Securing Connected OT Across Cloud, Vendors, Robotics, and AI
About This Session
We've Been Converging IT and OT for 20 Years. Are We Done Yet?
For two decades, the story of industrial security has been merging IT and OT into a single, connected environment. By most measures, that project succeeded: OT now interacts constantly with enterprise systems, cloud platforms, third-party vendors, robotics, and increasingly AI.
So are we done? Not quite. The challenge has simply shifted. The question is no longer whether IT and OT should connect, but how to enable all these new capabilities without converging trust along with them. Drawing on real-world architecture experience, this talk makes the case that neither the traditional Purdue model nor zero trust alone is sufficient for OT today, and that the two must work together: Purdue's zone-based segmentation as the structural foundation, and zero trust to govern who and what is trusted as connections cross those boundaries.
Attendees will leave with a clear view of what a combined "Purdue-plus-zero-trust" strategy looks like in practice and why it's the right architecture for an OT world now defined by connection rather than isolation. (#PHGRNG)
For two decades, the story of industrial security has been merging IT and OT into a single, connected environment. By most measures, that project succeeded: OT now interacts constantly with enterprise systems, cloud platforms, third-party vendors, robotics, and increasingly AI.
So are we done? Not quite. The challenge has simply shifted. The question is no longer whether IT and OT should connect, but how to enable all these new capabilities without converging trust along with them. Drawing on real-world architecture experience, this talk makes the case that neither the traditional Purdue model nor zero trust alone is sufficient for OT today, and that the two must work together: Purdue's zone-based segmentation as the structural foundation, and zero trust to govern who and what is trusted as connections cross those boundaries.
Attendees will leave with a clear view of what a combined "Purdue-plus-zero-trust" strategy looks like in practice and why it's the right architecture for an OT world now defined by connection rather than isolation. (#PHGRNG)
Speaker
Eric Devoy
OT Security Architect - Grainger
Eric Devoy is an OT cybersecurity and digital transformation leader with 25+ years of experience securing industrial operations and enabling digital transformation. At Grainger, he leads OT security for highly automated distribution centers, driving strategy, governance, segmentation, secure remote access, monitoring, incident response, vulnerability management, and reference architectures for automation and robotics. Previously at bp, he led global OT security strategy and architecture across 150+ industrial sites, including refineries, offshore platforms, renewables, and EV charging infrastructure. His expertise spans OT cybersecurity, ICS/SCADA, IT/OT architecture, industrial automation, cloud and edge platforms, and organizational transformation.
