Panel: From Warning to Action - Defending Critical Infrastructure in Real Time
About This Session
As geopolitical tensions increasingly translate into cyber activity targeting operational technology, critical infrastructure defenders may have only hours or minutes to interpret a warning, identify exposed systems, and protect physical operations. Yet turning government intelligence into effective action remains difficult, particularly when advisories must reach operators across multiple sectors, jurisdictions, and levels of cybersecurity maturity.
This public-private panel will examine what happens between the moment a threat is identified and the moment meaningful protections are implemented. Government representatives, infrastructure operators, and cybersecurity experts will discuss how threat intelligence is shared, how organizations determine whether an advisory applies to their environments, and where coordination can break down during an active campaign.
The conversation will explore reporting and information-sharing challenges, incident-response responsibilities, government support for resource-constrained operators, and the difficult decisions organizations face when cybersecurity, operational continuity, and public safety converge. Panelists will also identify practical ways to improve collaboration before the next warning arrives, so critical infrastructure organizations can move faster from awareness to mitigation, response, and resilience.
This public-private panel will examine what happens between the moment a threat is identified and the moment meaningful protections are implemented. Government representatives, infrastructure operators, and cybersecurity experts will discuss how threat intelligence is shared, how organizations determine whether an advisory applies to their environments, and where coordination can break down during an active campaign.
The conversation will explore reporting and information-sharing challenges, incident-response responsibilities, government support for resource-constrained operators, and the difficult decisions organizations face when cybersecurity, operational continuity, and public safety converge. Panelists will also identify practical ways to improve collaboration before the next warning arrives, so critical infrastructure organizations can move faster from awareness to mitigation, response, and resilience.
Speakers
Brad Willet
OT Security Infrastructure Architect - UPS
Brad Willet is an OT Security Infrastructure Architect at UPS, where he focuses on securing and strengthening the operational technology environments that support one of the world’s largest and most complex logistics networks.
His work sits at the intersection of cybersecurity, industrial infrastructure, and large-scale operations, addressing challenges such as OT asset visibility, infrastructure security, IT/OT convergence, and safely identifying and managing industrial assets without disrupting critical business operations. Brad brings a practitioner’s perspective shaped by working across a global enterprise with thousands of facilities and decades of operational technology.
His work sits at the intersection of cybersecurity, industrial infrastructure, and large-scale operations, addressing challenges such as OT asset visibility, infrastructure security, IT/OT convergence, and safely identifying and managing industrial assets without disrupting critical business operations. Brad brings a practitioner’s perspective shaped by working across a global enterprise with thousands of facilities and decades of operational technology.
Shery S Thomas
Enterprise Information Technology Officer - US Navy Installations Command
As the Enterprise Information Technology Officer, Mr. Thomas serves to deliver common, business and operational IT services as part of the overall IT service activity.
He provides advice and vision on all matters that are IT-related and enables the business and operational functions of the CNIC enterprise by providing strategic and tactical support to leverage information technology to accomplish the CNIC mission and provide better ways to receive, process, visualize, distribute and leverage existing data and collectively position CNIC for the role of Shore Force integrator for a total workforce of over 49,000+ sailors, civilians, and contractors across 10 regions and 70 installations across the globe. This includes oversight of Network and System Security Operations, Enterprise Ashore Enclave, Enterprise/Infrastructure Services, Enterprise Information Management, Information Assurance/Security Services, Managed IT Services, Capital and Resource Allocation, and Public Safety Systems. Mr. Thomas is dual-hatted as the command intelligence officer responsible for aggregating all intelligence and threat information for the shore enterprise to include operations, facilities and environment, fleet and family support services, and resource management to enable assured command and control.
He leads enabling cyber and intelligence for compute and store, collaboration, access control and identity management, data encryption and governance creating use of processes, tools, techniques and protocols for proactive network resiliency and command and control with data driven decision making.
He provides advice and vision on all matters that are IT-related and enables the business and operational functions of the CNIC enterprise by providing strategic and tactical support to leverage information technology to accomplish the CNIC mission and provide better ways to receive, process, visualize, distribute and leverage existing data and collectively position CNIC for the role of Shore Force integrator for a total workforce of over 49,000+ sailors, civilians, and contractors across 10 regions and 70 installations across the globe. This includes oversight of Network and System Security Operations, Enterprise Ashore Enclave, Enterprise/Infrastructure Services, Enterprise Information Management, Information Assurance/Security Services, Managed IT Services, Capital and Resource Allocation, and Public Safety Systems. Mr. Thomas is dual-hatted as the command intelligence officer responsible for aggregating all intelligence and threat information for the shore enterprise to include operations, facilities and environment, fleet and family support services, and resource management to enable assured command and control.
He leads enabling cyber and intelligence for compute and store, collaboration, access control and identity management, data encryption and governance creating use of processes, tools, techniques and protocols for proactive network resiliency and command and control with data driven decision making.
Brian "SchleiF" Schleifer
Director of Content, Events - SecurityWeek
Brian "SchleiF" Schleifer is Director of Content for SecurityWeek Events. He is a retired United States Air Force veteran, cybersecurity professional, podcast host and content leader. He previously served in senior cybersecurity engineering and leadership roles at Modern Technology Solutions, Inc. His experience includes cyber-physical and weapon systems security, security control assessment, cyber testing, risk management, and AI governance. He is pursuing a Doctor of Technology at Purdue University, where his research focuses on adaptive cybersecurity policy for AI-enabled systems. He is also the creator of the Adaptive Artificial Intelligence Risk and Assurance Framework, or AAIRAF. With more than 10,000 hours of public speaking, instruction, and panel moderation experience, Brian is known for making complex cybersecurity, technology, and risk topics practical and accessible.
