internet-security policy |
|
9.2.3 |
Identity & access management |
|
9.2.4 |
Employee cyber awareness |
|
9.2.5 |
Cyber incident response |
|
9.2.6 |
Asset inventory |
|
9.2.7 |
Supplier/third-party security |
|
9.2.8 |
Cyber business continuity |
|
9.2.9 |
Privacy |
|
9.2.10 |
Vulnerability management |
|
9.2.11 |
IT/OT network management |
|
9.2.12 |
Malware/ransomware |
|
9.2.13 |
Change management |
|
9.2.14 |
Legal/compliance |
|
9.2.15 |
Encryption |
|
9.2.16 |
Internet-facing applications |
|
9.2.17 |
Endpoint management |
|
9.2.18 |
Monitoring |
|
Annex A |
Mapping to ISO/IEC 27002 |
DAY 1 — UNDERSTAND & ASSESS
Module 1 — Cybersecurity vs
Internet Security → Clause 5
The Connected Automotive
Enterprise
Purpose
To help participants understand
how deeply the automobile organization is connected to the Internet and
external digital ecosystem.
Coverage
Corporate Environment
- Email
- ERP
- HR systems
- Finance
- Collaboration tools
- Cloud applications
Engineering Environment
- CAD
- PLM
- Engineering workstations
- Product-development systems
- Simulation platforms
- R&D databases
Manufacturing Environment
- Plant IT
- MES
- SCADA
- PLCs
- Industrial computers
- IIoT devices
- Connected machinery
External Ecosystem
- Suppliers
- Vendors
- Cloud providers
- Logistics partners
- Engineering partners
- Maintenance contractors
- Dealers/service ecosystem
Connected Product Ecosystem
- Telematics
- Mobile applications
- Cloud services
- OTA infrastructure
- Connected vehicle services
Activity 1 – “Draw Our
Connected World”
Each team receives a blank sheet.
They draw: Internet →
Enterprise → Plant → OT → Suppliers → Connected Products
Then identify:
- What connects to what?
- Who has access?
- What information moves?
- Where are external connections?
- Which connection would worry you most?
Key Takeaway
Cybersecurity starts with
knowing what is connected, who is connected and why.
Module 2 — Connected Automotive
Ecosystem → Clause 6
ISO/IEC 27032:2023 & the
Cybersecurity Ecosystem
ISO/IEC 27032:2023 specifically
explains the relationship between Internet security, web security, network
security and cybersecurity and identifies interested parties and their roles. (ISO)
Participants learn:
- What ISO/IEC 27032 is
- What it is intended to address
- Internet security
- Web security
- Network security
- Cybersecurity
- Stakeholder responsibilities
- Common Internet-security issues
Important comparison
|
Standard / Framework |
Primary Focus |
|
ISO/IEC 27001 |
Organizational Information Security
Management System |
|
ISO/IEC 27002 |
Information-security controls guidance |
|
ISO/IEC 27032 |
Internet security |
|
ISO/IEC 27033 |
Network security |
|
TISAX / VDA ISA |
Automotive information-security
assessment ecosystem |
|
ISO/SAE 21434 |
Vehicle cybersecurity engineering |
|
ISO 22301 |
Business continuity |
Activity 2 – “Which Standard
Addresses What?”
Teams receive 20 scenarios.
Examples:
Employee shares confidential CAD
data externally.
ECU has a cybersecurity
vulnerability.
Supplier requires remote access.
Factory loses network
connectivity.
Employee receives phishing email.
Teams identify which
framework/standard is primarily relevant.
Key Takeaway
No single cybersecurity
standard secures the entire automotive ecosystem. They must work together.
Module 3 — Interested Parties
& Responsibilities
→ Clause 7
Automotive Cyber Threat
Landscape
Threat Categories
1. Human
- Phishing
- Social engineering
- Credential theft
- Insider threats
2. Technical
- Malware
- Ransomware
- Vulnerability exploitation
- Misconfiguration
3. Connectivity
- Remote access
- Cloud
- APIs
- IoT
- IIoT
- Supplier connections
4. Supply Chain
- Compromised supplier
- Compromised software
- Third-party credentials
- Vendor remote access
5. Business
- Data theft
- Production disruption
- Service disruption
- Reputation damage
Activity 3 – Threat Ranking
Give each team 15 threat cards.
They rank them:
High / Medium / Low
based on:
Likelihood × Impact
Then compare their rankings with
other teams.
Key Takeaway
A cyber threat becomes a
business risk when it can affect people, information, operations, customers,
production or reputation.
Module 4 — Cyber Risk
Assessment → Clause 8
Cyber Attack Surface &
Asset Identification
This is one of the most important
practical modules.
Participants identify:
- Internet-facing websites
- Email systems
- VPN
- Remote-access gateways
- Cloud systems
- Web applications
- APIs
- Supplier portals
- Mobile applications
- Engineering systems
- IoT
- IIoT
- Plant IT
- OT gateways
Worksheet – Internet Exposure
Register
|
Asset |
Owner |
Internet Connected? |
External Users? |
Criticality |
Risk |
Action |
|
VPN |
IT |
Yes |
Employees/Vendors |
High |
High |
Review |
|
Supplier Portal |
SCM/IT |
Yes |
Suppliers |
High |
High |
Assess |
|
Engineering Server |
R&D/IT |
Limited |
Engineers |
High |
High |
Review |
|
IIoT Gateway |
OT |
Yes |
Vendor |
High |
High |
Segment |
Activity 4 – Attack Surface
Mapping
Teams map:
External Entry Point
↓
System
↓
User
↓
Internal Network
↓
Critical Asset
They then identify where controls
should stop the progression.
