Cybersecurity
Course Pack: Cybersecurity Basics
Cybersecurity Part 2 – Cyber Awareness, Access Control & Credential Security
Course Description
This course equips water and wastewater professionals with practical skills to identify human-centric cyber threats, including spear-phishing and USB baiting on plant grounds. Participants will learn to eliminate risky credential habits—such as default manufacturer logins and shared operator accounts—by applying CISA passphrase standards and individual role-based access controls. The curriculum delivers actionable safeguards for securing remote access, managing third-party vendor windows, enforcing workstation lockouts, and conducting low-cost utility access audits.
Learning Objectives
1) Identify Social Engineering Hazards: Recognize spear-phishing emails, spoofed supplier communications, credential harvesting portals, and physical USB baiting attempts targeting plant personnel.
2) Eliminate Default & Shared Credentials: Understand the critical operational threats posed by hardcoded manufacturer passwords, shared operator logins, and unmanaged vendor remote access backdoors.
3) Enforce Workstation & Session Security: Implement mandatory screen timeouts, automatic lockouts, default read-only guest HMI accounts on live plant control systems.
4) Deploy MFA & Control Vendor Access: Mandate Multi-Factor Authentication (MFA) across remote entry points and establish strict, time-bound vendor access windows.
Agenda
1) Course Overview & Trends.
2) The Human Vector & Social Engineering.
3) Credential Hygiene & Password Risks.
4) Access Control, Session Management & Vendor Access.
Target audience
Water and wastewater operators, maintenance technicians, supervisors, asset managers, engineers, and finance/administrative staff involved in system operations, maintenance, planning, budgeting, or regulatory reporting.
Level
I, II, III, IV
Learning material and method
Online on-demand
Assessment
Knowledge check and quiz (80% correct and above)
Instructor
Tung Nguyen