From Dwell Time to Dollars: Quantifying the Financial Value of Faster OT Incident Recovery
About This Session
OT incident response is moving in the wrong direction. The SANS 2025 ICS/OT survey data shows that detection, containment, and recovery timelines are getting longer, not shorter. In an industrial environment, that decline is not just a security problem; it becomes lost production, safety validation, customer impact, and executive scrutiny.
This practical session shows how to turn that problem into a defensible funding case. Using a representative manufacturing facility and the response stages of compromise-to-detection, detection-to-containment, and containment-to-remediation, we will quantify how OT incident response maturity changes expected loss, severe-event exposure, and residual risk.
Risk is delivered as a dollar value, that can be used with leadership to secure real funding to improve OT incident response.
Attendees will see how response-time improvements can be modeled as financial risk reduction, why containment often delivers strong early value, and why trusted recovery still determines resilience. The goal is simple: give ICS/OT practitioners a hands-on example, supporting data, and a reusable technical paper they can take back to leadership to justify improved OT incident response before the next incident proves the need the hard way.
This practical session shows how to turn that problem into a defensible funding case. Using a representative manufacturing facility and the response stages of compromise-to-detection, detection-to-containment, and containment-to-remediation, we will quantify how OT incident response maturity changes expected loss, severe-event exposure, and residual risk.
Risk is delivered as a dollar value, that can be used with leadership to secure real funding to improve OT incident response.
Attendees will see how response-time improvements can be modeled as financial risk reduction, why containment often delivers strong early value, and why trusted recovery still determines resilience. The goal is simple: give ICS/OT practitioners a hands-on example, supporting data, and a reusable technical paper they can take back to leadership to justify improved OT incident response before the next incident proves the need the hard way.
Speaker
Donovan Tindill
Sr Dir, OT Cybersecurity - DeNexus
Donovan is Sr Director and Subject Matter Expert (SME) at DeNexus. He spent over 17 years as a customer-facing ICS/OT cybersecurity consultant, and another 5 years in Product Management with direct leadership over Honeywell's ICS/OT cybersecurity products, consulting and managed security services. Donovan now provides industry expertise for DeNexus’ DeRISK platform.
From startups to large public companies, he has been a major contributor to the OT cybersecurity community since 2000 including ISA-99/62443 author/contributor/trainer, Vice-Chair for DHS Industrial Control Systems Joint Working Group (ICSJWG) Steering Team (IST); Public Safety Canada ICS Security Symposium Advisory Committee member and advisor to universities building ICS/OT cybersecurity curriculums.
From startups to large public companies, he has been a major contributor to the OT cybersecurity community since 2000 including ISA-99/62443 author/contributor/trainer, Vice-Chair for DHS Industrial Control Systems Joint Working Group (ICSJWG) Steering Team (IST); Public Safety Canada ICS Security Symposium Advisory Committee member and advisor to universities building ICS/OT cybersecurity curriculums.
