OT Resilience Under Cyber-Kinetic Attack: Lessons from a Wartime Capital
About This Session
When the power grid is under physical attack and the network is under cyberattack at the same moment, continuity stops being a tabletop exercise. This vendor-neutral, practitioner session draws on three years directing the municipal enterprise responsible for a capital city's critical-infrastructure networks, operational telemetry, alarms, command-and-control, and essential-service continuity through sustained, simultaneous cyber and kinetic attack - directly relevant to energy, water, utility, and transportation operators preparing for hybrid threats.
It covers real operational decisions and the lessons that proved decisive: telling a kinetic-caused outage apart from a cyberattack in real time (so response isn't wasted on the wrong failure mode); prioritizing scarce resources when not every system can be protected; treating redundancy - backup power, diverse routing, alternative communications such as TETRA and LoRaWAN, distributed workloads - as a governance and budget decision rather than an engineering afterthought; sustaining human-capital and command continuity when staff are mobilized or displaced; and running essential services in deliberate "degraded mode." Sensitive operational details are generalized.
What attendees will learn:
- How to distinguish, operationally, whether a control-system or telemetry outage is cyber or physical - and why that determination changes the response.
- A practical model for prioritizing critical OT and essential services when you cannot protect everything at once.
- Concrete redundancy and degraded-mode patterns that sustained critical city services through combined attack.
- How to architect human-capital and command-structure continuity for critical-infrastructure operations under sustained crisis.
- Transferable resilience principles US utility and critical-infrastructure operators can apply to hybrid-threat preparedness.
It covers real operational decisions and the lessons that proved decisive: telling a kinetic-caused outage apart from a cyberattack in real time (so response isn't wasted on the wrong failure mode); prioritizing scarce resources when not every system can be protected; treating redundancy - backup power, diverse routing, alternative communications such as TETRA and LoRaWAN, distributed workloads - as a governance and budget decision rather than an engineering afterthought; sustaining human-capital and command continuity when staff are mobilized or displaced; and running essential services in deliberate "degraded mode." Sensitive operational details are generalized.
What attendees will learn:
- How to distinguish, operationally, whether a control-system or telemetry outage is cyber or physical - and why that determination changes the response.
- A practical model for prioritizing critical OT and essential services when you cannot protect everything at once.
- Concrete redundancy and degraded-mode patterns that sustained critical city services through combined attack.
- How to architect human-capital and command-structure continuity for critical-infrastructure operations under sustained crisis.
- Transferable resilience principles US utility and critical-infrastructure operators can apply to hybrid-threat preparedness.
Speaker
Pavlo Chernikov
Critical-Infrastructure Cybersecurity Researcher & Practitioner (former Director, SME "Kyivteleservis") - Independent Researcher
Pavlo Chernikov directed the Kyiv municipal enterprise responsible for the city government's critical-infrastructure networks, operational telemetry, command-and-control, and digital-service continuity (2021-2024) - including utility/municipal IoT (LoRaWAN) and city-scale public-safety systems - sustained through active wartime cyber and kinetic attack across more than 1,800 institutions. He is a peer-reviewed researcher in critical-infrastructure resilience, with published work on operational resilience of municipal infrastructure under hostilities and on LoRaWAN resilience under electronic-warfare interference. ORCID: 0009-0006-7390-9698.
