About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

ICS / OT Stands the Cybersecurity CIA Triad on Its Head

Monday, October 5, 2026
4:30 PM - 5:05 PM
Training Room 1 (Studio 1)

About This Session

Three Foundational Pillars have long been referred to as the Cybersecurity TRIAD or more commonly, CIA (Confidentiality, Integrity, and Availability). In Information Technology, which focuses on business applications like email, payroll, and others for which “Confidentiality” is always of utmost importance.

But in ICS/OT environments, the critical piece is likely to be Availability. If industrial systems become unavailable or misbehave, critical operations may cease or cause unintended damage, including some that have life/safety impacts.

Designing for ICS Cybersecurity must still follow Security-by-Design, and Defense-in-Depth. But the approach to defining these must be informed by an understanding of both the control system architecture and the cybersecurity controls required to safeguard ICS from the adjusted CIA viewpoint.

This session will examine this critical shift in the approach to fulfilling the CIA Triad in implementing cybersecurity for ICS / OT.
• Which is more important in the OT environment, confidentiality, availability, or integrity?
• Why is this re-emphasis so critical during the design phase? (Life-safety)
• Examples of real-world impacts from breaches to OT systems
• How does this affect best practices for ICS / OT design?
• What published standards and best practices guide these designs?

Upon completion of this presentation, attendees will:
• Have increased understanding of how the Upside-Down view of the CIA Triad should be considered during design of ICS/OT networks
• Be able to quickly access standards, regulations, and other resources for effective and compliant ICS design
• Have a plan for the integration and coordination of multiple disciplines (HVAC, Electrical, Building Management Automation, Maunfacturing Automation, etc., to facilitate more efficient and robust industrial control systems design.

Speakers

Steve Johnson

Steve Johnson

Sr. Control Systems Cybersecurity Specialist - HDR

Steve Johnson, MSc, CISSP, C|CISO
Steve earned his MSc in Cybersecurity from Essex University in Colchester, England, following a career in the U.S. Army as a Communications Security Specialist. He has over 20 years of experience in the design of large-scale intelligent transportation systems, including 7 years as the program manager and principal investigator for a USDOT research project on Connected Vehicle technology.

Steve currently leads cybersecurity design and consulting services for several state DoTs, transit rail operators, and aviation facilities. He also leads cybersecurity design projects for the Department of War pertaining to building management systems.
He is a Professional Associate at HDR, a large A&E firm.
Matt Davis

Matt Davis

Control Systems Section Manager - HDR

Matt Davis is a Section Manager and Control Systems Engineer with HDR, where he leads a team of automation engineers and specializes in the planning, design, and implementation of industrial control systems for water and wastewater facilities. His experience spans PLC, SCADA, industrial networking, and control system modernization for utilities across the United States. Matt is passionate about developing practical, reliable automation solutions and helping clients navigate the technical and operational challenges of modernizing critical infrastructure.