About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

Beyond the Buzzwords: A Practical, Risk-Based Approach to What Actually Matters in OT Cybersecurity

Monday, October 5, 2026
12:35 PM - 1:10 PM
Training Room 1 (Studio 1)

About This Session

Beyond the Buzzwords: What Really Matters in OT Cybersecurity challenges the industry’s fixation on emerging technologies and reframes the conversation around practical, risk-reducing fundamentals. Drawing on real-world operational technology (OT) environments, this session cuts through hype—such as AI-driven detection, Zero Trust, and advanced analytics—to reveal why many organizations remain vulnerable despite significant investments.
The presentation highlights a critical disconnect: while cyber threats are growing, many OT environments still lack essential capabilities like asset visibility, network segmentation, access control, and tested recovery processes. Attendees will gain a clear, structured model for prioritizing these foundational controls, emphasizing that effective cybersecurity begins with understanding “the minimum required to avoid a major operational incident.”
A core theme of the session is that OT cybersecurity is fundamentally different from IT security. OT systems are designed for safety, uptime, and reliability—not security—and often rely on legacy technologies with limited patching windows and inherent vulnerabilities. The talk provides a pragmatic, risk-based maturity framework that helps organizations align security investments with operational realities, avoiding common pitfalls such as overengineering or copying IT approaches directly into industrial environments.
Most importantly, the presentation underscores the often-overlooked role of human behavior in cybersecurity outcomes. It demonstrates how the majority of incidents stem from simple human actions or omissions, and why awareness, training, and culture are the highest-leverage investments organizations can make. Attendees will learn how to build effective, role-based training programs and foster a reporting culture that improves detection and response.
The session concludes by outlining a maturity roadmap—from foundational controls to advanced capabilities—and identifying the most common mistakes organizations make, including over-reliance on tools and underinvestment in people.
This presentation delivers actionable guidance for security leaders, operations teams, and executives seeking clarity, prioritization, and measurable risk reduction in OT cybersecurity—focusing not on what sounds impressive, but on what actually works.

Speaker

Carl Eshelman

Carl Eshelman

Cyber Growth Leader, Americas - Honeywell

Carl Eshelman leads Honeywell’s Cyber Technical Solutions Consultant and Solution Architect team for the Americas. With more than 30 years of experience spanning IT infrastructure, networking, security, and industrial control systems, he is a recognized OT cybersecurity leader helping organizations across critical infrastructure and industrial sectors strengthen resilience in complex operational environments. Drawing on a broad, hands-on background across multiple technology domains, Carl brings a pragmatic perspective on how cyber risk impacts real-world operations and is known for cutting through industry buzzwords to deliver clear, experience-driven guidance on what actually works in OT cybersecurity.