This October, Cyber-Physical Attack Methods training makes its return to the Industrial Control Systems (ICS) Cybersecurity Conference. The course is offered for a second consecutive year through SecurityWeek in partnership with MTSI, and it runs alongside the event’s 25th anniversary edition.
Instead of relying on high-level threat reports, the training focuses on how real attackers work step by step when targeting environments where digital systems connect to physical processes. It’s designed to help teams understand not only what can go wrong, but how vulnerabilities chain together to produce meaningful operational impact.
Why cyber-physical attacks matter beyond downtime
Cyber-physical systems bring together computing and the real world—linking software and networks with equipment, control logic, and operational workflows. When adversaries succeed, the consequences can extend far beyond data loss or temporary service interruption.
Depending on the environment, attacks may threaten safety, disrupt mission readiness, reduce productivity, affect revenue, or impact the availability of services people rely on. That broader risk is a central theme of the course: understanding attacker methods helps defenders make better design, engineering, and security decisions.
Training that helps you think like an attacker
Cyber-Physical Attack Methods training places participants directly in an adversary role. The course is structured as a multi-day, guided program where learners progress through phases that mirror how an attacker typically operates.
Participants work inside an intentionally vulnerable virtual cyber-physical environment. Through hands-on exercises, they move through activities such as system discovery, vulnerability exploitation, and the execution of mission-focused attacks. Rather than treating adversary behavior as abstract theory, the labs require learners to follow the process and complete the steps with their own hands on the keyboard.
Importantly, the goal is not to turn attendees into hackers. The intent is practical: to give the people responsible for designing, building, testing, and protecting these systems a grounded understanding of attacker thinking and behavior.
What you learn during the exercises
Across the lab progression, the training emphasizes the way attackers combine individual actions into outcomes that matter operationally. Learners practice capabilities such as:
- Enumerating systems and identifying what is reachable and relevant.
- Locating and exploiting weaknesses that can be chained for broader impact.
- Connecting discrete actions into consequences tied to mission objectives.
- Assessing mitigations and evaluating how defenses influence attacker pathways.
Because security gaps often originate earlier than the deployment stage, the course also encourages participants to reflect on how architecture, development choices, and security decisions can reduce attack surface and strengthen resilience.
A course for more than the cybersecurity team
Although security practitioners can benefit, Cyber-Physical Attack Methods training is especially relevant for the broader community building cyber-physical environments. The course is intended for roles such as systems engineers, security engineers, programmers, developers, designers, and testers.
This wider audience matters because many factors that determine whether a system withstands an attack are decided before a product ever reaches production. Engineers and developers who understand attacker methods are more likely to spot risky assumptions, anticipate unexpected paths, and incorporate security into design and validation activities.
No previous cybersecurity experience is required. That said, the course is guided for accessibility, and learners can get more value from the exercises if they are comfortable using the Linux command line and have some programming experience.
Who is delivering the course
The training is developed and delivered through MTSI’s cyber-physical systems team. Their experience includes work in hacking, reverse engineering, and penetration testing across mission-critical domains such as aviation, maritime, weapons, and defense systems.
Beyond delivery of training material, the team also conducts cyber-physical security research. They have competed successfully in high-profile capture-the-flag events, including competitions associated with DEF CON’s ICS Village and Biohacking Village.
Course format and location
Cyber-Physical Attack Methods training takes place in October 6–8 at the W Nashville. It aligns with the conference schedule so that participants can attend sessions when the training is not running.
The course begins with a full day of instruction on Tuesday, October 6. It then continues with half-day sessions on Wednesday and Thursday. This structure makes it easier for attendees to balance immersive lab time with the broader ICS Cybersecurity Conference programming.
What’s included with registration
The registration fee for the CAM course is $3,995. That price includes several elements intended to support learning during and after the event.
Included in the registration are:
- The complete Cyber Attack Methods training course
- A self-contained virtual machine with the CAM simulation, exercises, and lesson content
- A certificate of course completion
- Access to ICS Cybersecurity Conference sessions
- Conference meals, networking events, and social functions (full conference pass)
Another practical benefit: participants may retain the course virtual machine after the event. That means you can revisit exercises and continue learning beyond the classroom.
Hardware requirements and eligibility
To participate, attendees must bring an Intel-based laptop that can run the required virtual machine. ARM-based MacBooks are not supported.
Additionally, the course is available exclusively to United States citizens. Seats are limited, so interested engineers, developers, testers, and security professionals are encouraged to register as early as possible.
How the training connects to the 25th anniversary conference
The CAM course is scheduled to coincide with the 2026 ICS Cybersecurity Conference at the W Nashville on October 6–8. The overall event brings together operations and control engineers, IT and OT security professionals, government representatives, researchers, vendors, and critical infrastructure operators.
For attendees, pairing hands-on attacker method training with conference sessions can help translate lab insights into real-world conversations about security priorities, operational risk, and defensive strategy across critical infrastructure environments.
Is Cyber-Physical Attack Methods training right for you?
If you want more than a summary of attack techniques, Cyber-Physical Attack Methods training is built for that purpose. It’s designed for people who need practical context on how cyber-physical compromises unfold—from initial discovery to the point where weaknesses combine into operational impact.
It can be valuable whether you focus on security engineering, system design, software development, testing, or broader engineering decisions. The labs help you better understand attacker workflows, evaluate mitigations, and think about how architecture and development choices influence the resilience of systems over time.
With limited seats and a structure that supports both training and conference access, it’s an opportunity to learn the process directly and apply it to the defensive work you do every day.
Conclusion
Cyber-Physical Attack Methods training returns this October as a hands-on course alongside the ICS Cybersecurity Conference’s 25th anniversary edition. By working through attacker-style steps in a virtual cyber-physical environment, participants gain a practical understanding of how adversaries enumerate systems, exploit weaknesses, and drive mission-focused outcomes—while also exploring defenses and mitigation strategies.
For engineers, developers, testers, and security professionals who want to move beyond abstract descriptions and see the attack process firsthand, this multi-day training offers a focused, realistic learning experience with conference access included.
