TÜV RHEINLAND CYBER SECURITY TRAINING 2026

Kursus

TÜV RHEINLAND CYBER
SECURITY TRAINING 2026

TÜV RHEINLAND CYBER SECURITY TRAINING 2026 will take place from 16.-19. November, Vestre Ringvej 96 DK-7000 Fredericia Danmark.

DotBlue is pleased to announce that we facilitate a new TÜV Rheinland Certified Cyber Security Risk
Assessment (SRA) Course, developed in collaboration with EFSTAS Limited.

The course covers the Interface between SRA (IEC61511-1) and the Cybersecurity Requirements Specification (IEC 62443).

The objective of the course is to provide participants with a fundamental understanding of the principles ofCybersecurity Risk Assessment in the process industries according to IEC 62443, with focus on Industrial Automation Control and Safety System.

The course provides participants with theoretical knowledge as well as practical methods and tools for
providing competences to be able to perform activities to reduce the risk of a successful cyber attack, satisfy legal and regulatory requirements and meet the organisation’s system security and business objectives.

The programme includes:

  • Principles and concepts of IEC 62443
  • How and when to apply
    • Security Risk Assessments (SRA)
    • Cybersecurity Management System
    • Network and information system
  • Defining tolerable risk criteria for security and the concept of ALARP
  • Techniques and methods for risk assessment
  • Interface between SRA and the Cybersecurity Requirements Specification
  • TÜV Rheinland certification examination as CySec Specialist (TÜV Rheinland)

Program

Day 1 Agenda

Provides an introduction to the background, concepts and principles to be applied to the Security risk assessment, competency, compliance, security management and the relevant international standards. The Security Risk Assessment using a risk matrix will be discussed as well as the introduction to the case study

The topics covered are:

  • Introduction to TUV Rheinland Cyber Security (CySec) Program
  • Requirements for Cyber Security in the IACS environment, including IEC 61511 and the Network and Information Systems (NIS) directive.
  • Security Management and Common Management Systems
  • Introduction to Security in the IACS environment
  • Introduction to the relevant Security and Safety Standards
  • Introduction to the IEC 62443 Security Lifecycle
  • Introduction to Risk Assessment specific standards
  • Asset Inventory and it’s relation to Security Risk Assessment
  • Introduction to the Case Study
  • Asset Inventory exercise – Session 1
  • Types of Risk Assessment – Quantitative, Semi Quantitative & Qualitative
  • High-Level Security Risk Assessment
    • How to use previous Process Hazard Analysis (PHA) as an input to High-Level SRA.
    • Determination of the High-Level Threat Scenarios
    • Determination of the High-Level Vulnerabilities
    • Determination of the High-Level Risk
    • Determination of the preliminary Security Level – Target
  • High-Level SRA exercise – Session 2

Day 2 Agenda

Further develops on the concepts, principles and techniques carried out in day one and the case study work by taking the output from the High-Level SRA and evaluates the risks based on their likelihood and consequence and prioritises them for examination in the Detailed-Level SRA. The second day also includes an explanation of what outputs would be expected from the High-Level SRA. The principles and activities of the Zoning and Conduit sections of the IEC 62443 will also be explained.

The topics covered are:

  • The required outputs from the High-Level SRA
  • Requirements of IEC 62443 with relation to the Zone and Conduit exercise.
  • Trust Boundaries, Entry Points and further benefits of the Zone and Conduit exercise.
  • Allocation of IACS to Zone
  • Network Segmentation
  • System Architecture
  • Allocation of Zones Exercise – Session 3

Day 3 Agenda

Develops on the case study work carried out in day one and two taking the outputs from the High-Level SRA and the Zone and Conduit exercise and then examining the prioritised risk zones in detail in the Detailed-Level SRA. Also covered is the relation between the Detailed-Level SRA and Attack Trees and how they may be used in both the risk assessment and the effective implementation of the countermeasures/security controls.

. The topics covered are:

  • IEC 62443 Detailed-Level SRA requirements
  • Description of Attack Surfaces in the ICS Environment
  • Detailed-Level SRA Process
  • Determination of Threats including Threat Assessment
  • Determination of Vulnerabilities including Vulnerability Assessment
  • Determination of the Detailed Risk and Security Level – Targets through the use of a Security Risk Matrix.
  • The Importance of Security Level – Targets and their relation to Foundational Requirements.
  • How pruning of Attack Trees can be used to demonstrate a Risk-Based approach to risk reduction
  • Detailed-Level SRA exercise – Session 4
  • Risk Management (Acceptance)
  • IEC 62443 Required Documentation for SRA, including the Cybersecurity Requirement Specification (CRS).
  • Risk Management (Monitoring and Review)
  • Concluding remarks
  • Format of exam and preparation and close.

Day 4 Agenda

A three (3) hour competency examination compromising 30 multiple-choice questions (1 mark per question) and open questions 10 questions (4 marks per question).

The pass score criterion is 75% on each paper


Please note that the programme is subject to change.
Last revised on 17-09-2026.

Course Fees

TÜV Rheinland Cyber Security Training 2026 4 days (including certification exam):
DKK 14,800 per participant (DKK 18,500 incl. VAT)

TÜV Rheinland Cyber Security Training 2026 3 days (excluding certification exam):
DKK 11,800 per participant (DKK 14,750 incl. VAT)


What's Included

  • Participation in the TÜV Rheinland Cyber Security Training 2026
  • Course materials
  • Daily refreshments, including coffee, tea, lunch, and snacks
  • TÜV Rheinland Certificate of Attendance (subject to course completion requirements) - only included in the 4 days training

Not Included

Accommodation is not included in the course fee.

Participants who wish to stay at the venue can book their accommodation directly by contacting caroline@hotel-fredericia.dk and quoting reservation number 19676.

Rooms can be booked at the special rate up to 30 days prior to the course. After this date, room availability cannot be guaranteed, but participants are welcome to contact the hotel to enquire about availability.


Language
This course will be conducted in English.

Who Should Attend?
Functional, Process and Technical Safety Engineers, Control and Instrument Engineers and Managers, Process Engineers, Operations personnel and managers, maintenance staff, consultants, advisors and persons involved in management, engineering, operations and safety of process operations as well as persons with PH&RA experience and who are currently involved process hazard and risk analysis, and will be required to take part in the Security Risk Assessments and Cybersecurity requirements specification.

  • A minimum of 3 to 5 years’ experience in a related field (e.g. Control & Instrumentation, process engineering, IT/OT, functional safety or cyber security).
  • University degree or equivalent engineering experience and responsibilities as certified by employer or engineering institution.
TÜV
Priser