The Cyber Scheme expands accredited training portfolio with new cyber risk and operational technology programmes

Share this Article

New programmes combine expert instruction, practical learning and independent accreditation to help organisations develop capability in two increasingly important areas of cyber security.
CHELTENHAM, UK. October 7th, 2026 – The Cyber Scheme has announced the expansion of its accredited training portfolio with the launch of two new programmes covering cyber security risk management and Operational Technology security.
The new courses have been developed to help practitioners apply their knowledge in real organisational and technical environments, while giving employers greater confidence in the quality, structure and professional relevance of the training they commission.
The first addition is an accredited Operational Technology Security Training Pathway, developed and delivered by Hacktonics. It comprises progressive Foundations, Practitioner and Advanced courses designed to build specialist capability in Operational Technology and Industrial Control Systems security.
The second is Cyber Scheme Foundations: Risk, a three-day practitioner course which provides a practical introduction to cyber security risk management, covering the identification, assessment, treatment, governance and communication of cyber risk. 
Although the programmes focus on different disciplines, both respond to a common workforce challenge: organisations need people who can do more than understand technical concepts. They need practitioners who can apply their knowledge, exercise sound judgement and contribute confidently within the environments they are expected to protect.
Developing specialist Operational Technology security skills
The new Hacktonics pathway addresses the need for cyber security professionals who can work confidently within Operational Technology and industrial environments, where technologies, operating constraints and potential consequences can differ significantly from those encountered in conventional enterprise IT.
The pathway consists of three progressive courses:
  • OT Security Testing – Foundations: A one-day introduction for cyber security professionals who understand IT security but are new to Operational Technology and Industrial Control Systems.
  • Pentesting Operational Technology Systems – Practitioner: A two-day course covering structured OT penetration testing, asset discovery, vulnerability scanning, security baseline assessment, industrial protocol exploitation and PLC-based attacks.
  • Operational Technology Security Testing – Advanced: A three-day programme covering industrial protocols, PLCs, HMIs, advanced attack techniques, end-to-end operational impacts and security architecture.  
Practical learning is embedded throughout the pathway. Participants will use Hacktonics’ LINICS platform, Lab-in-a-Box Industrial Control System training equipment, PLCs, HMIs and specialist OT security tools to investigate systems, identify vulnerabilities and understand how technical compromise can affect safety, reliability and operational continuity. 
Hacktonics is a University of Bristol spin-out founded by members of the University’s Department of Computer Science. The organisation specialises in hands-on cyber security training for Industrial Control Systems and has experience developing and delivering specialist ICS security test environments and training programmes.  
Professor Awais Rashid, Director of Hacktonics said: “Operational technology environments present unique security challenges that cannot be fully understood through theory alone. This training pathway has been designed to combine rigorous academic knowledge with practical experience, enabling participants to develop skills that can be applied confidently in real industrial environments.”
Building practical cyber risk capability
Cyber Scheme Foundations: Risk has been designed for people entering or developing within cyber risk management, as well as those working in governance, risk and compliance, audit, assurance, cyber security and IT roles.
Participants will explore the relationship between assets, threats, vulnerabilities, likelihood and impact, before considering risk appetite, tolerance, treatment, ownership, governance and control effectiveness. The programme also covers qualitative and quantitative assessment, recognised frameworks, threat modelling, risk metrics and communication with technical and non-technical stakeholders. 
Expert-led teaching is supported by discussion, practical exercises, individual activities and realistic organisational scenarios, helping participants understand not only the language and structure of cyber risk management, but how credible risk information is developed and used to support decisions.
Peter Loomes brings more than 35 years of experience assessing organisational risk across healthcare, central government, industry and the charity sector. He is a Chartered Cyber Security Professional in Risk and Governance, a Chartered Engineer, a Chartered IT Professional and a Fellow of the Chartered Institute of Information Security. 
Peter Loomes said: “Cyber risk is a business risk. Understanding where risk sits, what matters most to the organisation and how threats can affect its people, systems and services helps teams make better decisions before incidents happen.

“From setting risk appetite and assigning ownership to identifying threats, applying standards and planning for recovery, this course shows how the pieces fit together to protect the organisation and support its business goals.”
Connecting training with professional capability
Both programmes have been reviewed through The Cyber Scheme’s Training Accreditation framework, which considers course structure, learning outcomes, technical content, delivery quality and relevance to professional practice.
The expansion reflects the organisation’s wider commitment to connecting high-quality training with assessment, professional standards and workforce development. By working with experienced practitioners and specialist training providers, The Cyber Scheme aims to give learners and employers greater confidence that accredited courses support the development of practical, relevant and demonstrable capability.
Charles White, CEO of The Cyber Scheme, said: “Organisations need cyber security professionals who can combine specialist knowledge with practical application and informed judgement. These new programmes address two very different but increasingly important areas of capability.
“Cyber Scheme Foundations: Risk will help participants understand how cyber risk supports governance and organisational decision-making. The Hacktonics pathway provides a progressive route for practitioners building specialist expertise in Operational Technology and Industrial Control Systems security. Together, they demonstrate how expert instruction, practical learning and independent accreditation can support a stronger and more capable cyber workforce.”
Zeshan Sattar, Director at The Cyber Scheme, said: “Cyber security isn’t just about technology. Organisations need people who can understand risk, make informed decisions and communicate effectively with stakeholders. High-quality training should help people apply knowledge in practice, develop professional judgement and contribute confidently within their organisations. Expanding our accredited training portfolio is an important part of supporting that development.”
Cyber Scheme Foundations: Risk begins on 10 November 2026. The first OT Security Testing – Foundations course takes place on 28 October 2026, followed by further Foundations, Practitioner and Advanced courses during November and December. 
Further information, course dates, entry requirements, pricing and booking details are available at thecyberscheme.org.
ENDS
Press release distributed by PR Fire UK.
To find out more information, visit www.prfire.co.uk or book a call.