Tuesday, September 1, 2026

ISO/IEC 27032:2023 – Cybersecurity: Guidelines for Internet Security

This training on ISO/IEC 27032:2023 – Cybersecurity: Guidelines for Internet Security focuses on securing today’s connected automotive and manufacturing environment.
Participants will explore real-world cyber threats across IT, OT, IoT, cloud, connected vehicles, suppliers, and digital manufacturing systems.
Through hands-on exercises, live cybersecurity tools, case studies, simulations, and risk assessments, participants will learn to identify and respond to cyber risks.
The program emphasizes practical workplace implementation, enabling participants to strengthen cybersecurity within their own work areas.

Participants will leave with actionable checklists, risk matrices, response cards, and a 30/60/90-day roadmap to build a stronger cyber-resilient organization.ISO/IEC 27032:2012 vs ISO/IEC 27032:2023

2-Day Practical Programme

ISO/IEC 27032:2023 – Securing the Connected Automotive Manufacturing World

Learning philosophy

Understand → Identify → Assess → Decide → Act → Implement

Every module follows:

Real Case → Discussion → Hands-on Activity → Workplace Tool → Key Takeaway

ISO/IEC 27032:2023 – Cybersecurity – Guidelines for Internet Security

Global Cybersecurity – Securing the Connected Automotive World

Duration: 2 Days
Mode: Classroom / Hybrid / Online
Recommended Participants: IT + OT + Engineering + Production + Cybersecurity + Digital + Supply Chain + Management


1. PROGRAM OVERVIEW

Modern automobile manufacturing organizations are no longer isolated factories.

A typical automotive organization is a highly interconnected digital ecosystem involving:

Corporate IT

Engineering & R&D

Cloud Platforms

Digital Manufacturing

Plant IT

OT / Industrial Networks

Machines / PLCs / SCADA

IoT / IIoT Devices

Suppliers

Logistics Partners

Dealers / Service Ecosystem

Connected Vehicles / Digital Services

This connectivity creates enormous business value, but it also creates an expanded cyber-attack surface.

A compromised employee account can potentially expose business information. A compromised supplier connection can introduce risk into the enterprise. A poorly secured remote-access mechanism can expose a manufacturing environment. A compromised cloud service can affect engineering or business operations. A cyber incident originating through an Internet-connected system can potentially escalate into operational disruption.

ISO/IEC 27032:2023 provides guidance for organizations that use the Internet and specifically addresses the relationship between Internet security, web security, network security and cybersecurity. It also identifies relevant interested parties and their roles and provides high-level guidance for common Internet-security issues. (ISO)

For an automobile manufacturing giant, the value of this program lies in translating those concepts into the organization's real operating environment:

People

Employees | Contractors | Vendors | Administrators

Information

Engineering Data | IP | Customer Data | Business Data

Technology

IT | Cloud | Applications | Networks | IoT | IIoT

Operations

Plant IT | OT | Machines | Production Systems

Ecosystem

Suppliers | Logistics | Service Providers | Connected Products

The two-day program is therefore designed as an applied cybersecurity program, not simply a standard-awareness lecture.

Participants will learn to:

Identify → Understand → Assess → Protect → Detect → Respond → Recover → Improve

The training will use automotive case studies, attack-path mapping, cyber-risk worksheets, IT/OT scenarios, supplier-risk exercises, phishing simulations, remote-access scenarios, connected-factory simulations and daily cybersecurity checklists.


2. PROGRAM OBJECTIVES

By the end of the program, participants will be able to:

Understanding

  • Understand the purpose and scope of ISO/IEC 27032:2023.
  • Understand the current terminology and principles associated with Internet security.
  • Understand the relationship between Internet security, web security, network security and cybersecurity.
  • Understand the role of different stakeholders in a connected ecosystem.
  • Understand why cybersecurity is a business and operational responsibility rather than only an IT responsibility.

Risk Awareness

  • Identify Internet-facing assets.
  • Identify digital attack surfaces.
  • Identify common cybersecurity threats.
  • Understand risks associated with cloud services.
  • Understand web application and API risks at a conceptual level.
  • Understand remote-access risks.
  • Understand IoT and IIoT risks.
  • Understand IT/OT convergence risks.
  • Identify third-party and supply-chain cybersecurity exposure.

Protection

  • Understand identity and access-control principles.
  • Apply least-privilege thinking.
  • Understand MFA and secure authentication.
  • Understand network segmentation.
  • Understand endpoint security.
  • Understand secure remote access.
  • Understand data protection.
  • Understand backup and recovery principles.
  • Understand secure configuration and vulnerability-management principles.

Human Behaviour

  • Recognize phishing and social-engineering risks.
  • Improve cybersecurity communication.
  • Encourage employees to report suspicious activity.
  • Develop stronger cybersecurity habits.
  • Understand insider-risk scenarios.

Incident Management

  • Recognize early indicators of a cyber incident.
  • Understand incident escalation.
  • Understand containment principles.
  • Understand IT/OT coordination.
  • Understand communication during cybersecurity incidents.
  • Participate in a cyber incident simulation.

Implementation

  • Perform a basic connected-environment risk assessment.
  • Complete an Internet-exposure checklist.
  • Conduct a remote-access review.
  • Conduct a supplier-connectivity review.
  • Identify cybersecurity improvement opportunities.
  • Develop a department-level cybersecurity action plan.
  • Establish practical day-to-day cybersecurity controls.

3. LEARNING ARCHITECTURE

The entire two-day program follows this model:

