From Pumps to PLCs: A Reliability-Centered Approach to Cyber Risk Management
About This Session
As artificial intelligence accelerates the discovery of vulnerabilities and increases the speed and sophistication of cyber threats, organizations face growing pressure to manage cyber risk across increasingly complex operational technology (OT) environments. Traditional vulnerability management approaches often struggle in OT settings, where safety, reliability, uptime, and operational constraints frequently make patching or remediation impractical. This presentation introduces a risk-based approach to cybersecurity by applying Reliability-Centered Maintenance (RCM) principles—traditionally used to manage critical physical assets such as pumps, turbines, and compressors—to cyber assets including workstations, servers, network infrastructure, and programmable logic controllers (PLCs). Drawing on concepts developed through Mythos and Project Glasswing, this methodology uses the D-I-P-F (Design, Installation, Potential Failure, Failure) lifecycle model to assess cyber assets through a reliability and operational risk lens rather than relying solely on vulnerability counts or compliance-driven metrics. By integrating cybersecurity into established maintenance and asset management practices, organizations can proactively identify potential failure conditions, understand operational consequences, and implement risk-informed controls throughout an asset's lifecycle. Rather than treating all vulnerabilities equally, this approach enables organizations to prioritize resources based on operational impact and business risk. Attendees will gain practical insights into how RCM concepts can be adapted to cybersecurity programs, improve communication between cybersecurity and OT teams, and support more effective risk-based decision making. The session will demonstrate how aligning cybersecurity with familiar maintenance frameworks can strengthen organizational resilience, improve prioritization, and provide a scalable approach to managing cyber risk in the age of AI.
Speaker
Stephen Mozia
Sr.Manager - PwC
Stephen Mozia, CISSP is an experienced professional who has helped guide companies through their cybersecurity, asset reliability, and digital transformation journeys across most critical infrastructure industries. Mozia is currently a Sr. Manager within PwC where he helps clients secure their OT infrastructure. Mozia previously spent his career working in consulting, engineering, and business development capacities with the cybersecurity company, Optiv, and automation vendors, Rockwell Automation and Emerson. Mozia’s focus has always surrounded securing and digitally transforming organizations through supporting innovative technologies around asset management, cyber risk management, network architecture/design, data management, analytics, augmented/virtual reality, and automation.