Key Takeaway - You cannot
protect what you have not identified.
Module 5 — Threats,
Vulnerabilities & Attack Vectors → Clause 8.2–8.4
Internet, Network &
Communication Security
Topics
- Network security fundamentals
- Secure connectivity
- Firewalls
- Segmentation
- Access control
- Secure protocols
- Encryption
- HTTPS/TLS awareness
- VPN
- Remote access
- Email security
- Network monitoring
Automotive application
Discuss:
Corporate Network
vs
Engineering Network
vs
Plant Network
vs
OT Network
vs
Supplier Network
Activity 5 – Network
Segmentation Exercise
Give participants a fictional
plant network.
Ask:
Which systems should communicate?
Which systems should never
communicate directly?
Where should additional controls
exist?
Key Takeaway - Connectivity
should be intentional—not automatic.
Module 6 — Human Cyber Risk → Clause 9.2.4
Cloud, Web Applications &
API Security
Coverage
- Cloud applications
- SaaS
- Web applications
- APIs
- Authentication
- Authorization
- Data exposure
- Misconfiguration
- Excessive privileges
- Logging
- Monitoring
- Third-party cloud services
Case Study
“The Supplier Portal Incident”
A supplier portal accidentally
exposes confidential engineering information.
Participants determine:
- What failed?
- What information was exposed?
- Who should have detected it?
- What control should have prevented it?
- What should happen immediately?
- What should be changed permanently?
Worksheet
|
Question |
Finding |
|
What data is exposed? |
|
|
Who can access it? |
|
|
Is authentication adequate? |
|
|
Is authorization adequate? |
|
|
Is sensitive data encrypted? |
|
|
Are logs available? |
|
|
Who monitors the system? |
|
|
What corrective action is required? |
Key Takeaway - A cloud service
is not automatically secure simply because it is hosted by a cloud provider.
DAY-1 TAKEAWAY SHEET
Every participant completes:
TODAY I LEARNED
- The three most important cyber risks in my function:
- The most important Internet-connected asset I deal with:
- The biggest weakness I have observed:
- One thing I should stop doing:
- One thing I should start doing:
- One thing I should report:
DAY 2 — PROTECT & RESPOND
Module 7 — Internet Security
Controls → Clause 9.2
IT/OT Convergence & Connected
Manufacturing
The Core Model
Corporate IT
↓
Plant IT
↓
Manufacturing Network
↓
OT
↓
PLC / SCADA / Machines
Topics
- IT/OT convergence
- OT availability
- Legacy systems
- Remote maintenance
- Vendor access
- Engineering workstations
- Industrial networks
- IIoT
- Network segmentation
- Monitoring
- USB/removable media
- Secure remote support
Activity 6 – “Protect the
Production Line”
Give participants a scenario:
A machine vendor requires remote
access to troubleshoot a production machine.
Teams determine:
- Who authorizes access?
- How is identity verified?
- What system can they access?
- How long is access permitted?
- Is MFA required?
- Is the session monitored?
- Is access recorded?
- How is access removed?
- What happens after maintenance?
Key Takeaway - Remote access is a controlled privilege—not a permanent convenience.
Module 8 — Access &
Endpoint Security → 9.2.3 + 9.2.17
“From Phishing Email to
Production Disruption”
This is the major Day-1 activity.
Scenario
9:00 AM
Employee receives a convincing
email.
↓
9:30 AM
Credentials are compromised.
↓
10:30 AM
Unauthorized access is detected.
↓
11:30 AM
An internal engineering system
shows abnormal activity.
↓
12:30 PM
Plant IT begins experiencing
disruption.
↓
1:30 PM
Production-support systems become
unavailable.
Team Task
Identify:
- Initial entry point
- Attack surface
- Vulnerable control
- Critical assets
- Business impact
- Detection opportunity
- Containment opportunity
- Recovery requirement
Deliverable
Each team creates:
Cyber Attack Chain Map
Entry → Access → Movement →
Target → Impact → Control
Module 9 — IT/OT & Network
Security → 9.2.11
Identity, Authentication &
Access Management
Topics
- Identity
- Authentication
- MFA
- Passwords
- Privileged accounts
- Least privilege
- Access approval
- Access review
- Service accounts
- Vendor accounts
- Remote access
- Joiner/Mover/Leaver controls
Principle
Right Person + Right Access +
Right Purpose + Right Time
Daily Access Checklist
☐ I use only my own credentials.
☐ I do not share passwords.
☐ MFA is enabled where required.
☐ I lock my workstation when
leaving.
☐ I report suspicious login
activity.
☐ I do not use unauthorized
accounts.
☐ I do not grant access without
authorization.
☐ Vendor access is time-bound.
☐ Privileged access is
controlled.
☐ Former/transfer employees'
access is reviewed promptly.
Module 10 — Supplier & Third-Party Cybersecurity→ 9.2.7
Coverage
- Endpoint security
- Antivirus/EDR awareness
- Patch management
- Vulnerability management
- Secure configuration
- Network segmentation
- Firewall
- Encryption
- Data classification
- Backup
- Data-loss prevention
Activity 7 – Secure Your
Workstation
Give participants 20 workstation
behaviours.
They classify:
SAFE / UNSAFE / NEEDS APPROVAL
Examples:
Installing unauthorized software.
Connecting personal USB.
