About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

23 Attacks. 3 Controls. A Decade of OT Breaches and the Pattern Nobody Talks About

Thursday, October 8, 2026
10:10 AM - 10:40 AM
Tech Track (Great Room 1)

About This Session

Colonial Pipeline. NotPetya. The Oldsmar water treatment hack. Ukraine's power grid blackouts. Triton/TRISIS at a Saudi petrochemical facility. Jaguar Land Rover ransomware. The list of high-profile OT cyberattacks grows every year — and with it, an industry assumption that these incidents require sophisticated adversaries exploiting novel vulnerabilities. That assumption is wrong, and the data proves it.This session presents a structured analysis of 23 major OT cyberattacks drawn from public incident reports, government advisories, forensic analyses, and security research published between 2014 and 2026. The analysis identifies the specific failure mode that enabled each breach. The finding is consistent and, once you see it, impossible to unsee: fewer than two of the 23 attacks involved a genuine zero-day exploit against a core OT system. The vast majority succeeded through one of three failure modes: (1) internet-exposed systems with known CVEs that remained unpatched, (2) stolen, default, or phishable credentials used to gain authorized-looking access, or (3) lateral movement through flat, unsegmented networks that allowed initial access to escalate into plant-wide compromise. The session walks through selected case studies in detail — showing exactly how each failure mode played out in practice, what defenders saw (or didn’t see) at each stage, and how the attack would have been interrupted if the relevant control had been in place. It then addresses the uncomfortable question this analysis raises: if three controls had stopped virtually every major OT breach over the past decade, why are those breaches still happening? The answer has as much to do with organizational decision-making, regulatory timing, and budget cycles as it does with technical capability — and this session addresses all three dimensions.
KEY AUDIENCE TAKEAWAYS
-Review the specific failure modes (exposed systems, stolen credentials, lateral movement) that enabled 23 documented OT breaches — and understand why novel zero-days were rarely the root cause
-Identify which of the three recurring failure modes is most likely to be present in your own environment based on asset profile and architecture
-Understand the organizational and budgetary dynamics that allow known, preventable failure modes to persist in well-resourced OT environments
-Apply the case study framework to communicate breach risk to leadership using documented, real-world outcomes rather than hypothetical threat scenarios
-Leave with a prioritized defensive checklist based on frequency and impact of each failure mode across the 23-breach dataset

Speaker

Tom Sego

Tom Sego

CEO - BlastWave

Tom Sego is the CEO of BlastWave, an OT cybersecurity company focused on Zero Trust protection for industrial control systems and critical infrastructure. He has spent his career at the intersection of operational technology and cybersecurity, working with energy, manufacturing, water, government, and transportation organizations across 21 countries.
BlastWave has analyzed 23 of the most significant OT cyberattacks in recorded history (the BlastWave Hackopedia), and Tom draws on that dataset regularly in industry discussions, webinars, and public commentary. Tom speaks frequently on the intersection of AI and OT security: both the threat dimension (how AI is changing the attacker toolkit) and the defense dimension (why AI-powered defensive automation requires a different risk model in OT).