DAY 1

UNDERSTAND THE CONNECTED WORLD

IDENTIFY THE ATTACK SURFACE

UNDERSTAND THE THREATS

ASSESS THE RISK

IDENTIFY THE CONTROLS

DAY 2

PROTECT

DETECT

RESPOND

RECOVER

IMPROVE


4. TWO-DAY PROGRAM OUTLINE

DAY 1 – Understanding the Connected Automotive Cybersecurity Environment

Time

Module

Duration

9:30–10:15

Module 1 – The Connected Automotive Enterprise

45 min

10:15–11:15

Module 2 – ISO/IEC 27032:2023 & Cybersecurity Ecosystem

60 min

11:15–11:25

Tea Break

10 min

11:25–12:20

Module 3 – Automotive Cyber Threat Landscape

55 min

12:20–1:10

Module 4 – Cyber Attack Surface & Asset Identification

50 min

1:10–1:55

Lunch

45 min

1:55–2:45

Module 5 – Internet, Network & Communication Security

50 min

2:45–3:40

Module 6 – Cloud, Web Applications & API Security

55 min

3:40–3:50

Tea Break

10 min

3:50–4:50

Module 7 – IT/OT Convergence & Connected Manufacturing

60 min

4:50–5:30

Module 8 – Day-1 Integrated Case Study

40 min

DAY 2 – Protection, Detection, Response & Connected-Factory Resilience

Time

Module

Duration

9:30–10:00

Day-1 Recap & Cybersecurity Quiz

30 min

10:00–10:55

Module 9 – Identity, Authentication & Access Management

55 min

10:55–11:05

Tea Break

10 min

11:05–12:00

Module 10 – Endpoint, Network & Data Protection

55 min

12:00–12:50

Module 11 – Human Cybersecurity, Phishing & Social Engineering

50 min

12:50–1:35

Lunch

45 min

1:35–2:25

Module 12 – IoT, IIoT & Connected Manufacturing Security

50 min

2:25–3:15

Module 13 – Supplier, Third-Party & Supply-Chain Cybersecurity

50 min

3:15–3:25

Tea Break

10 min

3:25–4:15

Module 14 – Cybersecurity Monitoring & Incident Response

50 min

4:15–5:05

Module 15 – Connected Factory Cyber Incident Simulation

50 min

5:05–5:30

Module 16 – 30/60/90-Day Cybersecurity Action Plan & Final Assessment

25 min



1. Executive comparison

Area

ISO/IEC 27032:2012

ISO/IEC 27032:2023

Practical significance

Edition

1st edition

2nd edition

2023 is the current version

Publication

July 2012

June 2023

11-year revision cycle

Status

Withdrawn

Published/current

Use 2023 for current programmes

Pages

50

28

Much more concise

Original title

Information technology — Security techniques — Guidelines for cybersecurity

Cybersecurity — Guidelines for Internet security

Focus has shifted

Primary concept

Cybersecurity / cyberspace

Internet security

Narrower, more focused scope

Risk treatment

General cybersecurity risk assessment

Dedicated Internet-security risk assessment and treatment

More explicit risk methodology

Threats

Threats, threat agents, vulnerabilities, attack mechanisms

Threats, vulnerabilities and attack vectors

More Internet-attack-oriented

Stakeholders

Consumers and providers

Interested parties with defined categories

Terminology and stakeholder model changed

Controls

Separate cybersecurity controls chapter

Consolidated Internet-security guidelines

More operational

Social engineering

Explicit control subsection

Incorporated into broader Internet-security guidance

Less standalone treatment

Information sharing

Dedicated framework

No equivalent standalone chapter

Major structural change

ISO/IEC 27002 relationship

Not a dedicated cross-reference annex

Annex A maps controls to ISO/IEC 27002

Stronger integration with 27002

Critical infrastructure

More visible in original cybersecurity context

Not explicitly focused on critical infrastructure/national security

Important for manufacturing

IT Information Technology/OT
Operational Technology

Not specifically an OT standard

Still not an OT standard

Need IEC 62443/other OT standards alongside it

Best use today

Historical/reference understanding

Current Internet-security guidance

2023 should be your principal version

ISO itself describes the 2012 edition as addressing cybersecurity and its dependencies on information security, network security, Internet security and critical information infrastructure protection. The 2023 edition instead explicitly explains the relationship between Internet security, web security, network security and cybersecurity, and provides high-level guidance for common Internet-security issues.


2. Clause-by-clause structural comparison

The following is the most useful way to understand the transition.

Clause 1 — Scope

2012:
Scope was framed around improving the state of cybersecurity, with emphasis on cyberspace and its stakeholders.

2023:
Scope is oriented toward Internet security, including its relationship with web security, network security and cybersecurity.

What changed?

The conceptual centre moved:

2012

Cybersecurity → Cyberspace → Stakeholders → Assets → Threats → Controls

2023

Internet Security → Relationship with other security domains → Interested Parties → Risk → Security Guidelines

This is arguably the most important change in the entire revision.

For an automobile manufacturer, this means you should not present 27032:2023 as the complete cybersecurity framework for the factory. Instead, position it as an Internet-security guidance layer within the broader cybersecurity ecosystem.


3. Clause 2 — Applicability vs Normative References

2012

Clause 2 was:

Applicability

with:

  • 2.1 Audience
  • 2.2 Limitations

This explicitly discussed who the standard was intended for and its limitations.

2023

Clause 2 becomes:

Normative references

The audience/applicability material is no longer structured as a separate clause in the same way.

Manufacturing implication

This is a move away from a long introductory explanation toward a more conventional standards structure.

For training, don't spend excessive time on the old 2012 "audience/limitations" structure.


4. Clause 3 — Normative References → Terms and Definitions

2012

Clause 3:

Normative references

2023

Clause 3:

Terms and definitions

The 2023 structure moves terminology earlier, which makes sense because the standard introduces a number of related concepts.

Training activity

Ask participants:

"What is the difference between cybersecurity, Internet security, network security and web security?"

Then create this hierarchy:

Cybersecurity

Internet Security

Network Security / Web Security

This distinction is particularly useful for IT managers and plant engineering teams.


5. Clause 4 — Terms and Definitions → Abbreviated Terms

2012

Clause 4:

Terms and definitions

2023

Clause 4:

Abbreviated terms

This is largely a restructuring change.

The terminology itself becomes important because the 2023 standard deliberately distinguishes the security domains rather than treating "cybersecurity" as one large undifferentiated area.

Video on Internet Security



6. Clause 5 — Abbreviated Terms → Security-Domain Relationships

This is a major conceptual change.

2012

Clause 5:

Abbreviated terms

2023

Clause 5:

Relationship between Internet security, web security, network security and cybersecurity

This is one of the most important additions to your training.

Recommended training model

 


The 2023 edition explicitly establishes this relationship. (PECB)

Automobile example

A connected vehicle may involve:

  • vehicle cybersecurity
  • Internet connectivity
  • cloud services
  • web applications
  • APIs
  • mobile applications
  • supplier networks
  • plant networks
  • corporate IT
  • OT networks

Therefore, one cyber incident can cross several security domains.


7. Clause 6 — Overview

2012

Clause 6:

Overview

with:

  • 6.1 Introduction
  • 6.2 Nature of Cyberspace
  • 6.3 Nature of Cybersecurity
  • 6.4 General Model
  • 6.5 Approach

The 2012 edition spent significant effort explaining cyberspace itself.

2023

Clause 6:

Overview of Internet security

The focus is much more directly on Internet security.

Key transition

2012: "What is cyberspace and what is cybersecurity?"

2023: "What is Internet security and how should organizations address Internet-security risks?"

This is a significant change in philosophy.


8. Clause 7 — Stakeholders → Interested Parties

2012

Clause 7:

Stakeholders in the Cyberspace

including:

  • Consumers
  • Providers

2023

Clause 7:

Interested parties

with categories including:

  • Users
  • Coordinator and standardization organizations
  • Government authorities
  • Law enforcement agencies
  • Internet service providers

The structural comparison is documented by PECB. (PECB)

Why this matters

The 2012 standard looked at stakeholders operating within cyberspace.

The 2023 standard looks more specifically at parties involved in Internet security.

Automotive example

Your stakeholder map could therefore include:

Interested party

Automotive example

Users

Employees, dealers, customers

Organization

OEM

ISP

Internet connectivity provider

Suppliers

Tier 1/Tier 2 suppliers

Government

CERT-In / regulatory authorities

Law enforcement

Cybercrime authorities

Standardization bodies

ISO/IEC, industry bodies

Service providers

Cloud/SaaS providers


9. Clause 8 — Assets → Internet Security Risk Assessment

This is another major change.

2012

Clause 8:

Assets in the Cyberspace

with:

  • Personal assets
  • Organizational assets

2023

Clause 8:

Internet security risk assessment and treatment

with:

  • 8.1 General
  • 8.2 Threats
  • 8.3 Vulnerabilities
  • 8.4 Attack vectors

This represents a substantial shift.

Manufacturing activity

Give each team a connected-factory scenario:

MES (Manufacturing Execution System) server → Production network → PLC → Machine → Quality database

Ask:

  1. What is the asset?
  2. What is the threat?
  3. What vulnerability exists?
  4. What is the attack vector?
  5. What would be the business impact?
  6. What treatment should be applied?
In other words:

Asset = What are we protecting?
Threat = What can happen / who or what can cause harm?
Vulnerability = What weakness allows it to happen?
Attack Vector = How does the threat exploit the weakness?
Impact = What happens to the business?
Treatment = What will we do about the risk?

This directly translates the 2023 structure into manufacturing practice.


10. Clause 9 — Threats → Internet Security Guidelines

This is arguably the largest structural transformation.

2012

Clause 9:

Threats against the security of the Cyberspace

including:

  • 9.1 Threats
  • 9.2 Threat agents
  • 9.3 Vulnerabilities
  • 9.4 Attack mechanisms

2023

Clause 9:

Security guidelines for the Internet

with a broad set of operational areas.

The 2023 structure includes:

  1. General
  2. Policies for Internet security
  3. Access control
  4. Education, awareness and training
  5. Security incident management
  6. Asset management
  7. Supplier management
  8. Business continuity over the Internet
  9. Privacy protection over the Internet
  10. Vulnerability management
  11. Network management
  12. Protection against malware
  13. Change management
  14. Legislation and compliance
  15. Cryptography
  16. Application security for Internet-facing applications
  17. Endpoint device management
  18. Monitoring

These changes are documented in the detailed structural comparison. (PECB)

This is extremely relevant to your training programme.

The 2023 standard essentially takes you from:

"Understand cyber threats"

to:

"What should the organization actually do about Internet security?"


11. Clause 9.2.2 — Internet Security Policies

This is particularly useful for management.

For an automobile manufacturer, translate this into:

Plant Internet Security Policy

Questions:

  • Who can connect plant systems to the Internet?
  • Who approves Internet-facing applications?
  • Who approves remote access?
  • Who owns Internet-connected assets?
  • What constitutes unacceptable Internet use?
  • How are exceptions approved?
  • How are third-party connections controlled?

12. Clause 9.2.3 — Access Control

This should become a major workshop topic.

Manufacturing examples

  • Employee login
  • Privileged administrator accounts
  • Vendor remote access
  • Engineering workstation access
  • PLC programming access
  • MES access
  • VPN access
  • Cloud dashboards
  • Dealer portals

Practical rule

No person + no device + no application should receive more Internet-connected access than required for the job.