Sending confidential engineering
data to personal email.
Leaving workstation unlocked.
Installing an approved update.
Sharing credentials with a
colleague.
Key Takeaway
Cybersecurity is a series of
small decisions made every day.
Module 11 — Incident Management
& Ransomware → 9.2.5 + 9.2.12
Human Cybersecurity – Phishing
& Social Engineering
Topics
- Phishing
- Spear phishing
- Business-email compromise
- Fake invoices
- Fake password-reset requests
- Malicious attachments
- Suspicious links
- Social engineering
- Impersonation
- Urgency manipulation
The 5-Question Test
Before clicking:
1. Who sent it?
2. Was I expecting it?
3. Is the request unusual?
4. Does the link/destination
make sense?
5. Can I verify through another
channel?
Activity 8 – Phishing
Identification
Participants review simulated
messages and classify:
GENUINE / SUSPICIOUS / REPORT
IMMEDIATELY
Golden Rule
STOP → VERIFY → REPORT
Not:
CLICK → DISCOVER → PANIC
Module 12 — Vulnerability &
Change Management→ 9.2.10 + 9.2.13
IoT, IIoT & Connected
Manufacturing Security
Topics
- IoT
- IIoT
- Sensors
- Connected machines
- Industrial gateways
- Cloud-connected equipment
- Remote monitoring
- Device identity
- Device lifecycle
- Firmware
- Network exposure
- Monitoring
Worksheet – Connected Device
Risk Review
|
Question |
Yes/No |
Action |
|
Is the device connected to a network? |
||
|
Is Internet access required? |
||
|
Does it have unique credentials? |
||
|
Is MFA available? |
||
|
Is remote access enabled? |
||
|
Is access monitored? |
||
|
Is firmware maintained? |
||
|
Is the device inventoried? |
||
|
Is the device segmented? |
||
|
Who owns the device? |
||
|
What happens if it is compromised? |
Key Takeaway
Every connected device should
have an owner, purpose, identity, access control and lifecycle.
Module 13 — Business Continuity
& Monitoring → 9.2.8 + 9.2.18
Supplier, Third-Party &
Supply-Chain Cybersecurity
Automotive organizations depend
heavily on suppliers and external service providers.
Risk areas
- Supplier portals
- Remote maintenance
- Cloud services
- Software providers
- Engineering partners
- Logistics providers
- Managed IT services
- Contractors
Supplier Risk Formula
Participants assess:
Information Access
System Access
Connectivity
Business Criticality
Potential Impact
Activity 9 – Supplier Cyber
Risk Ranking
Each team receives five supplier
profiles.
|
Supplier |
Access |
Criticality |
Connectivity |
Information |
Overall Risk |
|
A |
High |
High |
High |
High |
|
|
B |
Low |
Medium |
Low |
Medium |
|
|
C |
Medium |
High |
High |
High |
|
|
D |
High |
Low |
Medium |
Low |
Discussion
Which supplier requires the
strongest controls?
Which supplier requires continuous
monitoring?
Which supplier should have
time-bound remote access?
Key Takeaway
Your cybersecurity posture is influenced by the security of the organizations connected to you.
Module 14 — 30-60-90 Day
Cybersecurity Action Plan
Cybersecurity Monitoring &
Incident Response
Incident Lifecycle
DETECT
↓
VERIFY
↓
CLASSIFY
↓
ESCALATE
↓
CONTAIN
↓
ERADICATE
↓
RECOVER
↓
LEARN
Participants learn:
- What constitutes a suspicious event
- Who should be notified
- Escalation
- Evidence preservation
- Containment
- IT/OT coordination
- Communication
- Recovery
- Lessons learned
Important principle
Participants should not
independently investigate, alter or destroy potentially relevant evidence
unless that is part of their authorized role and procedure.
SIGNATURE ACTIVITY
Connected Factory Cyber
Incident Simulation
This should be the main
experiential exercise of the entire two-day program.
Scenario
Stage 1 – Phishing
An employee receives a fake
supplier email.
Stage 2 – Credential Compromise
The employee's credentials appear
in an unusual login event.
Stage 3 – Remote Access
An unusual remote-access session
is detected.
Stage 4 – Engineering
An engineering workstation behaves
abnormally.
Stage 5 – Plant IT
Plant systems begin experiencing
unusual network activity.
Stage 6 – OT Alert
OT monitoring identifies abnormal
communication.
Stage 7 – Production Risk
Production-support systems become
unavailable.
Stage 8 – Supplier
A supplier says its system may
also have been affected.
SIMULATION ROLES
Participants are divided into:
Team A – IT
Responsible for enterprise
systems.
Team B – OT
Responsible for plant systems.
Team C – Production
Responsible for manufacturing
continuity.
Team D – Cybersecurity
Responsible for security
coordination.
Team E – Management
Responsible for business
decisions.
Team F – Supplier
Responsible for external-party
coordination.
INCIDENT DECISION WORKSHEET
For every event:
|
Question |
Team Response |
|
What happened? |
|
|
What do we know? |
|
|
What do we not know? |
|
|
What is the immediate risk? |
|
|
What should be isolated? |
|
|
Who must be informed? |
|
|
What must NOT be done? |
|
|
What evidence must be preserved? |
|
|
Could production be affected? |
|
|
What is the next decision? |
|
|
Who owns the decision? |
MANAGEMENT DECISION BOARD
Management must decide:
1. Do we isolate the affected
system?
YES / NO / NEED MORE INFORMATION
2. Do we restrict remote
access?
