Simulations Engagement
Simulator Exploring how cyber attacks move through industrial control networks
View live demoNetSimOT is a self-contained, single-file web application that simulates cyber attacks against industrial control systems, built to teach the one thing that separates OT security from IT security: the worst outcome is not data loss, it is physical consequence.
You pick one of four industry sectors (power grid, oil and gas, water treatment, or aircraft manufacturing), choose how the network is architected across three options from a flat legacy estate to full Zero Trust micro-segmentation, set which of five defensive controls your organisation actually funds, and then face one of ten attack playbooks drawn from documented incidents — BlackEnergy, Stuxnet, TRITON, Colonial, EKANS and others.
Each runs three phases with two choices, and the engine deliberately makes architecture the deciding factor: a funded, switched-on control can still fail on a flat network because there is no zone boundary for it to enforce, while Zero Trust can contain an attack with no named control at all. Four of the playbooks run two concurrent attack streams you cannot both defend, which teaches that owning a control and being able to staff it at the moment it matters are different things.
Consequences land on an animated Purdue-model canvas, a System Safety Level meter in the header, and — in the manufacturing sector — ten animated machines that degrade or fail with real engineering consequences, while every decision is judged live against IEC 62443, NIST SP 800-82 Rev 3, NIS 2 and the Cyber Resilience Act. It ships with a Dockerfile and compose file for port 8080, and an 18-page A4 PDF user and facilitator guide covering session formats, five ready-made scenario progressions, debrief questions and an assessment rubric.
Ships as a single self-contained HTML file with Docker deployment and an 18-page PDF user and facilitator guide.