Operational Data Meshing for Critical Infrastructure: Advancing OT Detection and Response in ICS Env
About This Session
Industrial control system (ICS) environments support critical infrastructure sectors, from power generation and water systems to oil and gas, transportation and manufacturing. As these systems become increasingly connected and data-driven, traditional approaches to OT cybersecurity monitoring—primarily focused on network traffic analysis—are no longer sufficient. While network visibility remains essential, it provides only a partial view of system behavior and often lacks the operational context required to accurately detect and respond to evolving threats.
In reality, critical infrastructure operators generate vast amounts of operational data across their environments, including sensor readings, control system logs, maintenance records, engineering changes and physical security inputs. Yet much of this data remains siloed, underutilized, or disconnected from cybersecurity workflows. Operational data meshing introduces a new model: integrating cyber, operational and contextual data sources to create a unified, intelligence-driven view of risk.
This session explores how data meshing reshapes detection and response in ICS environments. By correlating network activity with process conditions and equipment behavior, organizations can more accurately distinguish between cyber incidents and normal operational anomalies, validate alerts across multiple data sources and uncover attack techniques that would otherwise remain undetected. This approach enhances visibility, reduces time-to-detection and response and improves decision-making during incident handling.
The discussion will explore the benefits of data meshing implementation across critical infrastructure environments, leveraging existing data assets, adopting an intelligence-led approach and evolving from a traditional security operations center (SOC) to a broader operational intelligence capability.
Attendees will leave with a clear understanding of how to move beyond isolated monitoring tools toward a more adaptive, context-rich cybersecurity model, one that strengthens resilience, supports operational continuity and enables more proactive and predictive defense across modern ICS environments.
In reality, critical infrastructure operators generate vast amounts of operational data across their environments, including sensor readings, control system logs, maintenance records, engineering changes and physical security inputs. Yet much of this data remains siloed, underutilized, or disconnected from cybersecurity workflows. Operational data meshing introduces a new model: integrating cyber, operational and contextual data sources to create a unified, intelligence-driven view of risk.
This session explores how data meshing reshapes detection and response in ICS environments. By correlating network activity with process conditions and equipment behavior, organizations can more accurately distinguish between cyber incidents and normal operational anomalies, validate alerts across multiple data sources and uncover attack techniques that would otherwise remain undetected. This approach enhances visibility, reduces time-to-detection and response and improves decision-making during incident handling.
The discussion will explore the benefits of data meshing implementation across critical infrastructure environments, leveraging existing data assets, adopting an intelligence-led approach and evolving from a traditional security operations center (SOC) to a broader operational intelligence capability.
Attendees will leave with a clear understanding of how to move beyond isolated monitoring tools toward a more adaptive, context-rich cybersecurity model, one that strengthens resilience, supports operational continuity and enables more proactive and predictive defense across modern ICS environments.
Speaker
Keon McEwen
Head of Solutions Development, Global Industrial Cybersecurity - Black & Veatch
Keon is the Head of Solutions Development at Black & Veatch’s Industrial Cybersecurity practice. His expertise includes cybersecurity, control systems, automation and data. He brings a unique combination of technical expertise and market development acumen to help companies achieve success during pivotal moments of change. At ABS Group, he designed, built and managed their Industrial Security Operations Center (ISOC) and under his leadership, the ISOC expanded globally to 20+ countries and grew the customer base across critical infrastructure industries such as Power, Oil & Gas, Transportation and Manufacturing. Keon has a strong knowledge in OT/ICS systems, related compliance requirements and guidelines (NERC CIP, IMO) and cybersecurity frameworks (NIST, ISA/IEC 62443, ISO).
