About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

Engineering Out the Adversary: Applying Consequence-Driven Cyber-Informed Engineering (CCE)

Wednesday, October 7, 2026
11:00 AM - 11:35 AM
Strategy Track (Great Room 3)

About This Session

Industrial control system security teams talk in CVEs, APTs, and threat models. Mechanical and electrical engineers talk in FMEA, margins, and safety factors. Value engineers track line items and budgets. Risk owners demand defensible compliance records. Each discipline does the right work in its own language, and the consequences that matter most sit at the blind handoffs between them.

Consequence-driven Cyber-informed Engineering (CCE) is Idaho National Laboratory's methodology for working backwards from the worst-case engineered consequence. It asks a singular question: can an adversary trigger that specific consequence through cyber means? CCE assumes breach by design. It prioritizes engineered and procedural protections that take the consequence out of cyber reach. Once those protections are in place, they hold whether the trigger is an adversary, an operator, a software bug, or an AI agent acting outside its envelope.

To demonstrate this, the session runs an accelerated CCE tabletop on a representative ICS system selected by the room from a curated list. The audience works through Phase 1 consequence prioritization and Phase 2 system-of-systems analysis, as we map the process from both sides of the aisle. We take the physical failure modes engineers care about and connect them to the attack paths security uses to reach them. By the end of the exercise, we produce what every CCE engagement yields: a functional block diagram highlighting choke points and engineered protection candidates.

The resulting diagram gives every discipline the same reference to work from. Each team sees functional blocks, trust boundaries, and attack paths without needing to be an expert in everything. The same artifact carries into traditional IT penetration testing, design review, and cost decisions, because it ties the argument to consequence rather than tool findings alone. The analysis handles the parts of OT where ownership and visibility break down, including the closed-source vendor devices the architect can only engineer around. The steps don't change. What changes the outcome is running them early enough to influence design, with the right people in the room.

Speaker

Tyler Berube

Tyler Berube

Senior OT Platform and Security Engineer - Microsoft

Tyler Berube is a Senior OT Security Engineer at Microsoft, where he focuses on industrial control system and operational technology security for cloud and datacenter operations. He came into the discipline from the floor, moving through critical facilities technician, critical environment instrumentation, and critical infrastructure platform engineering roles before specializing in OT security. His current work covers consequence-driven engineering, OT and ICS architecture review, identity and access management for control system environments, and the secure integration of new mechanical, electrical, and automation technologies into operating fleets. He partners with mechanical, controls, and platform engineering teams to make consequence analysis a routine part of design and operations.