13. Clause 9.2.4 — Education, Awareness and Training

This is especially relevant to your role as a trainer.

Participants should learn:

  • phishing recognition
  • password hygiene
  • MFA
  • suspicious USB/device handling
  • social engineering
  • reporting procedures
  • remote-access risks
  • data sharing
  • safe browsing
  • incident escalation

Manufacturing activity

"One Minute Cyber Decision"

Give workers 10 scenarios:

Unknown USB found near workstation.

Vendor asks for temporary VPN access.

Manager requests password through WhatsApp.

Unexpected software update appears.

Participants answer:

STOP / PROCEED / REPORT


14. Clause 9.2.5 — Security Incident Management - Video Link - Hindi - Tamil


TAMIL - VIDEO



This is much more directly operational than simply talking about threats.

Create a simple plant response model:

IDENTIFY

   ↓

VERIFY

   ↓

REPORT

   ↓

CONTAIN

   ↓

INVESTIGATE

   ↓

RECOVER

   ↓

LEARN

For manufacturing, add:

"Protect production safety before restoring IT connectivity."



15. Clause 9.2.6 — Asset Management

This connects directly with your earlier competency/risk work.

Create an:

Internet-Connected Asset Register

Asset

Owner

Location

Internet exposure

Criticality

Risk

MES

IT

Plant

Yes

Critical

High

Engineering workstation

Engineering

Line 2

Limited

High

High

PLC

OT

Assembly

Indirect

Critical

Critical

Vendor laptop

Supplier

Plant

Temporary

High

High

HR system

HR

Corporate

Yes

Medium

Medium


16. Clause 9.2.7 — Supplier Management

This is highly relevant to automobile manufacturing.

A modern OEM has hundreds or thousands of external relationships.

Potential access includes:

  • supplier portals
  • VPN
  • remote maintenance
  • cloud platforms
  • software updates
  • engineering data
  • production equipment
  • diagnostic systems

Supplier Cybersecurity Checklist

Before granting access:

Business justification
Named individual
Named device
Defined access period
MFA
Least privilege
Approval
Logging
Monitoring
Access removal after completion


17. Clause 9.2.8 — Business Continuity over the Internet

The 2012 version had broader cybersecurity continuity concepts.

The 2023 version explicitly brings business continuity over the Internet into its security guidelines.

Manufacturing scenario

Suppose:

Internet connectivity to the plant is unavailable for 6 hours.

Ask:

  • Can production continue?
  • Can MES operate?
  • Can suppliers communicate?
  • Can logistics operate?
  • Can quality systems operate?
  • Can remote support operate?
  • What becomes manual?

This produces a Cyber Business Continuity Exercise.


18. Clause 9.2.9 — Privacy Protection over the Internet

This is another area that deserves more attention in today's connected environment.

Automotive organizations may process:

  • employee information
  • customer information
  • dealer information
  • vehicle data
  • telemetry
  • location information
  • video/CCTV
  • biometric/access information

The security discussion therefore extends beyond protecting corporate files.


19. Clause 9.2.10 — Vulnerability Management

This is an important evolution from simply identifying vulnerabilities.

Manufacturing vulnerability cycle


For legacy OT systems where patching may be dangerous:

Identify → Assess → Compensating Controls → Monitor → Planned Remediation


20. Clause 9.2.11 — Network Management

This becomes particularly important for your automobile manufacturing audience.

SCADA - Supervisory Control and Data Acquisition 
PLC - Programmable Logic Controller

21. Clause 9.2.12 — Protection Against Malware

This encompasses:

  • ransomware
  • trojans
  • spyware
  • malicious downloads
  • infected removable media
  • malicious attachments
  • compromised software

Manufacturing scenario

A supplier technician connects an infected laptop to an engineering workstation.

Ask:

What happens next?

Teams identify:

Entry → Propagation → Detection → Isolation → Recovery


22. Clause 9.2.13 — Change Management


This is often underestimated in manufacturing.

Cybersecurity can be compromised through legitimate changes.

Examples:

  • PLC firmware update
  • firewall configuration
  • Windows update
  • new application
  • new IoT sensor
  • network change
  • vendor software installation
  • cloud integration

Rule - Every technological change can create a cybersecurity change.


23. Clause 9.2.14 — Legislation and Compliance

The organization needs to identify applicable:

  • cybersecurity requirements
  • privacy requirements
  • contractual requirements
  • regulatory requirements
  • industry requirements

For an Indian automotive organization, this should be connected to the organization's legal/compliance function rather than treated purely as an IT responsibility.


24. Clause 9.2.15 — Cryptography

This covers protection mechanisms such as:

  • encryption
  • secure communications
  • cryptographic controls
  • key management

Automotive examples include:

  • VPN
  • TLS
  • encrypted databases
  • secure APIs
  • encrypted remote access
  • protected communications between systems

25. Clause 9.2.16 — Internet-Facing Application Security

This is particularly important because automotive organizations increasingly expose:

  • supplier portals
  • dealer portals
  • customer applications
  • APIs
  • cloud applications
  • e-commerce services
  • employee portals
  • connected-vehicle services

Activity

Attack Surface Mapping

Teams identify:

What applications does our organization expose to the Internet?

Then ask:

  1. Who owns it?
  2. What data does it process?
  3. What authentication does it use?
  4. What happens if it is compromised?
  5. Is it monitored?

26. Clause 9.2.17 — Endpoint Device Management

Endpoints can include:

  • laptops
  • desktops
  • mobile phones
  • tablets
  • engineering workstations
  • diagnostic devices
  • remote-support systems

Daily checklist

Screen locked
Approved software only
Antivirus/EDR active
OS updated
USB controlled
MFA enabled
Suspicious activity reported


27. Clause 9.2.18 — Monitoring

This is an important operational element.

Organizations need visibility into:

  • unusual logins
  • failed authentication
  • abnormal network activity
  • malware alerts
  • suspicious remote access
  • unusual data transfers
  • unexpected configuration changes

Manufacturing principle

You cannot protect what you cannot see.


28. What happened to 2012 Clause 10?

2012 Clause 10

Roles of stakeholders in Cybersecurity

with:

  • 10.1 Overview
  • 10.2 Roles of consumers
  • 10.3 Roles of providers

2023

This concept is reorganized under:

Clause 7 — Interested parties

and the security guidance in Clause 9.

So the role-based philosophy hasn't disappeared completely; it has been reorganized around Internet-security interested parties and security guidance.


29. What happened to 2012 Clause 11?

2012

Guidelines for stakeholders

including:

  • Risk assessment and treatment
  • Guidelines for consumers
  • Guidelines for organizations and service providers

2023

Risk assessment gets its own:

Clause 8 — Internet security risk assessment and treatment

while practical security guidance moves into:

Clause 9 — Security guidelines for the Internet

This is an important improvement in structure.


30. What happened to 2012 Clause 12?

2012

Cybersecurity controls

including:

  • Application-level controls
  • Server protection
  • End-user controls
  • Social engineering controls
  • Cybersecurity readiness
  • Other controls

2023

These are reorganized under:

9.2 Controls for Internet security

with substantially broader categories.

This is why I would describe the 2023 version as more operationally organized rather than simply "new controls."


31. What happened to 2012 Clause 13?

This is a very important change.

2012

Clause 13:

Framework of information sharing and coordination

including:

  • Policies
  • Methods and processes
  • People and organizations
  • Technical aspects
  • Implementation guidance

2023

There is no equivalent standalone Clause 13 framework.

Instead, coordination is reflected through the interested-party model and the various Internet-security practices.

Training implication

Do not teach the old 2012 information-sharing framework as if it were a current mandatory clause.

Instead, teach:

Who needs to know? → What needs to be reported? → When? → Through which channel?


32. Annexes — Major Change

2012 Annexes

Annex A: Cybersecurity readiness
Annex B: Additional resources
Annex C: Examples of related documents

2023

Annex A: Cross-references between ISO/IEC 27032:2023 controls and ISO/IEC 27002

This is strategically important.

