East - West Detection Engineering in OT Environments
About This Session
Most industrial organizations are operating with a dangerous blind spot at the heart of their OT security programs: their IT SOC and OT monitoring teams are working in complete isolation from one another, managing risk signals from disconnected platforms with under-qualified resources lacking the cross-domain context needed to recognize a coordinated attack in progress.
This session examines the structural maturity gap in OT Detection Engineering through the lens of two distinct ** and equally critical ** visibility domains: North - South detection at the IT/OT boundary, and East - West detection within the OT environment itself. Attendees will learn how sophisticated threat actors exploit the seam between these domains, why OT-native monitoring platforms routinely underperform even when deployed correctly, and what a unified, cross-domain detection engineering model looks like in practice.
Drawing on real-world practitioner experience across industrial environments, this session delivers a concrete framework for building detection capability that spans OT telemetry, mapped to MITRE ATT&CK for ICS, allowing your organization to move beyond vendor default alerting toward a governed, environment-specific detection use case library.
This session examines the structural maturity gap in OT Detection Engineering through the lens of two distinct ** and equally critical ** visibility domains: North - South detection at the IT/OT boundary, and East - West detection within the OT environment itself. Attendees will learn how sophisticated threat actors exploit the seam between these domains, why OT-native monitoring platforms routinely underperform even when deployed correctly, and what a unified, cross-domain detection engineering model looks like in practice.
Drawing on real-world practitioner experience across industrial environments, this session delivers a concrete framework for building detection capability that spans OT telemetry, mapped to MITRE ATT&CK for ICS, allowing your organization to move beyond vendor default alerting toward a governed, environment-specific detection use case library.
Speaker
Terry McCorkle
CEO & Founder - PhishCloud, Inc
Terry is the Founder and CEO of PhishCloud Inc, a proactive intelligence delivery company. He is a certified hacker with over twenty-one years of experience in the cybersecurity industry and has served in a broad range of technical, analytical, and leadership roles. He is passionate about his family, employees, and helping people in cybersecurity. Terry loves entrepreneurship and, as CTO and Co-Founder of Spearpoint Security, helped lead through an acquisition by Cylance in 2013. He holds a BS in Information Technology from Capella University and several cybersecurity certifications.
