NE

Simulations Engagement

NetSimOT

Simulator Exploring how cyber attacks move through industrial control networks

View live demo

Overview

NetSimOT is a self-contained, single-file web application that simulates cyber attacks against industrial control systems, built to teach the one thing that separates OT security from IT security: the worst outcome is not data loss, it is physical consequence.


You pick one of four industry sectors (power grid, oil and gas, water treatment, or aircraft manufacturing), choose how the network is architected across three options from a flat legacy estate to full Zero Trust micro-segmentation, set which of five defensive controls your organisation actually funds, and then face one of ten attack playbooks drawn from documented incidents — BlackEnergy, Stuxnet, TRITON, Colonial, EKANS and others.


Each runs three phases with two choices, and the engine deliberately makes architecture the deciding factor: a funded, switched-on control can still fail on a flat network because there is no zone boundary for it to enforce, while Zero Trust can contain an attack with no named control at all. Four of the playbooks run two concurrent attack streams you cannot both defend, which teaches that owning a control and being able to staff it at the moment it matters are different things.


Consequences land on an animated Purdue-model canvas, a System Safety Level meter in the header, and — in the manufacturing sector — ten animated machines that degrade or fail with real engineering consequences, while every decision is judged live against IEC 62443, NIST SP 800-82 Rev 3, NIS 2 and the Cyber Resilience Act. It ships with a Dockerfile and compose file for port 8080, and an 18-page A4 PDF user and facilitator guide covering session formats, five ready-made scenario progressions, debrief questions and an assessment rubric.

Features

  • Live Purdue-model network canvas that redraws itself from your chosen sector and architecture, with animated industrial protocol flows and colour-coded node states.
  • Four industry sectors — power grid, oil and gas, water treatment, and a substantially larger aircraft manufacturing estate.
  • Three network architectures spanning flat legacy, Purdue-compliant segmentation, and Zero Trust micro-segmentation.
  • Five independently toggleable defensive controls, from IDMZ isolation and fieldbus deep packet inspection through to an independent safety instrumented system.
  • Ten attack playbooks drawn from documented incidents, each running three branching phases with sector-specific physical consequences.
  • A deterministic decision engine in which architecture can defeat a funded control or rescue an absent one, both named explicitly in the log.
  • Multi-stream playbooks that run two concurrent attacks you cannot both defend, forcing a genuine resource trade-off.
  • A System Safety Level meter that weights damage by Purdue depth and triggers an SIS emergency trip to prevent physical destruction.
  • Ten animated manufacturing machines with derived Running, Degraded, Failed and Safe-Stop states reported as real engineering consequences.
  • A dual SIEM and compliance terminal judging every decision live against IEC 62443, NIST SP 800-82 Rev 3, NIS 2 and the Cyber Resilience Act.


Ships as a single self-contained HTML file with Docker deployment and an 18-page PDF user and facilitator guide.

Capabilities

  • Simulates cyber attacks against industrial control networks across four industry sectors and three network architectures, from flat legacy estates to Zero Trust micro-segmentation.
  • Presents ten branching attack playbooks drawn from documented incidents, including concurrent multi-stream attacks that cannot both be defended.
  • Models defensive posture through five independently toggleable controls, where architecture itself can defeat a funded control or rescue an absent one.
  • Tracks physical consequence through a Purdue-weighted safety meter, an independent safety instrumented system, and animated manufacturing machinery that degrades and fails in real engineering terms.
  • Judges every decision live against IEC 62443, NIST SP 800-82 Rev 3, NIS 2 and the Cyber Resilience Act, producing an audit-style record of the run.


Benefits

  • Makes the case for segmentation investment far more persuasively than a slide deck, by demonstrating a funded control failing on a flat network and an unfunded one holding under Zero Trust.
  • Closes the gap between IT and OT teams by putting both in front of the same screen, where the worst outcome is visibly physical rather than financial.
  • Exposes uncomfortable truths that rarely surface in tabletop exercises — that a control you cannot staff at 3am is worth less than its business case claimed, and that being unbreached is useless if you cannot prove it.
  • Converts a training session into a compliance artefact, producing findings mapped to real IEC 62443, NIST, NIS 2 and CRA clauses that a board or regulator would recognise.
  • Runs anywhere with no backend, database or telemetry, making it safe to deploy inside the restricted environments its own subject matter describes.

How it links to other apps


No documents uploaded yet.