YES / NO
3. Do we stop a production
process?
YES / NO / PARTIAL
4. Do we notify customers?
YES / NO / UNDER REVIEW
5. Do we notify the supplier?
YES / NO
6. Do we activate the
incident-response team?
YES / NO
7. Do we activate
business-continuity procedures?
YES / NO
This creates a realistic
cross-functional decision environment without teaching offensive attack
techniques.
MODULE 16
30/60/90-DAY CYBERSECURITY
IMPLEMENTATION PLAN
The program should not end with
the certificate.
Every participant should leave
with an action plan.
FIRST 30 DAYS – VISIBILITY
Objective:
Know what you have and what is
exposed.
Actions:
☐ Identify Internet-facing
assets.
☐ Review critical external
connections.
☐ Review remote-access accounts.
☐ Identify third-party
connections.
☐ Identify critical cloud
services.
☐ Identify connected OT/IIoT
systems.
☐ Confirm system owners.
☐ Review privileged accounts.
☐ Review critical supplier
access.
Deliverable:
Connected Asset & Exposure
Register
31–60 DAYS – CONTROL
Objective:
Reduce avoidable exposure.
Actions:
☐ Remove unnecessary access.
☐ Review inactive accounts.
☐ Strengthen authentication.
☐ Review MFA coverage.
☐ Review remote-access controls.
☐ Review network segmentation.
☐ Review endpoint protection.
☐ Review patch/vulnerability
status.
☐ Review backup arrangements.
☐ Review supplier access.
☐ Conduct cybersecurity
awareness sessions.
Deliverable:
Cybersecurity Gap Closure
Register
61–90 DAYS – RESILIENCE
Objective:
Detect faster and respond
better.
Actions:
☐ Review incident-response
procedure.
☐ Conduct phishing awareness
exercise.
☐ Conduct tabletop incident
exercise.
☐ Test IT/OT communication.
☐ Test escalation matrix.
☐ Review cybersecurity
monitoring.
☐ Conduct supplier incident
scenario.
☐ Conduct management simulation.
☐ Document lessons learned.
Deliverable:
Cyber Incident Readiness Report
DAILY CYBERSECURITY CHECKLIST
This is the most important takeaway
tool for day-to-day implementation.
Every Employee
Before Starting Work
☐ Is my workstation/device
behaving normally?
☐ Have I received any unusual
login/security notification?
☐ Am I using my own credentials?
☐ Is my workstation locked when
unattended?
☐ Are removable devices
authorized?
☐ Are there suspicious
emails/messages requiring attention?
During Work
☐ Am I accessing only
information required for my job?
☐ Am I sharing confidential
information only through approved channels?
☐ Am I using approved software?
☐ Am I connecting only
authorized devices?
☐ Am I verifying unusual
requests?
☐ Am I protecting passwords and
credentials?
Before Sending Information
Ask:
WHO?
Who is receiving it?
WHAT?
What information am I sending?
WHY?
Why do they need it?
WHERE?
Where is it being sent?
HOW?
Is this an approved method?
Before Clicking a Link
STOP
↓
CHECK
↓
VERIFY
↓
REPORT if suspicious
SUPERVISOR'S DAILY CYBER
CHECKLIST
☐ Are employees following
cybersecurity procedures?
☐ Are shared accounts being
used?
☐ Are unauthorized USB devices
being used?
☐ Are contractors accessing
systems?
☐ Are vendor connections active?
☐ Are suspicious activities
being reported?
☐ Have employees raised
cybersecurity concerns?
☐ Are new employees properly
provisioned?
☐ Have transferred employees had
access reviewed?
☐ Are terminated employees'
accesses removed?
☐ Are production systems being
accessed only by authorized personnel?
IT/OT DAILY CHECKLIST
☐ Review critical alerts.
☐ Review unusual authentication
events.
☐ Review remote-access activity.
☐ Review privileged access.
☐ Review critical endpoint
status.
☐ Review suspicious network
activity.
☐ Review unauthorized device
connections.
☐ Review critical backup status.
☐ Review major vulnerabilities.
☐ Review vendor access.
☐ Confirm incident-escalation
readiness.
CYBERSECURITY RED-FLAG
CHECKLIST
Employees should immediately
report:
ACCESS
☐ Unexpected password-reset
message
☐ Unknown login notification
☐ MFA request not initiated by
the user
☐ Account locked unexpectedly
EMAIL
☐ Suspicious attachment
☐ Urgent payment request
☐ Unexpected supplier
communication
☐ Request for credentials
☐ Unusual link
DEVICE
☐ Unusual pop-ups
☐ Unexpected software
☐ Sudden slowness
☐ Antivirus/security alert
☐ Unknown USB device
PRODUCTION
☐ Unexpected machine behaviour
☐ Unusual network activity
☐ Unexplained system outage
☐ Unauthorized remote access
☐ Unusual engineering
workstation behaviour
SUPPLIERS
☐ Unexpected vendor connection
☐ Vendor requesting emergency
access
☐ Unknown third-party account
☐ Supplier reports suspicious
activity
CYBERSECURITY OBSERVATION CARD
Every employee/supervisor can use
this simple format:
I OBSERVED:
SYSTEM / AREA:
WHAT COULD GO WRONG?
IMMEDIATE ACTION TAKEN:
WHO WAS INFORMED?