The 2023 edition therefore makes it easier to connect Internet-security guidance with an organization's broader information-security control environment. PECB specifically identifies this cross-reference as one of the significant changes. (PECB)


33. The biggest conceptual difference

I would explain it to your automobile manufacturing participants this way:

This reflects the restructuring documented by PECB and the scope descriptions published by ISO. (PECB)


34. Automobile manufacturing mapping

For your 2-day automobile manufacturing programme, I would map the standard like this:

ISO/IEC 27032:2023

Automobile manufacturing application

Clause 5

IT / OT / Internet / Web security relationship

Clause 6

Connected factory cybersecurity

Clause 7

Employees, suppliers, ISPs, government, customers

Clause 8

Cyber risk assessment

8.2

Threat identification

8.3

Vulnerability identification

8.4

Attack-vector identification

9.2.2

Plant Internet-security policy

9.2.3

Identity & access management

9.2.4

Employee cyber awareness

9.2.5

Cyber incident response

9.2.6

Asset inventory

9.2.7

Supplier/third-party security

9.2.8

Cyber business continuity

9.2.9

Privacy

9.2.10

Vulnerability management

9.2.11

IT/OT network management

9.2.12

Malware/ransomware

9.2.13

Change management

9.2.14

Legal/compliance

9.2.15

Encryption

9.2.16

Internet-facing applications

9.2.17

Endpoint management

9.2.18

Monitoring

Annex A

Mapping to ISO/IEC 27002


DAY 1 — UNDERSTAND & ASSESS

Module 1 — Cybersecurity vs Internet Security → Clause 5

The Connected Automotive Enterprise

Purpose

To help participants understand how deeply the automobile organization is connected to the Internet and external digital ecosystem.

Coverage

Corporate Environment

  • Email
  • ERP
  • HR systems
  • Finance
  • Collaboration tools
  • Cloud applications

Engineering Environment

  • CAD
  • PLM
  • Engineering workstations
  • Product-development systems
  • Simulation platforms
  • R&D databases

Manufacturing Environment

  • Plant IT
  • MES
  • SCADA
  • PLCs
  • Industrial computers
  • IIoT devices
  • Connected machinery

External Ecosystem

  • Suppliers
  • Vendors
  • Cloud providers
  • Logistics partners
  • Engineering partners
  • Maintenance contractors
  • Dealers/service ecosystem

Connected Product Ecosystem

  • Telematics
  • Mobile applications
  • Cloud services
  • OTA infrastructure
  • Connected vehicle services

Activity 1 – “Draw Our Connected World”

Each team receives a blank sheet.

They draw: Internet → Enterprise → Plant → OT → Suppliers → Connected Products

Then identify:

  • What connects to what?
  • Who has access?
  • What information moves?
  • Where are external connections?
  • Which connection would worry you most?

Key Takeaway

Cybersecurity starts with knowing what is connected, who is connected and why.


Module 2 — Connected Automotive Ecosystem → Clause 6

ISO/IEC 27032:2023 & the Cybersecurity Ecosystem

ISO/IEC 27032:2023 specifically explains the relationship between Internet security, web security, network security and cybersecurity and identifies interested parties and their roles. (ISO)

Participants learn:

  • What ISO/IEC 27032 is
  • What it is intended to address
  • Internet security
  • Web security
  • Network security
  • Cybersecurity
  • Stakeholder responsibilities
  • Common Internet-security issues

Important comparison

Standard / Framework

Primary Focus

ISO/IEC 27001

Organizational Information Security Management System

ISO/IEC 27002

Information-security controls guidance

ISO/IEC 27032

Internet security

ISO/IEC 27033

Network security

TISAX / VDA ISA

Automotive information-security assessment ecosystem

ISO/SAE 21434

Vehicle cybersecurity engineering

ISO 22301

Business continuity

 

Activity 2 – “Which Standard Addresses What?”

Teams receive 20 scenarios.

Examples:

Employee shares confidential CAD data externally.

ECU has a cybersecurity vulnerability.

Supplier requires remote access.

Factory loses network connectivity.

Employee receives phishing email.

Teams identify which framework/standard is primarily relevant.

Key Takeaway

No single cybersecurity standard secures the entire automotive ecosystem. They must work together.


Module 3 — Interested Parties & Responsibilities
→ Clause 7

 

Automotive Cyber Threat Landscape

Threat Categories

1. Human

  • Phishing
  • Social engineering
  • Credential theft
  • Insider threats

2. Technical

  • Malware
  • Ransomware
  • Vulnerability exploitation
  • Misconfiguration

3. Connectivity

  • Remote access
  • Cloud
  • APIs
  • IoT
  • IIoT
  • Supplier connections

4. Supply Chain

  • Compromised supplier
  • Compromised software
  • Third-party credentials
  • Vendor remote access

5. Business

  • Data theft
  • Production disruption
  • Service disruption
  • Reputation damage

Activity 3 – Threat Ranking

Give each team 15 threat cards.

They rank them:

High / Medium / Low

based on:

Likelihood × Impact

Then compare their rankings with other teams.

Key Takeaway

A cyber threat becomes a business risk when it can affect people, information, operations, customers, production or reputation.


Module 4 — Cyber Risk Assessment → Clause 8

Cyber Attack Surface & Asset Identification

This is one of the most important practical modules.

Participants identify:

  • Internet-facing websites
  • Email systems
  • VPN
  • Remote-access gateways
  • Cloud systems
  • Web applications
  • APIs
  • Supplier portals
  • Mobile applications
  • Engineering systems
  • IoT
  • IIoT
  • Plant IT
  • OT gateways

Worksheet – Internet Exposure Register

Asset

Owner

Internet Connected?

External Users?

Criticality

Risk

Action

VPN

IT

Yes

Employees/Vendors

High

High

Review

Supplier Portal

SCM/IT

Yes

Suppliers

High

High

Assess

Engineering Server

R&D/IT

Limited

Engineers

High

High

Review

IIoT Gateway

OT

Yes

Vendor

High

High

Segment

Activity 4 – Attack Surface Mapping

Teams map:

External Entry Point

System

User

Internal Network

Critical Asset

They then identify where controls should stop the progression.

Key Takeaway - You cannot protect what you have not identified.


Module 5 — Threats, Vulnerabilities & Attack Vectors → Clause 8.2–8.4

Internet, Network & Communication Security

Topics

  • Network security fundamentals
  • Secure connectivity
  • Firewalls
  • Segmentation
  • Access control
  • Secure protocols
  • Encryption
  • HTTPS/TLS awareness
  • VPN
  • Remote access
  • Email security
  • Network monitoring

Automotive application

Discuss:

Corporate Network

vs

Engineering Network

vs

Plant Network

vs

OT Network

vs

Supplier Network

Activity 5 – Network Segmentation Exercise

Give participants a fictional plant network.

Ask:

Which systems should communicate?

Which systems should never communicate directly?

Where should additional controls exist?

Key Takeaway - Connectivity should be intentional—not automatic.


Module 6 — Human Cyber Risk → Clause 9.2.4

Cloud, Web Applications & API Security

Coverage

  • Cloud applications
  • SaaS
  • Web applications
  • APIs
  • Authentication
  • Authorization
  • Data exposure
  • Misconfiguration
  • Excessive privileges
  • Logging
  • Monitoring
  • Third-party cloud services

Case Study

“The Supplier Portal Incident”

A supplier portal accidentally exposes confidential engineering information.

Participants determine:

  1. What failed?
  2. What information was exposed?
  3. Who should have detected it?
  4. What control should have prevented it?
  5. What should happen immediately?
  6. What should be changed permanently?

Worksheet

Question

Finding

What data is exposed?

Who can access it?

Is authentication adequate?

Is authorization adequate?

Is sensitive data encrypted?

Are logs available?

Who monitors the system?

What corrective action is required?

Key Takeaway - A cloud service is not automatically secure simply because it is hosted by a cloud provider.


DAY-1 TAKEAWAY SHEET

Every participant completes:

TODAY I LEARNED

  1. The three most important cyber risks in my function:


  2. The most important Internet-connected asset I deal with:



  3. The biggest weakness I have observed:



  4. One thing I should stop doing:



  5. One thing I should start doing:



  6. One thing I should report:



DAY 2 — PROTECT & RESPOND

Module 7 — Internet Security Controls → Clause 9.2

IT/OT Convergence & Connected Manufacturing

The Core Model

Corporate IT

Plant IT

Manufacturing Network

OT

PLC / SCADA / Machines

Topics

  • IT/OT convergence
  • OT availability
  • Legacy systems
  • Remote maintenance
  • Vendor access
  • Engineering workstations
  • Industrial networks
  • IIoT
  • Network segmentation
  • Monitoring
  • USB/removable media
  • Secure remote support

Activity 6 – “Protect the Production Line”

Give participants a scenario:

A machine vendor requires remote access to troubleshoot a production machine.

