Hogeschool West-Vlaanderen
Howest Brugge
Spoorwegstraat 4 - 8200 Brugge
Tel: 050 682666
studentadmin@howest.be - Website: www.howest.be
Industrial and IOT Security21494/2013/2627/1/53
Study guide

Industrial and IOT Security

21494/2013/2627/1/53
Academic year 2026-27
Is found in:
  • Bachelor of Cybersecurity, programme stage 5
This is a single course unit.
Study load: 6 credits
Total study time: 150,00 hours
Re-sit exam: is possible.
It is not possible to enrol in this course unit under
  • exam contract (to obtain a credit).
  • exam contract (to obtain a degree).
Co-ordinator: Brouckxon Henk
Other teaching staff: Kalantari Shirin, Singier Laurens
Teaching staff are not (all) known yet.
Language course: No
Languages: English

Omschrijving Volgtijdelijkheid (VT) (EN)

previously registered for Cyberops AND previously registered for Practical Reverse Engineering and Malware Analysis AND previously registered for Network and System Pentesting.

Omschrijving Doelstellingen (EN)

LR 1:
01.1.2 Explains principles of cybersecurity and the principles of relevant standards and frameworks related to cybersecurity
01.1.3 Enumerates possible organizational and high- level technical measures for mitigating risks and threats
01.2.1 Analyzes the threats to a defined system to determine associated cybersecurity requirements
01.3.1 Selects appropriate measures to mitigate risks
01.3.3 Evaluates measures that reduce the impact or likelihood of identified threats or risks in a realistic simulated context

LR 3:
03.1.4 Identifies and describes networks and protocols
03.2.2 Selects relevant security testing techniques (including penetration testing, vulnerability scanning, SAST, DAST) and interprets the results
03.3.1 Integrates security testing (including penetration testing, vulnerability scanning, SAST, DAST) in a simulated context
03.3.2 Relates operating system, network security and hardware vulnerabilities to a simulated context employing techniques to reduce the digital footprint

LR 4:
04.1.3 Articulates and characterizes the different environments such as IT, OT, IOT, within which cyber security is applied, including physical security of cyber assets
04.2.1 Configures and implements identification, authentication, authorization
04.2.2 Secures applications in an IT, OT, IOT, cloud, container, and physical context
04.2.6 Secures a cloud application

LR 5:
05.2.4 Assesses security in a cloud and virtualization environment

LR 7:
07.2.3 Creates an effective network monitoring environment
07.3.4 Installs and configures a cybersecurity detection and response solution in a simulated realistic context

LR 10:
10.4.1 Implements and documents a cybersecurity improvement project tailored to the organization, and executes it with relevant stakeholders within the preconditions of a project

Omschrijving Inhoud (EN)

Where some years ago the corporate IT networks of most companies mainly consisted of Windows and Linux based systems, modern networks increasingly see the addition of new systems and applications. Two important examples are Industrial Systems (also known as OT or Operational Technology, ranging from production machines to building management) and the Internet of Things (IoT), where various types of devices are connected to the network and the internet to allow new applications and remote management. Due to their nature and design, with limited local resources (processing/memory/...), wireless connections and antiquated protocols, these systems however frequently cause security (and safety) issues in the network.
In this course, we'll look into these Industrial and IoT systems, how they can be secured, and what is necessary to design and manage them in a good way. For this, we'll focus on the following three domains:

1. Industrial Security

  • Introduction to Industrial Control Systems (ICS/OT)
  • The basics of Automation Engineering
  • Industrial Communication

2. Radio Communication and Security

  • Introduction to analog and digital wireless communication
  • Software Defined Radio (SDR)
  • RFID and Near-Field Communication (NFC)

3. IOT Security

  • IoT cloud application development
  • API Development
  • API Authorization
  • API Integration Platforms

Omschrijving Studiematerialen (lijst) (EN)

Lecturer's courseMandatory
PresentationMandatory
WebcourseMandatory

Omschrijving Eindcompetenties (lijst) (EN)

PBACS001: Analyses critical business processes, data and infrastructure and makes a substantial contribution to cybersecurity by design and data protection by design through the identification, evaluation and mitigation of risks and threats, establishing an information security policy, including strategic objectives, procedures, guidelines and policies.
CodeDescription
PBACS001Analyses critical business processes, data and infrastructure and makes a substantial contribution to cybersecurity by design and data protection by design through the identification, evaluation and mitigation of risks and threats, establishing an information security policy, including strategic objectives, procedures, guidelines and policies.
PBACS003: Across the full range of software, firmware and hardware technologies, evaluates and improves the cybersecurity of (sub)systems by detecting, analysing and dealing with existing attack vectors and vulnerabilities, this by deploying existing defensive and offensive security software, including developing proprietary scripts, penetration testing, digital footprint reduction and participating in red teaming exercises.
CodeDescription
PBACS003Across the full range of software, firmware and hardware technologies, evaluates and improves the cybersecurity of (sub)systems by detecting, analysing and dealing with existing attack vectors and vulnerabilities, this by deploying existing defensive and offensive security software, including developing proprietary scripts, penetration testing, digital footprint reduction and participating in red teaming exercises.
PBACS004: Selects and configures the optimal techniques, including identification, authentication and authorization and applies these within mainstream environments including physical and industrial environments for each phase of the cyber security process.
CodeDescription
PBACS004Selects and configures the optimal techniques, including identification, authentication and authorization and applies these within mainstream environments including physical and industrial environments for each phase of the cyber security process.
PBACS005: Contributes to structuring and optimising a secure development life cycle in which each phase is adequately protected by an appropriate combination of technical and organizational controls, tailored to specific requirements within relevant domains
CodeDescription
PBACS005Contributes to structuring and optimising a secure development life cycle in which each phase is adequately protected by an appropriate combination of technical and organizational controls, tailored to specific requirements within relevant domains
PBACS007: Achieves prevention, detection, response, recovery and investigation of cyber threats and attacks through selecting, applying and interpreting the appropriate techniques.
CodeDescription
PBACS007Achieves prevention, detection, response, recovery and investigation of cyber threats and attacks through selecting, applying and interpreting the appropriate techniques.
PBACS010: Initiates, implements, substantiates, documents cybersecurity projects tailored to the organisation, working in a team-oriented way in a multidisciplinary context, setting appropriate priorities and demonstrating good time management, problem-solving ability. and self-critical attitude.
CodeDescription
PBACS010Initiates, implements, substantiates, documents cybersecurity projects tailored to the organisation, working in a team-oriented way in a multidisciplinary context, setting appropriate priorities and demonstrating good time management, problem-solving ability. and self-critical attitude.

Omschrijving Onderwijsvorm (EN)

  • Lecture
  • Exercise class

Omschrijving Evaluatie (lijst) (EN)

Evaluation(s) for first exam chance
MomentForm%Remark
exam period 1 (1st sem) (regular exam schedule)exam: specific method or combination of methods100,00
Evaluation(s) for re-sit exam
MomentForm%Remark
exam period 3 (august/september) (regular exam schedule)exam: specific method or combination of methods100,00