RECOMMENDED IMPROVEMENT:
DATE:
CONNECTED ASSET CHECKLIST
For each connected asset:
|
Question |
Yes |
No |
N/A |
Action |
|
Asset is identified |
☐ |
☐ |
☐ |
|
|
Owner identified |
☐ |
☐ |
☐ |
|
|
Business purpose defined |
☐ |
☐ |
☐ |
|
|
Internet connection known |
☐ |
☐ |
☐ |
|
|
External access known |
☐ |
☐ |
☐ |
|
|
Users identified |
☐ |
☐ |
☐ |
|
|
Privileged users identified |
☐ |
☐ |
☐ |
|
|
MFA reviewed |
☐ |
☐ |
☐ |
|
|
Network location known |
☐ |
☐ |
☐ |
|
|
Backup requirement defined |
☐ |
☐ |
☐ |
|
|
Vulnerability status known |
☐ |
☐ |
☐ |
|
|
Monitoring available |
☐ |
☐ |
☐ |
|
|
Incident owner identified |
☐ |
☐ |
☐ |
|
|
Vendor access reviewed |
☐ |
☐ |
☐ |
REMOTE ACCESS REVIEW WORKSHEET
Every external connection should
be reviewed using:
|
Question |
Response |
|
Who requires access? |
|
|
Why is access required? |
|
|
What system is accessed? |
|
|
Is access permanent or temporary? |
|
|
Who approved it? |
|
|
Is MFA enabled? |
|
|
Is access limited to required systems? |
|
|
Is activity logged? |
|
|
Is activity monitored? |
|
|
Can access be revoked immediately? |
|
|
When was the access last reviewed? |
|
|
What happens when the contract ends? |
Key principle:
No permanent access merely
because temporary access is inconvenient.
SUPPLIER CYBERSECURITY
CHECKLIST
Before allowing significant
third-party connectivity:
☐ Supplier identified
☐ Business justification
documented
☐ Information access identified
☐ System access identified
☐ Remote access identified
☐ Named users identified
☐ Authentication requirements
established
☐ MFA considered/required where
appropriate
☐ Access scope defined
☐ Access duration defined
☐ Logging enabled
☐ Monitoring established
☐ Incident notification
expectations defined
☐ Access-review frequency
established
☐ Exit/access-removal process
defined
CLOUD / APPLICATION SECURITY
CHECKLIST
For each critical cloud/web
application:
☐ Business owner identified
☐ Technical owner identified
☐ Data classification completed
☐ User access reviewed
☐ Privileged access reviewed
☐ MFA considered/implemented
☐ Logging available
☐ Monitoring available
☐ Backup/recovery requirements
identified
☐ Third-party dependencies
identified
☐ Security responsibilities
understood
☐ Incident escalation defined
☐ Periodic security review
established
IT/OT SECURITY CHECKLIST
Network
☐ IT/OT boundaries defined
☐ Network segmentation
implemented
☐ Remote access controlled
☐ Vendor access controlled
☐ Unnecessary connectivity
removed
Devices
☐ OT assets inventoried
☐ Asset owners identified
☐ Unsupported/legacy devices
identified
☐ USB/removable-media controls
established
Access
☐ Unique accounts used
☐ Privileged access controlled
☐ Remote access monitored
Monitoring
☐ Critical systems monitored
☐ Abnormal activity escalated
☐ Incident-response contacts
available
CYBER INCIDENT FIRST-RESPONSE
CARD
When something suspicious happens:
1. STOP
Do not continue suspicious
activity.
2. DON'T PANIC
Do not make uncontrolled changes.
3. REPORT
Notify the designated
cybersecurity/IT contact immediately.
4. PRESERVE
Do not delete potentially relevant
information unless instructed by the authorized response team.
5. ISOLATE ONLY AS AUTHORIZED
Follow the organization's incident
procedure.
6. DOCUMENT
Record:
- What happened
- When it happened
- What was observed
- Who was informed
- What action was taken
7. WAIT FOR INSTRUCTIONS
Do not independently investigate
beyond your authorized role.
GROUP WORKSHEET
“FIND THE WEAK LINK”
Each team receives a connected
automotive scenario.
They answer:
PEOPLE
Who could be exploited?
PROCESS
Which process could fail?
TECHNOLOGY
Which system could be compromised?
CONNECTION
Which connection creates exposure?
INFORMATION
What could be lost or altered?
OPERATIONS
What could happen to production?
CUSTOMER
What could happen to the customer?
CONTROL
Which control could
prevent/detect/respond?
FINAL TEAM ASSIGNMENT
Each team develops a:
CONNECTED AUTOMOTIVE
CYBERSECURITY IMPROVEMENT PLAN
Using this format:
|
Risk / Weakness |
Impact |
Current Control |
Gap |
Recommended Action |
Owner |
Priority |
Due Date |
DAY 1 — UNDERSTAND & ASSESS
MODULE 1 — Cybersecurity vs
Internet Security
"Is Cybersecurity really
an IT problem?"
Relevant ISO/IEC 27032:2023
theme: Relationship between cybersecurity, Internet security, network
security and web security.
Real-world case: Toyota–Kojima
Industries
In February 2022, Toyota supplier
Kojima Industries suffered a cyberattack. Toyota subsequently halted production
at all 14 Japanese plants because the supplier could not support the
just-in-time production flow. Toyota later described how employees had to
revert to paper-based processes while systems were unavailable. (ใใจใฟใคใ ใบ)
Facilitator question
"Toyota itself was not
initially attacked. So why did Toyota's production stop?"
Allow participants to debate
before revealing the supply-chain dependency.