Teams determine:

  • Who authorizes access?
  • How is identity verified?
  • What system can they access?
  • How long is access permitted?
  • Is MFA required?
  • Is the session monitored?
  • Is access recorded?
  • How is access removed?
  • What happens after maintenance?

Key Takeaway - Remote access is a controlled privilege—not a permanent convenience.


Module 8 — Access & Endpoint Security → 9.2.3 + 9.2.17

“From Phishing Email to Production Disruption”

This is the major Day-1 activity.

Scenario

9:00 AM

Employee receives a convincing email.

9:30 AM

Credentials are compromised.

10:30 AM

Unauthorized access is detected.

11:30 AM

An internal engineering system shows abnormal activity.

12:30 PM

Plant IT begins experiencing disruption.

1:30 PM

Production-support systems become unavailable.

Team Task

Identify:

  • Initial entry point
  • Attack surface
  • Vulnerable control
  • Critical assets
  • Business impact
  • Detection opportunity
  • Containment opportunity
  • Recovery requirement

Deliverable

Each team creates:

Cyber Attack Chain Map

Entry → Access → Movement → Target → Impact → Control


Module 9 — IT/OT & Network Security → 9.2.11

Identity, Authentication & Access Management

Topics

  • Identity
  • Authentication
  • MFA
  • Passwords
  • Privileged accounts
  • Least privilege
  • Access approval
  • Access review
  • Service accounts
  • Vendor accounts
  • Remote access
  • Joiner/Mover/Leaver controls

Principle

Right Person + Right Access + Right Purpose + Right Time

Daily Access Checklist

I use only my own credentials.

I do not share passwords.

MFA is enabled where required.

I lock my workstation when leaving.

I report suspicious login activity.

I do not use unauthorized accounts.

I do not grant access without authorization.

Vendor access is time-bound.

Privileged access is controlled.

Former/transfer employees' access is reviewed promptly.


Module 10 — Supplier & Third-Party Cybersecurity→ 9.2.7

Endpoint, Network & Data Protection

Coverage

  • Endpoint security
  • Antivirus/EDR awareness
  • Patch management
  • Vulnerability management
  • Secure configuration
  • Network segmentation
  • Firewall
  • Encryption
  • Data classification
  • Backup
  • Data-loss prevention

Activity 7 – Secure Your Workstation

Give participants 20 workstation behaviours.

They classify:

SAFE / UNSAFE / NEEDS APPROVAL

Examples:

Installing unauthorized software.

Connecting personal USB.

Sending confidential engineering data to personal email.

Leaving workstation unlocked.

Installing an approved update.

Sharing credentials with a colleague.

Key Takeaway

Cybersecurity is a series of small decisions made every day.


Module 11 — Incident Management & Ransomware → 9.2.5 + 9.2.12

Human Cybersecurity – Phishing & Social Engineering

Topics

  • Phishing
  • Spear phishing
  • Business-email compromise
  • Fake invoices
  • Fake password-reset requests
  • Malicious attachments
  • Suspicious links
  • Social engineering
  • Impersonation
  • Urgency manipulation

The 5-Question Test

Before clicking:

1. Who sent it?

2. Was I expecting it?

3. Is the request unusual?

4. Does the link/destination make sense?

5. Can I verify through another channel?

Activity 8 – Phishing Identification

Participants review simulated messages and classify:

GENUINE / SUSPICIOUS / REPORT IMMEDIATELY

Golden Rule

STOP → VERIFY → REPORT

Not:

CLICK → DISCOVER → PANIC


Module 12 — Vulnerability & Change Management→ 9.2.10 + 9.2.13

IoT, IIoT & Connected Manufacturing Security

Topics

  • IoT
  • IIoT
  • Sensors
  • Connected machines
  • Industrial gateways
  • Cloud-connected equipment
  • Remote monitoring
  • Device identity
  • Device lifecycle
  • Firmware
  • Network exposure
  • Monitoring

Worksheet – Connected Device Risk Review

Question

Yes/No

Action

Is the device connected to a network?

Is Internet access required?

Does it have unique credentials?

Is MFA available?

Is remote access enabled?

Is access monitored?

Is firmware maintained?

Is the device inventoried?

Is the device segmented?

Who owns the device?

What happens if it is compromised?

Key Takeaway

Every connected device should have an owner, purpose, identity, access control and lifecycle.


Module 13 — Business Continuity & Monitoring → 9.2.8 + 9.2.18

Supplier, Third-Party & Supply-Chain Cybersecurity

Automotive organizations depend heavily on suppliers and external service providers.

Risk areas

  • Supplier portals
  • Remote maintenance
  • Cloud services
  • Software providers
  • Engineering partners
  • Logistics providers
  • Managed IT services
  • Contractors

Supplier Risk Formula

Participants assess:

Information Access

  •  

System Access

  •  

Connectivity

  •  

Business Criticality

  •  

Potential Impact

Activity 9 – Supplier Cyber Risk Ranking

Each team receives five supplier profiles.

Supplier

Access

Criticality

Connectivity

Information

Overall Risk

A

High

High

High

High

B

Low

Medium

Low

Medium

C

Medium

High

High

High

D

High

Low

Medium

Low

Discussion

Which supplier requires the strongest controls?

Which supplier requires continuous monitoring?

Which supplier should have time-bound remote access?

Key Takeaway

Your cybersecurity posture is influenced by the security of the organizations connected to you.

Module 14 — 30-60-90 Day Cybersecurity Action Plan

Cybersecurity Monitoring & Incident Response

Incident Lifecycle

DETECT

VERIFY

CLASSIFY

ESCALATE

CONTAIN

ERADICATE

RECOVER

LEARN

Participants learn:

  • What constitutes a suspicious event
  • Who should be notified
  • Escalation
  • Evidence preservation
  • Containment
  • IT/OT coordination
  • Communication
  • Recovery
  • Lessons learned

Important principle

Participants should not independently investigate, alter or destroy potentially relevant evidence unless that is part of their authorized role and procedure.


SIGNATURE ACTIVITY

Connected Factory Cyber Incident Simulation

This should be the main experiential exercise of the entire two-day program.


Scenario

Stage 1 – Phishing

An employee receives a fake supplier email.

Stage 2 – Credential Compromise

The employee's credentials appear in an unusual login event.

Stage 3 – Remote Access

An unusual remote-access session is detected.

Stage 4 – Engineering

An engineering workstation behaves abnormally.

Stage 5 – Plant IT

Plant systems begin experiencing unusual network activity.

Stage 6 – OT Alert

OT monitoring identifies abnormal communication.

Stage 7 – Production Risk

Production-support systems become unavailable.

Stage 8 – Supplier

A supplier says its system may also have been affected.


SIMULATION ROLES

Participants are divided into:

Team A – IT

Responsible for enterprise systems.

Team B – OT

Responsible for plant systems.

Team C – Production

Responsible for manufacturing continuity.

Team D – Cybersecurity

Responsible for security coordination.

Team E – Management

Responsible for business decisions.

Team F – Supplier

Responsible for external-party coordination.


INCIDENT DECISION WORKSHEET

For every event:

Question

Team Response

What happened?

What do we know?

What do we not know?

What is the immediate risk?

What should be isolated?

Who must be informed?

What must NOT be done?

What evidence must be preserved?

Could production be affected?

What is the next decision?

Who owns the decision?


MANAGEMENT DECISION BOARD

Management must decide:

1. Do we isolate the affected system?

YES / NO / NEED MORE INFORMATION

2. Do we restrict remote access?

YES / NO

3. Do we stop a production process?

YES / NO / PARTIAL

4. Do we notify customers?

YES / NO / UNDER REVIEW

5. Do we notify the supplier?

YES / NO

6. Do we activate the incident-response team?

YES / NO

7. Do we activate business-continuity procedures?

YES / NO

This creates a realistic cross-functional decision environment without teaching offensive attack techniques.


MODULE 16

30/60/90-DAY CYBERSECURITY IMPLEMENTATION PLAN

The program should not end with the certificate.

Every participant should leave with an action plan.


FIRST 30 DAYS – VISIBILITY

Objective:

Know what you have and what is exposed.

Actions:

Identify Internet-facing assets.

Review critical external connections.

Review remote-access accounts.

Identify third-party connections.

Identify critical cloud services.

Identify connected OT/IIoT systems.

