About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

Espionage vs. Sabotage

Monday, October 5, 2026
3:55 PM - 4:30 PM
Training Room 1 (Studio 1)

About This Session

What's old is new again. 50 year old (!) cybersecurity theory (Bell/La Padula vs. Biba) teaches us that a detailed asset inventory showing us where is the information we must protect is the wrong first step when we are trying to prevent sabotage vs. prevent espionage. In espionage, information is the asset - we need to know what and where it is to prevent theft and leakage. In sabotage, information is the threat - the first inventory is not of assets and information, but of data flows / attack vectors. The most important such vectors are not internal to the system, but vectors that cross consequence boundaries. When preventing sabotage, securing connectivity across consequence boundaries is not a "compensating measure," but a primary protective measure. The latest cross-agency guidance authored by the UK NCSC "Secure connectivity principles for Operational Technology" makes this distinction clear. The guidance offers strong advice for controlling the movement of incoming information flows, including hardware-enforced / ASIC-based "unhackable" inspection of dangerous incoming information. In this presentation we look at the latest advice in terms of (long forgotten) 50-year-old theory, and look at it in light of the latest threats and attacks highlighted in the (open, public) data set of cyber attacks with physical consequences in 2025.

Speaker

Andrew Ginter

Andrew Ginter

VP Industrial Security - Waterfall Security

At Waterfall Security Andrew leads a team of experts who work with the world's most secure industrial enterprises. Before Waterfall, he led the development of high-end industrial control system products at HP, of IT/OT middleware products at Agilent , and of the world's first industrial SIEM at Industrial Defender. Andrew is the author of three books on industrial / OT cybersecurity with 35,000 copies in print. He co-hosts the Industrial Security Podcast and contributes regularly to industrial security standards and best-practice guidance.