Hands-on: Cyber Domino
Give teams cards:
Supplier → VPN → Network → MES
→ Production Planning → Logistics → Assembly Line → Customer
Remove one card.
Teams must identify the
consequences.
Participant worksheet
Cyber Dependency Map
|
Dependency |
What does it support? |
If unavailable |
Maximum tolerable downtime |
Owner |
|
Supplier portal |
Material ordering |
|||
|
MES |
Production |
|||
|
VPN |
Vendor support |
|||
|
ERP |
Planning |
Workplace takeaway
Connected Dependency Map
Each participant identifies 5
critical digital dependencies in their own work area.
MODULE 2 — Connected Automotive
Ecosystem
Real-world scenario
A modern automobile plant is
connected to:
- ERP
- MES
- SCADA
- PLCs
- robots
- quality systems
- warehouse systems
- supplier portals
- cloud systems
- engineering systems
- remote vendor support
- employee devices
The important lesson is that the
attack surface extends beyond the traditional "IT network."
Activity: Build Your Digital
Factory
Give teams a blank factory
diagram.
They must place:
Then draw the communication paths.
Challenge
Ask:
"If an attacker compromises
this device, what can they reach next?"
Hands-on deliverable
Connected Factory Attack
Surface Map
|
Asset |
Connected to |
Internet exposed? |
Business criticality |
Owner |
|
|
|
|
|
|
|
|
|
|
|
|
Daily implementation
Every department maintains a
simple:
"What are we connected
to?" map.
MODULE 3 — Interested Parties
& Cybersecurity Responsibilities
Case: Supplier ecosystem
failure
The Toyota/Kojima incident is
excellent here because it demonstrates that cybersecurity responsibility
doesn't stop at the OEM boundary. The attack on a Tier-1 supplier disrupted
Toyota's production ecosystem. (PLOS)
Activity: Who Owns the Risk?
Give this scenario:
A vendor's remote-support account
is compromised.
Ask each team:
- IT?
- OT?
- Procurement?
- Vendor?
- Plant Head?
- Cybersecurity?
- Engineering?
- Business owner?
Then introduce:
RACI Cybersecurity Model
|
Activity |
IT |
OT |
Procurement |
Vendor |
Plant Head |
|
Vendor approval |
C |
C |
R |
I |
A |
|
Remote access |
R |
C |
I |
R |
A |
|
Incident reporting |
R |
R |
I |
R |
A |
|
Access removal |
R |
R |
I |
C |
A |
Takeaway
Each participant creates:
"My Cybersecurity
Responsibility Card"
MODULE 4 — Cyber Risk
Assessment
This should be one of the most
hands-on modules.
Case
A production planning server is
connected to:
- ERP
- MES
- supplier network
- engineering systems
A vulnerability is discovered.
Activity: Cyber Risk Auction
Give every team 100 imaginary
"risk budget points."
Present risks one at a time:
- Phishing
- Ransomware
- Vendor VPN
- Unpatched server
- USB malware
- Insider misuse
- Cloud outage
- Internet-facing application
Teams must spend their limited
budget on the risks they consider most important.
Then calculate:
Likelihood × Impact = Risk
Score
Worksheet
|
Asset |
Threat |
Vulnerability |
Likelihood 1–5 |
Impact 1–5 |
Score |
Treatment |
|
MES |
Ransomware |
Weak segmentation |
4 |
5 |
20 |
Mitigate |
|
Vendor VPN |
Account compromise |
No MFA |
4 |
4 |
16 |
Mitigate |
Takeaway
Participants leave with a: 5×5
Cyber Risk Matrix that they can use immediately.
MODULE 5 — Threats,
Vulnerabilities & Attack Vectors
Case: Remote access
vulnerability
Use the Kojima case to explain how
an external business-partner connection reportedly provided an attack path into
the supplier environment. Public analyses identify the incident as a major
illustration of supply-chain and remote-connectivity risk. (PLOS)
Activity: Attack Vector Hunt
Give teams a fictional plant:
Supplier laptop → VPN → Plant
network → Engineering workstation → MES
Teams receive cards:
- Weak password
- No MFA
- Unpatched VPN
- Phishing
- Excessive privilege
- Flat network
- Shared account
- Uncontrolled USB
They must construct the most
likely attack chain.
Rule
Don't teach participants how to
exploit the vulnerabilities technically.
Teach them how to recognise and
break the chain.
Deliverable
Attack Vector Control Sheet
|
Attack vector |
Warning sign |
Preventive control |
Owner |
|
Phishing |
Unexpected attachment |
Email filtering + awareness |
IT |
|
Vendor VPN |
Unusual login |
MFA + monitoring |
IT |
|
USB |
Unknown device |
Device control |
IT/OT |
MODULE 6 — Human Factor,
Awareness & Social Engineering
Real-world case
Social engineering remains
particularly dangerous because a technically secure environment can still be
compromised through human decisions. A 2024 case study involving a
vehicle-parts manufacturer described both ransomware and a social-engineering
incident, illustrating the importance of combining technical and human
controls. (Raidar)
Activity: Phishing Detective
Give participants 5 simulated
emails.
Example:
Subject: URGENT – Supplier
Payment Account Changed
The email contains:
- urgency
- unusual sender
- attachment
- payment request
- suspicious link
Participants mark:
Second activity: CEO Fraud Role
Play
The attacker asks for an urgent
payment/account change.