Confirm system owners.

Review privileged accounts.

Review critical supplier access.

Deliverable:

Connected Asset & Exposure Register


31–60 DAYS – CONTROL

Objective:

Reduce avoidable exposure.

Actions:

Remove unnecessary access.

Review inactive accounts.

Strengthen authentication.

Review MFA coverage.

Review remote-access controls.

Review network segmentation.

Review endpoint protection.

Review patch/vulnerability status.

Review backup arrangements.

Review supplier access.

Conduct cybersecurity awareness sessions.

Deliverable:

Cybersecurity Gap Closure Register


61–90 DAYS – RESILIENCE

Objective:

Detect faster and respond better.

Actions:

Review incident-response procedure.

Conduct phishing awareness exercise.

Conduct tabletop incident exercise.

Test IT/OT communication.

Test escalation matrix.

Review cybersecurity monitoring.

Conduct supplier incident scenario.

Conduct management simulation.

Document lessons learned.

Deliverable:

Cyber Incident Readiness Report


DAILY CYBERSECURITY CHECKLIST

This is the most important takeaway tool for day-to-day implementation.

Every Employee

Before Starting Work

Is my workstation/device behaving normally?

Have I received any unusual login/security notification?

Am I using my own credentials?

Is my workstation locked when unattended?

Are removable devices authorized?

Are there suspicious emails/messages requiring attention?


During Work

Am I accessing only information required for my job?

Am I sharing confidential information only through approved channels?

Am I using approved software?

Am I connecting only authorized devices?

Am I verifying unusual requests?

Am I protecting passwords and credentials?


Before Sending Information

Ask:

WHO?

Who is receiving it?

WHAT?

What information am I sending?

WHY?

Why do they need it?

WHERE?

Where is it being sent?

HOW?

Is this an approved method?


Before Clicking a Link

STOP

CHECK

VERIFY

REPORT if suspicious


SUPERVISOR'S DAILY CYBER CHECKLIST

Are employees following cybersecurity procedures?

Are shared accounts being used?

Are unauthorized USB devices being used?

Are contractors accessing systems?

Are vendor connections active?

Are suspicious activities being reported?

Have employees raised cybersecurity concerns?

Are new employees properly provisioned?

Have transferred employees had access reviewed?

Are terminated employees' accesses removed?

Are production systems being accessed only by authorized personnel?


IT/OT DAILY CHECKLIST

Review critical alerts.

Review unusual authentication events.

Review remote-access activity.

Review privileged access.

Review critical endpoint status.

Review suspicious network activity.

Review unauthorized device connections.

Review critical backup status.

Review major vulnerabilities.

Review vendor access.

Confirm incident-escalation readiness.


CYBERSECURITY RED-FLAG CHECKLIST

Employees should immediately report:

ACCESS

Unexpected password-reset message

Unknown login notification

MFA request not initiated by the user

Account locked unexpectedly

EMAIL

Suspicious attachment

Urgent payment request

Unexpected supplier communication

Request for credentials

Unusual link

DEVICE

Unusual pop-ups

Unexpected software

Sudden slowness

Antivirus/security alert

Unknown USB device

PRODUCTION

Unexpected machine behaviour

Unusual network activity

Unexplained system outage

Unauthorized remote access

Unusual engineering workstation behaviour

SUPPLIERS

Unexpected vendor connection

Vendor requesting emergency access

Unknown third-party account

Supplier reports suspicious activity


CYBERSECURITY OBSERVATION CARD

Every employee/supervisor can use this simple format:

I OBSERVED:


SYSTEM / AREA:


WHAT COULD GO WRONG?


IMMEDIATE ACTION TAKEN:


WHO WAS INFORMED?


RECOMMENDED IMPROVEMENT:


DATE:



CONNECTED ASSET CHECKLIST

For each connected asset:

Question

Yes

No

N/A

Action

Asset is identified

Owner identified

Business purpose defined

Internet connection known

External access known

Users identified

Privileged users identified

MFA reviewed

Network location known

Backup requirement defined

Vulnerability status known

Monitoring available

Incident owner identified

Vendor access reviewed


REMOTE ACCESS REVIEW WORKSHEET

Every external connection should be reviewed using:

Question

Response

Who requires access?

Why is access required?

What system is accessed?

Is access permanent or temporary?

Who approved it?

Is MFA enabled?

Is access limited to required systems?

Is activity logged?

Is activity monitored?

Can access be revoked immediately?

When was the access last reviewed?

What happens when the contract ends?

Key principle:

No permanent access merely because temporary access is inconvenient.


SUPPLIER CYBERSECURITY CHECKLIST

Before allowing significant third-party connectivity:

Supplier identified

Business justification documented

Information access identified

System access identified

Remote access identified

Named users identified

Authentication requirements established

MFA considered/required where appropriate

Access scope defined

Access duration defined

Logging enabled

Monitoring established

Incident notification expectations defined

Access-review frequency established

Exit/access-removal process defined


CLOUD / APPLICATION SECURITY CHECKLIST

For each critical cloud/web application:

Business owner identified

Technical owner identified

Data classification completed

User access reviewed

Privileged access reviewed

MFA considered/implemented

Logging available

Monitoring available

Backup/recovery requirements identified

Third-party dependencies identified

Security responsibilities understood

Incident escalation defined

Periodic security review established


IT/OT SECURITY CHECKLIST

Network

IT/OT boundaries defined

Network segmentation implemented

Remote access controlled

Vendor access controlled

Unnecessary connectivity removed

Devices

OT assets inventoried

Asset owners identified

Unsupported/legacy devices identified

USB/removable-media controls established

Access

Unique accounts used

Privileged access controlled

Remote access monitored

Monitoring

Critical systems monitored

Abnormal activity escalated

Incident-response contacts available


CYBER INCIDENT FIRST-RESPONSE CARD

When something suspicious happens:

1. STOP

Do not continue suspicious activity.

2. DON'T PANIC

Do not make uncontrolled changes.

3. REPORT

Notify the designated cybersecurity/IT contact immediately.

4. PRESERVE

Do not delete potentially relevant information unless instructed by the authorized response team.

5. ISOLATE ONLY AS AUTHORIZED

Follow the organization's incident procedure.

6. DOCUMENT

Record:

  • What happened
  • When it happened
  • What was observed
  • Who was informed
  • What action was taken

7. WAIT FOR INSTRUCTIONS

Do not independently investigate beyond your authorized role.


GROUP WORKSHEET

“FIND THE WEAK LINK”

Each team receives a connected automotive scenario.

They answer:

PEOPLE

Who could be exploited?

PROCESS

Which process could fail?

TECHNOLOGY

Which system could be compromised?

CONNECTION

Which connection creates exposure?

INFORMATION

What could be lost or altered?

OPERATIONS

What could happen to production?

CUSTOMER

What could happen to the customer?

CONTROL

Which control could prevent/detect/respond?


FINAL TEAM ASSIGNMENT

Each team develops a:

CONNECTED AUTOMOTIVE CYBERSECURITY IMPROVEMENT PLAN

Using this format:

Risk / Weakness

Impact

Current Control

Gap

Recommended Action

Owner

Priority

Due Date



DAY 1 — UNDERSTAND & ASSESS

MODULE 1 — Cybersecurity vs Internet Security

"Is Cybersecurity really an IT problem?"

Relevant ISO/IEC 27032:2023 theme: Relationship between cybersecurity, Internet security, network security and web security.

Real-world case: Toyota–Kojima Industries

In February 2022, Toyota supplier Kojima Industries suffered a cyberattack. Toyota subsequently halted production at all 14 Japanese plants because the supplier could not support the just-in-time production flow. Toyota later described how employees had to revert to paper-based processes while systems were unavailable. (ใƒˆใƒจใ‚ฟใ‚คใƒ ใ‚บ)

Facilitator question

"Toyota itself was not initially attacked. So why did Toyota's production stop?"

Allow participants to debate before revealing the supply-chain dependency.

Hands-on: Cyber Domino

Give teams cards:

Supplier → VPN → Network → MES → Production Planning → Logistics → Assembly Line → Customer

Remove one card.

Teams must identify the consequences.

Participant worksheet

Cyber Dependency Map

Dependency

What does it support?

If unavailable

Maximum tolerable downtime

Owner

Supplier portal

Material ordering

MES

Production

VPN

Vendor support

ERP

Planning

Workplace takeaway

Connected Dependency Map

Each participant identifies 5 critical digital dependencies in their own work area.


