The power grid that lights a city. The pipeline that fuels a nation. The water treatment plant that sustains a community. The factory floor that drives an economy. These are not just critical systems, they are targets. And the adversaries aiming at them have never been more capable, more patient, or more dangerous.
Operational Technology security is not IT security with a different name. it is an entirely distinct discipline, one where the stakes extend far beyond data breaches and financial loss into the realm of physical destruction, environmental catastrophe, and threats to human life itself. In OT environments, a misconfigured control system is not an inconvenience. It is a crisis. And a compromised industrial network is not a liability; it is a potential weapon. SecOT+ Study Guide is the definitive certification companion for cyber security professionals stepping into this high-consequence world, delivering the specialized knowledge, frameworks, and operational expertise needed to protect the systems that keep the modern world running.
Aligned with the CompTIA SecOT+ exam objectives and built for practitioners operating at the intersection of cybersecurity and industrial control systems, this guide goes beyond exam preparation to provide the deep, mission-critical understanding required to defend OT environments with precision, confidence, and real-world competence.
About the Authors
Video Library
Introduction
Chapter 1: Introduction to Operational Technology Security
Chapter 2: Foundational OT Concepts and Control Theory
Chapter 3: OT Risk Management Frameworks and Governance
Chapter 4: OT Cybersecurity Program Management
Chapter 5: OT Risk Assessment Methodologies
Chapter 6: Change Management Processes in OT
Chapter 7: OT Threat Intelligence and Landscape
Chapter 8: OT Cybersecurity Architecture and Design Principles
Chapter 9: Hardware and Application Security in OT
Chapter 10: Identification, Authentication, and Authorization (IAA) in OT
Chapter 11: OT Security Operations and Monitoring
Chapter 12: Portable Device and Removable Media Security
Chapter 13: OT Incident Response Planning and Preparation
Chapter 14: OT Incident Response Handling and Procedures
Chapter 15: OT Incident Recovery and Post-Incident Activities
Further Readings
Index
Rebecca M Basta
Rebecca M. Basta is a distinguished bioinformatics and cybersecurity education specialist with deep expertise at the critical intersection of health care technology, data science, and cybersecurity. Holding a Master of Science in Bioinformatics and a Bachelor of Science in Biochemistry with a Minor in Biotechnology, Basta combines advanced academic credentials with hands-on laboratory and educational expertise.
With an impressive portfolio of 30+ professional certifications spanning health care data analytics, AI governance, cybersecurity, risk management, and emerging security technologies, Basta demonstrates exceptional breadth across intersecting disciplines. Her credentials include Certified Health Data Analyst (CHDA), Certified Information Privacy Professional/United States (CIPP/US), Artificial Intelligence Governance Professional (AIGP), ISO 27001 and ISO 42001 Certified Lead Auditor, Certified Analytics Professional Expert (CAP), Certified Lean Six Sigma Master Black Belt, Certified Red Team Operations Management (CRTOM), and Certified Artificial Intelligence Security & Risk (CAISR). This diverse certification landscape reflects her commitment to understanding security from multiple angles: defensive, offensive, and governance perspectives. Basta’s research and publication record is exceptionally prolific, focusing on the convergence of health care security and advanced data analytics.
Stavros E Basta
Stavros E. Basta is an accomplished cybersecurity professional and published researcher
specializing in industrial control systems (ICS) security and critical infrastructure protection. Holding a Master of Science in Cybersecurity and a Bachelor of Science in Cybersecurity, Basta brings advanced academic credentials alongside extensive industry experience.
With an impressive portfolio of 25+ professional certifications spanning security leadership, penetration testing, risk management, and cloud security, including GIAC Global Industrial Cyber Security Professional (GICSP), Certified Information Security Manager (CISM), Licensed Penetration Testing Master (LPTM), GIAC Security Leadership (GSLC), and Certified Penetration Testing Professional (CPENT), Basta demonstrates deep expertise across the cybersecurity landscape. Basta’s research investigates the critical gap between traditional cybersecurity frameworks and the unique vulnerabilities of industrial control systems and critical infrastructure.