Takeaway
STOP–CHECK–REPORT
Before:
- clicking
- downloading
- sharing
- paying
- granting access
Workplace tool
60-second suspicious
communication checklist
DAY 2 — PROTECT & RESPOND
MODULE 7 — Internet Security
Controls
Case
A vehicle manufacturer/supplier
environment contains dozens of Internet-connected systems.
Ask:
"If you were allowed only 10
cybersecurity controls for this plant, what would you choose?"
Activity: Cybersecurity
Survival Challenge
Give teams 20 control cards:
- MFA
- firewall
- EDR
- backup
- network segmentation
- patching
- encryption
- access control
- awareness
- monitoring
- vulnerability management
- logging
- supplier assessment
- incident response
- etc.
Teams may select only 10.
Then introduce a new threat:
"Ransomware has entered
through a supplier account."
Teams reassess their choices.
Learning
Cybersecurity is not:
"Buy more technology."
It is:
Risk → Priority → Control →
Ownership → Monitoring
Takeaway
Top 10 Cyber Controls for My
Department
MODULE 8 — IT/OT & Network
Security
Case: Toyota supply-chain
disruption
The Toyota/Kojima incident is
particularly useful for demonstrating that manufacturing's cyber risk is
ultimately an operational risk. Toyota's plants stopped because a
supplier's systems could no longer support production. (ใใจใฟใคใ ใบ)
Activity: Secure the Factory
Give teams a network diagram:
INTERNET
|
CORPORATE IT
|
?
|
MES
|
OT NETWORK
|
PLC
|
ROBOT
|
PRODUCTION
Teams must decide where to place:
- firewall
- DMZ
- jump server
- MFA
- monitoring
- vendor access
- segmentation
Red-team challenge
One team designs the attack path.
Another team designs the defensive
architecture.
Takeaway
My Plant's Critical Network
Segmentation Questions
MODULE 9 — Third-Party &
Supply Chain Cybersecurity
Major case: Toyota–Kojima
Industries
This should be your flagship
supply-chain case study.
Toyota had to stop all 14 Japanese
plants after its supplier Kojima Industries suffered a cyberattack. Toyota
reported that the production shutdown lasted one day, while Kojima's recovery
continued for considerably longer. (ใใจใฟใคใ ใบ)
Activity: Vendor Wants Access
Scenario:
A machine supplier says:
"Our engineer needs remote
access immediately. Production is already delayed."
The vendor asks for:
- VPN access
- administrator rights
- unrestricted network access
Teams have 5 minutes to
decide.
Then reveal:
The vendor's laptop has an
outdated endpoint security system.
Discussion
Should access be:
APPROVED / DENIED / CONTROLLED?
Vendor Cybersecurity Scorecard
|
Control |
Yes |
No |
Evidence |
|
MFA |
|||
|
Named accounts |
|||
|
Least privilege |
|||
|
Access expiry |
|||
|
Endpoint protection |
|||
|
Logging |
|||
|
Incident notification |
|||
|
Backup |
|||
|
Vulnerability management |
Takeaway
Every participant should identify:Top
5 critical vendors in my function
and classify: Critical / High /
Medium / Low cyber dependency
MODULE 10 — Incident Detection
& Response
Case: Automotive ransomware
Automotive suppliers have
experienced ransomware incidents that locked business-critical systems and
required external incident-response support. For example, EDAG, an automotive
engineering/supplier organization, publicly describes a ransomware incident
affecting business-critical systems and subsequent incident-response activity.
(Orange Cyberdefense)
Activity: Cyber Incident War
Room
Give participants this first
message:
09:05 AM: Production
supervisor reports that 15 computers are displaying unusual messages.
Then progressively reveal:
09:10: MES unavailable.
09:15: Several shared
drives inaccessible.
09:20: Supplier reports
similar symptoms.
09:30: IT identifies
abnormal network traffic.
Teams must decide:
- Who do we inform?
- What do we isolate?
- What must NOT be switched off?
- Do we stop production?
- Do we contact the vendor?
- Do we communicate externally?
- Who makes the final decision?
Deliverable
Incident Response Card
Takeaway - Each participant receives a one-page Cyber Incident Reporting Card.
MODULE 11 — Ransomware
Simulation
This should be the high-energy
capstone exercise.
Scenario
08:30 AM – Monday
Production starts normally.
09:05 AM
Operators report that files are
inaccessible.
09:10 AM
MES becomes unavailable.
09:15 AM
Production planning cannot access
schedules.
09:20 AM
A ransom message appears.
Round 1
Ask:
"What do you do?"
Teams write their first five
actions.
Round 2
Reveal:
Backup server is still accessible.
Ask:
"Do you immediately
restore?"
Round 3
Reveal:
An administrator account is still
showing suspicious activity.
Now ask:
"What happens if you restore
before containing the attacker?"
Round 4
Reveal:
Supplier communication is also
unavailable.
Now teams must manage business
continuity.
Scoring
|
Category |
Points |
|
Detection |
10 |
|
Escalation |
10 |
|
Containment |
20 |
|
Production continuity |
20 |
|
Communication |
10 |
|
Recovery |
20 |
|
Lessons learned |
10 |
|
Total |
100 |
Final takeaway
Each team creates:
Plant Ransomware
First-60-Minutes Checklist
MODULE 12 — Vulnerability &
Change Management
Case scenario
Engineering wants to install new
software on an engineering workstation.
Production says:
"Install it
immediately."
IT says:
"The software has not
completed security testing."
Engineering says:
"Without it, the machine
cannot operate efficiently."