MODULE 2 — Connected Automotive Ecosystem

Real-world scenario

A modern automobile plant is connected to:

  • ERP
  • MES
  • SCADA
  • PLCs
  • robots
  • quality systems
  • warehouse systems
  • supplier portals
  • cloud systems
  • engineering systems
  • remote vendor support
  • employee devices

The important lesson is that the attack surface extends beyond the traditional "IT network."

Activity: Build Your Digital Factory

Give teams a blank factory diagram.

They must place:

๐Ÿ–ฅ IT
OT
๐Ÿค– Robots
๐Ÿ“ก IoT
Cloud
๐Ÿ”— Suppliers
๐Ÿ‘จ‍๐Ÿ’ป Vendors
๐Ÿ“ฑ Mobile devices
๐Ÿš— Connected vehicles

Then draw the communication paths.

Challenge

Ask:

"If an attacker compromises this device, what can they reach next?"

Hands-on deliverable

Connected Factory Attack Surface Map

Asset

Connected to

Internet exposed?

Business criticality

Owner

 

 

 

 

 

 

 

 

 

 

Daily implementation

Every department maintains a simple:

"What are we connected to?" map.


MODULE 3 — Interested Parties & Cybersecurity Responsibilities

Case: Supplier ecosystem failure

The Toyota/Kojima incident is excellent here because it demonstrates that cybersecurity responsibility doesn't stop at the OEM boundary. The attack on a Tier-1 supplier disrupted Toyota's production ecosystem. (PLOS)

Activity: Who Owns the Risk?

Give this scenario:

A vendor's remote-support account is compromised.

Ask each team:

  • IT?
  • OT?
  • Procurement?
  • Vendor?
  • Plant Head?
  • Cybersecurity?
  • Engineering?
  • Business owner?

Then introduce:

RACI Cybersecurity Model

Activity

IT

OT

Procurement

Vendor

Plant Head

Vendor approval

C

C

R

I

A

Remote access

R

C

I

R

A

Incident reporting

R

R

I

R

A

Access removal

R

R

I

C

A

Takeaway

Each participant creates:

"My Cybersecurity Responsibility Card"

I own ______
I must protect ______
I must report ______
I must never ______
I need support from ______


MODULE 4 — Cyber Risk Assessment

This should be one of the most hands-on modules.

Case

A production planning server is connected to:

  • ERP
  • MES
  • supplier network
  • engineering systems

A vulnerability is discovered.

Activity: Cyber Risk Auction

Give every team 100 imaginary "risk budget points."

Present risks one at a time:

  1. Phishing
  2. Ransomware
  3. Vendor VPN
  4. Unpatched server
  5. USB malware
  6. Insider misuse
  7. Cloud outage
  8. Internet-facing application

Teams must spend their limited budget on the risks they consider most important.

Then calculate:

Likelihood × Impact = Risk Score

Worksheet

Asset

Threat

Vulnerability

Likelihood 1–5

Impact 1–5

Score

Treatment

MES

Ransomware

Weak segmentation

4

5

20

Mitigate

Vendor VPN

Account compromise

No MFA

4

4

16

Mitigate

Takeaway

Participants leave with a: 5×5 Cyber Risk Matrix that they can use immediately.


MODULE 5 — Threats, Vulnerabilities & Attack Vectors


Case: Remote access vulnerability

Use the Kojima case to explain how an external business-partner connection reportedly provided an attack path into the supplier environment. Public analyses identify the incident as a major illustration of supply-chain and remote-connectivity risk. (PLOS)

Activity: Attack Vector Hunt

Give teams a fictional plant:

Supplier laptop → VPN → Plant network → Engineering workstation → MES

Teams receive cards:

  • Weak password
  • No MFA
  • Unpatched VPN
  • Phishing
  • Excessive privilege
  • Flat network
  • Shared account
  • Uncontrolled USB

They must construct the most likely attack chain.

Rule

Don't teach participants how to exploit the vulnerabilities technically.

Teach them how to recognise and break the chain.

Deliverable

Attack Vector Control Sheet

Attack vector

Warning sign

Preventive control

Owner

Phishing

Unexpected attachment

Email filtering + awareness

IT

Vendor VPN

Unusual login

MFA + monitoring

IT

USB

Unknown device

Device control

IT/OT


MODULE 6 — Human Factor, Awareness & Social Engineering

Real-world case

Social engineering remains particularly dangerous because a technically secure environment can still be compromised through human decisions. A 2024 case study involving a vehicle-parts manufacturer described both ransomware and a social-engineering incident, illustrating the importance of combining technical and human controls. (Raidar)

Activity: Phishing Detective

Give participants 5 simulated emails.

Example:

Subject: URGENT – Supplier Payment Account Changed

The email contains:

  • urgency
  • unusual sender
  • attachment
  • payment request
  • suspicious link

Participants mark:

๐ŸŸข Safe
๐ŸŸก Suspicious
๐Ÿ”ด Report

Second activity: CEO Fraud Role Play

Person A = Finance Manager
Person B = CEO
Person C = Attacker

The attacker asks for an urgent payment/account change.

Takeaway

STOP–CHECK–REPORT

Before:

  • clicking
  • downloading
  • sharing
  • paying
  • granting access

Workplace tool

60-second suspicious communication checklist

Do I know the sender?
Was I expecting this?
Is the request urgent?
Is money involved?
Is sensitive information requested?
Is there a link/attachment?
Should I verify independently?


DAY 2 — PROTECT & RESPOND

MODULE 7 — Internet Security Controls

Case

A vehicle manufacturer/supplier environment contains dozens of Internet-connected systems.

Ask:

"If you were allowed only 10 cybersecurity controls for this plant, what would you choose?"

Activity: Cybersecurity Survival Challenge

Give teams 20 control cards:

  • MFA
  • firewall
  • EDR
  • backup
  • network segmentation
  • patching
  • encryption
  • access control
  • awareness
  • monitoring
  • vulnerability management
  • logging
  • supplier assessment
  • incident response
  • etc.

Teams may select only 10.

Then introduce a new threat:

"Ransomware has entered through a supplier account."

Teams reassess their choices.

Learning

Cybersecurity is not:

"Buy more technology."

It is:

Risk → Priority → Control → Ownership → Monitoring

Takeaway

Top 10 Cyber Controls for My Department


MODULE 8 — IT/OT & Network Security

Case: Toyota supply-chain disruption

The Toyota/Kojima incident is particularly useful for demonstrating that manufacturing's cyber risk is ultimately an operational risk. Toyota's plants stopped because a supplier's systems could no longer support production. (ใƒˆใƒจใ‚ฟใ‚คใƒ ใ‚บ)

Activity: Secure the Factory



Give teams a network diagram:

INTERNET

    |

CORPORATE IT

    |

   ?

    |

MES

    |

OT NETWORK

    |

PLC

    |

ROBOT

    |

PRODUCTION

Teams must decide where to place:

  • firewall
  • DMZ
  • jump server
  • MFA
  • monitoring
  • vendor access
  • segmentation

Red-team challenge

One team designs the attack path.

Another team designs the defensive architecture.

Takeaway

My Plant's Critical Network Segmentation Questions

Is IT separated from OT?
Is vendor access controlled?
Is remote access authenticated?
Are critical systems monitored?
Are legacy devices protected?
Is unnecessary Internet connectivity removed?


MODULE 9 — Third-Party & Supply Chain Cybersecurity

Major case: Toyota–Kojima Industries

This should be your flagship supply-chain case study.

Toyota had to stop all 14 Japanese plants after its supplier Kojima Industries suffered a cyberattack. Toyota reported that the production shutdown lasted one day, while Kojima's recovery continued for considerably longer. (ใƒˆใƒจใ‚ฟใ‚คใƒ ใ‚บ)

Activity: Vendor Wants Access

Scenario:

A machine supplier says:

"Our engineer needs remote access immediately. Production is already delayed."

The vendor asks for:

  • VPN access
  • administrator rights
  • unrestricted network access

Teams have 5 minutes to decide.

Then reveal:

The vendor's laptop has an outdated endpoint security system.

Discussion

Should access be:

APPROVED / DENIED / CONTROLLED?

