TÜV RHEINLAND CYBER
SECURITY TRAINING 2026
TÜV RHEINLAND CYBER SECURITY TRAINING 2026 will take place from 16.-19. November, Milling Hotel Park, Viaduktvej 28, Middelfart, 5500, Danmark.
DotBlue is pleased to announce that we facilitate a new TÜV Rheinland Certified Cyber Security Risk
Assessment (SRA) Course, developed in collaboration with EFSTAS Limited.
The course covers the Interface between SRA (IEC61511-1) and the Cybersecurity Requirements Specification (IEC 62443).
The objective of the course is to provide participants with a fundamental understanding of the principles ofCybersecurity Risk Assessment in the process industries according to IEC 62443, with focus on Industrial Automation Control and Safety System.
The course provides participants with theoretical knowledge as well as practical methods and tools for
providing competences to be able to perform activities to reduce the risk of a successful cyber attack, satisfy legal and regulatory requirements and meet the organisation’s system security and business objectives.
The programme includes:
- Principles and concepts of IEC 62443
- How and when to apply
- Security Risk Assessments (SRA)
- Cybersecurity Management System
- Network and information system
- Defining tolerable risk criteria for security and the concept of ALARP
- Techniques and methods for risk assessment
- Interface between SRA and the Cybersecurity Requirements Specification
- TÜV Rheinland certification examination as CySec Specialist (TÜV Rheinland)
Program
Day 1 Agenda
Provides an introduction to the background, concepts and principles to be applied to the Security risk assessment, competency, compliance, security management and the relevant international standards. The Security Risk Assessment using a risk matrix will be discussed as well as the introduction to the case study
The topics covered are:
- Introduction to TUV Rheinland Cyber Security (CySec) Program
- Requirements for Cyber Security in the IACS environment, including IEC 61511 and the Network and Information Systems (NIS) directive.
- Security Management and Common Management Systems
- Introduction to Security in the IACS environment
- Introduction to the relevant Security and Safety Standards
- Introduction to the IEC 62443 Security Lifecycle
- Introduction to Risk Assessment specific standards
- Asset Inventory and it’s relation to Security Risk Assessment
- Introduction to the Case Study
- Asset Inventory exercise – Session 1
- Types of Risk Assessment – Quantitative, Semi Quantitative & Qualitative
- High-Level Security Risk Assessment
- How to use previous Process Hazard Analysis (PHA) as an input to High-Level SRA.
- Determination of the High-Level Threat Scenarios
- Determination of the High-Level Vulnerabilities
- Determination of the High-Level Risk
- Determination of the preliminary Security Level – Target
- High-Level SRA exercise – Session 2
Day 2 Agenda
Further develops on the concepts, principles and techniques carried out in day one and the case study work by taking the output from the High-Level SRA and evaluates the risks based on their likelihood and consequence and prioritises them for examination in the Detailed-Level SRA. The second day also includes an explanation of what outputs would be expected from the High-Level SRA. The principles and activities of the Zoning and Conduit sections of the IEC 62443 will also be explained.
The topics covered are:
- The required outputs from the High-Level SRA
- Requirements of IEC 62443 with relation to the Zone and Conduit exercise.
- Trust Boundaries, Entry Points and further benefits of the Zone and Conduit exercise.
- Allocation of IACS to Zone
- Network Segmentation
- System Architecture
- Allocation of Zones Exercise – Session 3
Day 3 Agenda
Develops on the case study work carried out in day one and two taking the outputs from the High-Level SRA and the Zone and Conduit exercise and then examining the prioritised risk zones in detail in the Detailed-Level SRA. Also covered is the relation between the Detailed-Level SRA and Attack Trees and how they may be used in both the risk assessment and the effective implementation of the countermeasures/security controls.
. The topics covered are:
- IEC 62443 Detailed-Level SRA requirements
- Description of Attack Surfaces in the ICS Environment
- Detailed-Level SRA Process
- Determination of Threats including Threat Assessment
- Determination of Vulnerabilities including Vulnerability Assessment
- Determination of the Detailed Risk and Security Level – Targets through the use of a Security Risk Matrix.
- The Importance of Security Level – Targets and their relation to Foundational Requirements.
- How pruning of Attack Trees can be used to demonstrate a Risk-Based approach to risk reduction
- Detailed-Level SRA exercise – Session 4
- Risk Management (Acceptance)
- IEC 62443 Required Documentation for SRA, including the Cybersecurity Requirement Specification (CRS).
- Risk Management (Monitoring and Review)
- Concluding remarks
- Format of exam and preparation and close.
Day 4 Agenda
A three (3) hour competency examination compromising 30 multiple-choice questions (1 mark per question) and open questions 10 questions (4 marks per question).
The pass score criterion is 75% on each paper
Please note that the programme is subject to change.
Last revised on 09-09-2026.
Language
This course will be conducted in English.
Who Should Attend?
Functional, Process and Technical Safety Engineers, Control and Instrument Engineers and Managers, Process Engineers, Operations personnel and managers, maintenance staff, consultants, advisors and persons involved in management, engineering, operations and safety of process operations as well as persons with PH&RA experience and who are currently involved process hazard and risk analysis, and will be required to take part in the Security Risk Assessments and Cybersecurity requirements specification.

Date
16.-19. November 2026
Place
Milling Hotel Park, Viaduktvej 28, Middelfart, 5500, Danmark.
COURSES & UPCOMING EVENTS
Get the opportunity to experience more of our courses and events – and learn more about Functional Safety!
Feel the atmosphere and learn more from our held Functional Safety events.
EVENT ORGANIZER
About DotBlue
As the organizer of this event, we want to put an end to the often lack of understanding or lack of safety standards within the machine- and process industry.
Low prioritization, lack of proposed solutions or difficulties in understanding procedures and the authorities’ requirements. In addition, some companies operate with overqualified security solutions that require unnecessary and expensive maintenance. Due to missing or non-existent safety standards / procedures, accidents can occur, accidents that could easily have been prevented.
Bringing together experts from leading companies enables us to highlight the topics that present the greatest challenges to end users. In collaboration with experts and authorities, we will answer questions and contribute tools for solutions that the participants can bring home to their companies.
DotBlue strives to make Functional Safety tangible and puts the importance in focus!
Contact the organizer
DotBlue A/S
Email: event@dotblue.dk
Disclaimer
We accept no liability for any printing errors.
For your safety
You are always welcome to contact us if you have any questions.