About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

From Pumps to PLCs: A Reliability-Centered Approach to Cyber Risk Management

Monday, October 5, 2026
1:10 PM - 1:45 PM
Training Room 1 (Studio 1)

About This Session

As artificial intelligence accelerates the discovery of vulnerabilities and increases the speed and sophistication of cyber threats, organizations face growing pressure to manage cyber risk across increasingly complex operational technology (OT) environments. Traditional vulnerability management approaches often struggle in OT settings, where safety, reliability, uptime, and operational constraints frequently make patching or remediation impractical. This presentation introduces a risk-based approach to cybersecurity by applying Reliability-Centered Maintenance (RCM) principles—traditionally used to manage critical physical assets such as pumps, turbines, and compressors—to cyber assets including workstations, servers, network infrastructure, and programmable logic controllers (PLCs). Drawing on concepts developed through Mythos and Project Glasswing, this methodology uses the D-I-P-F (Design, Installation, Potential Failure, Failure) lifecycle model to assess cyber assets through a reliability and operational risk lens rather than relying solely on vulnerability counts or compliance-driven metrics. By integrating cybersecurity into established maintenance and asset management practices, organizations can proactively identify potential failure conditions, understand operational consequences, and implement risk-informed controls throughout an asset's lifecycle. Rather than treating all vulnerabilities equally, this approach enables organizations to prioritize resources based on operational impact and business risk. Attendees will gain practical insights into how RCM concepts can be adapted to cybersecurity programs, improve communication between cybersecurity and OT teams, and support more effective risk-based decision making. The session will demonstrate how aligning cybersecurity with familiar maintenance frameworks can strengthen organizational resilience, improve prioritization, and provide a scalable approach to managing cyber risk in the age of AI.

Speaker

Stephen Mozia

Stephen Mozia

Sr.Manager - PwC

Stephen Mozia, CISSP is an experienced professional who has helped guide companies through their cybersecurity, asset reliability, and digital transformation journeys across most critical infrastructure industries. Mozia is currently a Sr. Manager within PwC where he helps clients secure their OT infrastructure. Mozia previously spent his career working in consulting, engineering, and business development capacities with the cybersecurity company, Optiv, and automation vendors, Rockwell Automation and Emerson. Mozia’s focus has always surrounded securing and digitally transforming organizations through supporting innovative technologies around asset management, cyber risk management, network architecture/design, data management, analytics, augmented/virtual reality, and automation.