Vendor Cybersecurity Scorecard

Control

Yes

No

Evidence

MFA

Named accounts

Least privilege

Access expiry

Endpoint protection

Logging

Incident notification

Backup

Vulnerability management

Takeaway

Every participant should identify:Top 5 critical vendors in my function

and classify: Critical / High / Medium / Low cyber dependency


MODULE 10 — Incident Detection & Response

Case: Automotive ransomware

Automotive suppliers have experienced ransomware incidents that locked business-critical systems and required external incident-response support. For example, EDAG, an automotive engineering/supplier organization, publicly describes a ransomware incident affecting business-critical systems and subsequent incident-response activity. (Orange Cyberdefense)

Activity: Cyber Incident War Room

Give participants this first message:

09:05 AM: Production supervisor reports that 15 computers are displaying unusual messages.

Then progressively reveal:

09:10: MES unavailable.

09:15: Several shared drives inaccessible.

09:20: Supplier reports similar symptoms.

09:30: IT identifies abnormal network traffic.

Teams must decide:

  1. Who do we inform?
  2. What do we isolate?
  3. What must NOT be switched off?
  4. Do we stop production?
  5. Do we contact the vendor?
  6. Do we communicate externally?
  7. Who makes the final decision?

Deliverable

Incident Response Card

Takeaway - Each participant receives a one-page Cyber Incident Reporting Card.


MODULE 11 — Ransomware Simulation

This should be the high-energy capstone exercise.

Scenario

08:30 AM – Monday

Production starts normally.

09:05 AM

Operators report that files are inaccessible.

09:10 AM

MES becomes unavailable.

09:15 AM

Production planning cannot access schedules.

09:20 AM

A ransom message appears.

Round 1

Ask:

"What do you do?"

Teams write their first five actions.

Round 2

Reveal:

Backup server is still accessible.

Ask:

"Do you immediately restore?"

Round 3

Reveal:

An administrator account is still showing suspicious activity.

Now ask:

"What happens if you restore before containing the attacker?"

Round 4

Reveal:

Supplier communication is also unavailable.

Now teams must manage business continuity.

Scoring

Category

Points

Detection

10

Escalation

10

Containment

20

Production continuity

20

Communication

10

Recovery

20

Lessons learned

10

Total

100

Final takeaway

Each team creates:

Plant Ransomware First-60-Minutes Checklist


MODULE 12 — Vulnerability & Change Management

Case scenario

Engineering wants to install new software on an engineering workstation.

Production says:

"Install it immediately."

IT says:

"The software has not completed security testing."

Engineering says:

"Without it, the machine cannot operate efficiently."

Activity: Change Approval Board

Participants play:

  • Plant Head
  • Production
  • Engineering
  • IT
  • OT Cybersecurity
  • Quality
  • Vendor

They must approve/reject/modify the change.

Change Risk Worksheet

Question

Yes/No

Is the asset critical?

Is the software approved?

Has vulnerability testing been done?

Is a rollback available?

Has backup been verified?

Has downtime been planned?

Has vendor access been controlled?

Has security approval been obtained?

Takeaway

No change without security thinking.

Participants leave with a Cybersecurity Change Assessment Form.


MODULE 13 — Business Continuity, Monitoring & Recovery

Case: Kojima recovery

Toyota's account of the Kojima incident describes employees reverting to paper-based processes and manually organising information while systems were unavailable. (ใƒˆใƒจใ‚ฟใ‚คใƒ ใ‚บ)

This is an excellent opportunity to teach:

Cyber resilience is not only about preventing the attack. It is about continuing the business when prevention fails.

Activity: Go Manual

Tell teams:

"Your MES has been unavailable for 4 hours."

They must design a manual process for:

  • production scheduling
  • material movement
  • quality records
  • maintenance
  • dispatch
  • supplier communication

Exercise

Give them:

Paper + marker + production orders

No laptops.

Challenge

Run the production process manually for 15 minutes.

Then ask:

"What information did you realise you normally depend on technology for?"

Takeaway

Department Business Continuity Card

Process

System normally used

Manual alternative

Maximum downtime

Owner

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 


MODULE 14 — Cybersecurity Culture & 30-60-90 Action Plan

This is where the training must become implementation-focused.

Activity: Cybersecurity Culture Diagnostic

Ask participants to score their department from 1–5:

Area

Score

Awareness

/5

Password/MFA discipline

/5

Incident reporting

/5

Vendor control

/5

Asset visibility

/5

Patch management

/5

Access control

/5

Backup/recovery

/5

Network security

/5

Management involvement

/5

Then create a:

Department Cybersecurity Heat Map

๐Ÿ”ด 1–2 = Immediate attention
๐ŸŸก 3 = Improvement required
๐ŸŸข 4–5 = Strong


Final Exercise — The Cybersecurity Command Centre

I would make this the final 60–90 minute integrated exercise.

Scenario

Participants are given a fictional automobile plant:

10,000 employees

300+ suppliers

Multiple production lines

MES + ERP + OT

Remote vendor support

Cloud applications

Connected equipment

At 9:00 AM:

A supplier reports a cyber incident.

At 9:10:

One plant application becomes unavailable.

At 9:20:

Employees receive phishing emails.

At 9:30:

Engineering reports abnormal machine behaviour.

At 9:40:

Media asks whether production has been compromised.

At 10:00:

Plant management asks:

"Can we continue production?"


Teams have to perform six roles

Team 1 — Cybersecurity

Identify and contain the threat.

Team 2 — IT

Protect infrastructure.

Team 3 — OT/Engineering

Protect production.

Team 4 — HR/People

Manage employee communication.

Team 5 — Procurement/Supply Chain

Manage suppliers.

Team 6 — Management

Make business decisions.


Final Participant Deliverables

This is what I would physically put into the participant workbook.

1. Connected Factory Map

"What am I connected to?"

2. Critical Asset Register

"What must I protect?"

3. Cyber Risk Register

"What can go wrong?"

4. Attack Vector Map

"How could it happen?"

5. Phishing Checklist

"Should I trust this?"

6. Cyber Incident Card

"What should I do first?"

7. Supplier Cybersecurity Checklist

"Can I trust this third party?"

8. IT/OT Security Checklist

"Is my plant environment protected?"

9. Cyber Change Assessment

"Is this change safe?"

10. Business Continuity Card

"What do we do if the system goes down?"

11. Department Cybersecurity Scorecard

"How mature are we?"

12. 30-60-90 Action Plan

"What will I actually change?"


30-60-90 Day Implementation Plan

First 30 Days — IDENTIFY

Participants should:

Identify critical digital assets
Identify Internet-connected systems
Identify critical suppliers
Review privileged accounts
Review vendor access
Identify major cyber risks
Check backup status
Review incident-reporting channels

Output

Department Cyber Risk Register


Days 31–60 — PROTECT

Remove unnecessary access
Implement/strengthen MFA
Review vendor access
Review endpoint protection
Improve network segmentation
Conduct phishing awareness
Review patch/vulnerability process
Test incident escalation

Output

Cybersecurity Improvement Tracker


Days 61–90 — RESILIENCE

Conduct ransomware tabletop exercise
Test backup restoration
Test manual production process
Review supplier cyber readiness
Conduct vulnerability review
Test incident communication
Establish cybersecurity KPIs
Present status to management

Output

Department Cybersecurity Maturity Score


Daily Cybersecurity Routine





The 5-5-5 Rule


Every day:

5 things to CHECK

  1. Suspicious emails
  2. Unusual system behaviour
  3. Unknown devices/USBs
  4. Unexpected access requests
  5. Unusual production/network behaviour

Every week:

5 things to REVIEW

  1. New users
  2. Privileged access
  3. Vendor access
  4. Security alerts
  5. Vulnerabilities

Every month:

5 things to TEST

  1. Incident response
  2. Backup
  3. Recovery
  4. Vendor access
  5. Employee awareness

Recommended Case Study Library

 

Case

Best module

Toyota–Kojima Industries, 2022

Supply chain, JIT, business continuity, risk

EDAG ransomware incident

Incident response, ransomware

Automotive parts manufacturer ransomware/social engineering case

Human factor

CDK Global 2024

Third-party dependency and ecosystem risk

Recent automotive ransomware cases

Threat landscape

Fictional connected-factory incident

IT/OT

Fictional supplier VPN compromise

Third-party access

Fictional MES ransomware

Incident command

Fictional engineering workstation compromise

Endpoint/change management

CDK Global is also a useful ecosystem case because the 2024 ransomware incident disrupted automotive dealership operations across a large customer base, demonstrating how a technology provider can become a critical dependency for an automotive ecosystem. (VicOne
























No comments:

Post a Comment