About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

Applying Network Detection and Response in OT without Breaking Operations

Wednesday, October 7, 2026
1:30 PM - 2:00 PM
Strategy Track (Great Room 3)

About This Session

Most industrial organizations have invested for years in asset inventories, segmentation, and monitoring. Yet many still struggle to answer one critical question: what is happening on the wire inside the plant right now?

In OT, endpoint agents often cannot be deployed. Logs are incomplete or unavailable. And the activity that matters most — controller-to-controller traffic, unexpected engineering workstation access, unauthorized protocol commands, and lateral movement across flat networks — can remain invisible until it becomes an incident.

This session explains where Network Detection and Response fits in an industrial cybersecurity strategy, and where it does not. We will cover how NDR complements segmentation, SIEM, and EDR without disrupting safety-critical operations. Attendees will learn how to evaluate NDR for real OT environments, including passive monitoring, tap and SPAN placement, Purdue model visibility, protocol coverage, data residency, and integration requirements.

We will close with three practical OT use cases: passive asset discovery, baseline-driven anomaly detection, and threat hunting for lateral movement in legacy or flat networks.

Learning Objectives:
- Explain how NDR differs from EDR, SIEM, and segmentation in an OT architecture.
- Apply a vendor-neutral checklist for evaluating OT NDR solutions before procurement.
- Identify three high-value industrial use cases for NDR and recognize environments where it may not provide sufficient value.

(Sponsored Session by Fortinet)

Speaker

Carlos Sanchez

Carlos Sanchez

Fortinet, Director, OT Systems Engineering Specialist - Fortinet

Carlos-Raul Sanchez is a technologist with 32 years of experience in network, telecommunications, and critical infrastructure security. Carlos specializes in simplifying complex business problems with a pragmatic application of technology. With master’s degrees in computer science, business administration, and a wide range of experience ranging from US Air Force, DOD contractor, and O&G IT security, he is known for securing critical infrastructure worldwide. He spent 15 years leading teams securing oil fields in the United States and offshore assets in the Gulf of Mexico, Western Africa, Brazil, and South China Sea. He is the senior director of operational technology, providing solutions and education to companies seeking to improve their critical infrastructure security posture.