Activity: Change Approval Board
Participants play:
- Plant Head
- Production
- Engineering
- IT
- OT Cybersecurity
- Quality
- Vendor
They must approve/reject/modify
the change.
Change Risk Worksheet
|
Question |
Yes/No |
|
Is the asset critical? |
|
|
Is the software approved? |
|
|
Has vulnerability testing been done? |
|
|
Is a rollback available? |
|
|
Has backup been verified? |
|
|
Has downtime been planned? |
|
|
Has vendor access been controlled? |
|
|
Has security approval been obtained? |
Takeaway
No change without security
thinking.
Participants leave with a Cybersecurity
Change Assessment Form.
MODULE 13 — Business
Continuity, Monitoring & Recovery
Case: Kojima recovery
Toyota's account of the Kojima
incident describes employees reverting to paper-based processes and manually
organising information while systems were unavailable. (ใใจใฟใคใ ใบ)
This is an excellent opportunity
to teach:
Cyber resilience is not only
about preventing the attack. It is about continuing the business when
prevention fails.
Activity: Go Manual
Tell teams:
"Your MES has been
unavailable for 4 hours."
They must design a manual process
for:
- production scheduling
- material movement
- quality records
- maintenance
- dispatch
- supplier communication
Exercise
Give them:
Paper + marker + production
orders
No laptops.
Challenge
Run the production process
manually for 15 minutes.
Then ask:
"What information did you
realise you normally depend on technology for?"
Takeaway
Department Business Continuity
Card
|
Process |
System normally used |
Manual alternative |
Maximum downtime |
Owner |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
MODULE 14 — Cybersecurity
Culture & 30-60-90 Action Plan
This is where the training must
become implementation-focused.
Activity: Cybersecurity Culture
Diagnostic
Ask participants to score their
department from 1–5:
|
Area |
Score |
|
Awareness |
/5 |
|
Password/MFA discipline |
/5 |
|
Incident reporting |
/5 |
|
Vendor control |
/5 |
|
Asset visibility |
/5 |
|
Patch management |
/5 |
|
Access control |
/5 |
|
Backup/recovery |
/5 |
|
Network security |
/5 |
|
Management involvement |
/5 |
Then create a:
Department Cybersecurity Heat
Map
Final Exercise — The
Cybersecurity Command Centre
I would make this the final
60–90 minute integrated exercise.
Scenario
Participants are given a fictional
automobile plant:
10,000 employees
300+ suppliers
Multiple production lines
MES + ERP + OT
Remote vendor support
Cloud applications
Connected equipment
At 9:00 AM:
A supplier reports a cyber
incident.
At 9:10:
One plant application becomes
unavailable.
At 9:20:
Employees receive phishing emails.
At 9:30:
Engineering reports abnormal
machine behaviour.
At 9:40:
Media asks whether production has
been compromised.
At 10:00:
Plant management asks:
"Can we continue
production?"
Teams have to perform six roles
Team 1 — Cybersecurity
Identify and contain the threat.
Team 2 — IT
Protect infrastructure.
Team 3 — OT/Engineering
Protect production.
Team 4 — HR/People
Manage employee communication.
Team 5 — Procurement/Supply
Chain
Manage suppliers.
Team 6 — Management
Make business decisions.
Final Participant Deliverables
This is what I would physically
put into the participant workbook.
1. Connected Factory Map
"What am I connected
to?"
2. Critical Asset Register
"What must I
protect?"
3. Cyber Risk Register
"What can go wrong?"
4. Attack Vector Map
"How could it
happen?"
5. Phishing Checklist
"Should I trust
this?"
6. Cyber Incident Card
"What should I do
first?"
7. Supplier Cybersecurity
Checklist
"Can I trust this third
party?"
8. IT/OT Security Checklist
"Is my plant environment
protected?"
9. Cyber Change Assessment
"Is this change
safe?"
10. Business Continuity Card
"What do we do if the
system goes down?"
11. Department Cybersecurity
Scorecard
"How mature are we?"
12. 30-60-90 Action Plan
"What will I actually
change?"
30-60-90 Day Implementation
Plan
First 30 Days — IDENTIFY
Participants should:
Output
Department Cyber Risk Register
Days 31–60 — PROTECT
Output
Cybersecurity Improvement
Tracker
Days 61–90 — RESILIENCE
Output
Department Cybersecurity
Maturity Score
Daily Cybersecurity Routine
The 5-5-5 Rule
Every day:
5 things to CHECK
- Suspicious emails
- Unusual system behaviour
- Unknown devices/USBs
- Unexpected access requests
- Unusual production/network behaviour
Every week:
5 things to REVIEW
- New users
- Privileged access
- Vendor access
- Security alerts
- Vulnerabilities
Every month:
5 things to TEST
- Incident response
- Backup
- Recovery
- Vendor access
- Employee awareness
Recommended Case Study Library
|
Case |
Best module |
|
Toyota–Kojima Industries, 2022 |
Supply chain, JIT, business continuity,
risk |
|
EDAG ransomware incident |
Incident response, ransomware |
|
Automotive parts manufacturer
ransomware/social engineering case |
Human factor |
|
CDK Global 2024 |
Third-party dependency and ecosystem
risk |
|
Recent automotive ransomware cases |
Threat landscape |
|
Fictional connected-factory incident |
IT/OT |
|
Fictional supplier VPN compromise |
Third-party access |
|
Fictional MES ransomware |
Incident command |
|
Fictional engineering workstation
compromise |
Endpoint/change management |











No comments:
Post a Comment