Christian Azuero

Christian Azuero is a Offensive Cyber Security Engineer at Netpoleon, specializing in penetration testing. With over five years of experience in firewall auditing, threat detection, DFIR, and regulatory compliance, he brings strong offensive and defensive security expertise to every engagement. He has a particular passion for OT security projects, applying his red team skills to help organizations strengthen industrial and critical infrastructure systems. Christian also designs hands-on Blue-Team and CTF learning environments, including the Hacker Escape Room platform used by students and cybersecurity communities across Australia. He holds an MSc in Network & Security from Monash University.


Christian Azuero's Schedule

2:30 pm

OT Range in the Backyard

40 minutes
Christian Azuero

Most OT security training occurs in two ways: costly commercial cyber ranges that few people can access, or free virtual testbeds that mimic protocols but not physical processes. Neither option allows learners to see how a poor PLC decision can actually drain a battery, trip a relay, or cause a historian to fail. This talk focuses on bridging that gap with a range built in an actual backyard.

I will explain the OT Cyber Range: a real off-grid solar setup that generates and stores actual power. It is designed with a fully segmented Purdue Level 0 to Level 5 architecture, including field devices, a PLC, a supervisory layer, an Industrial DMZ, and a cloud-hosted detection layer. Academic testbeds like SWaT and EPIC have shown how valuable physical process fidelity is for research. This project explores what this looks like when scaled down to something a single person can build in their backyard for a few thousand dollars.

The session will cover three key takeaways for attendees. First is the architecture itself: how each Purdue level was implemented using real (not simulated) hardware, and the firewall logic that maintains the IDMZ’s integrity by ensuring no inbound connection exists from IT to OT. Second is the detection engineering: how field-layer telemetry turns into KQL analytic rules mapped to MITRE ATT&CK for ICS, and what it looks like when a rule activates in response to a live attack on the physical process instead of a synthetic dataset. Third is the practical and financial aspects of accomplishing this at home, including choices of components, costs, mistakes made, and safety measures that prevented it from becoming a fire hazard or electrical issue.

The goal is not to sell a product or course; instead, it is to provide the audience with a replicable blueprint. Attendees will leave with a clear understanding of what it takes to build a small, functional, physical OT range for training or research and which design decisions are most important when the ""plant"" consists of real hardware rather than a Docker container.