Why ICS Cybersecurity Investments Fail in Critical Infrastructure
About This Session
Despite increased spending on industrial cybersecurity, many critical infrastructure organizations continue to experience preventable incidents, operational disruptions, and delayed risk mitigation. This session presents a data-driven and field-tested perspective on why cybersecurity investments in ICS/SCADA environments often fail to produce the intended outcomes.
Drawing from doctoral research on SME cybersecurity decision-making and over 25 years of real-world experience supporting enterprise and industrial environments, this talk bridges the gap between executive decision-making and operational security execution in ICS settings. While frameworks, tools, and compliance mandates continue to evolve, the underlying issue is not always technical; it is behavioral, organizational, and strategic.
Attendees will gain insight into how risk perception, decision delays, and competing operational priorities directly impact ICS security posture. The session will map these behavioral patterns to real-world ICS/SCADA environments, including energy, utilities, and manufacturing, where safety, uptime, and reliability are critical.
The presentation will also explore how modern challenges such as AI-driven threats, increasing connectivity of OT systems, and third-party risk exacerbate existing gaps in decision-making and investment effectiveness.
Most importantly, this session will provide actionable guidance tailored for ICS practitioners, including:
How to align cybersecurity investments with operational risk and safety outcomes
Techniques to overcome decision paralysis in high-stakes environments
Practical approaches to integrating IT, OT, and executive leadership priorities
A framework for improving ROI on ICS cybersecurity investments
Drawing from doctoral research on SME cybersecurity decision-making and over 25 years of real-world experience supporting enterprise and industrial environments, this talk bridges the gap between executive decision-making and operational security execution in ICS settings. While frameworks, tools, and compliance mandates continue to evolve, the underlying issue is not always technical; it is behavioral, organizational, and strategic.
Attendees will gain insight into how risk perception, decision delays, and competing operational priorities directly impact ICS security posture. The session will map these behavioral patterns to real-world ICS/SCADA environments, including energy, utilities, and manufacturing, where safety, uptime, and reliability are critical.
The presentation will also explore how modern challenges such as AI-driven threats, increasing connectivity of OT systems, and third-party risk exacerbate existing gaps in decision-making and investment effectiveness.
Most importantly, this session will provide actionable guidance tailored for ICS practitioners, including:
How to align cybersecurity investments with operational risk and safety outcomes
Techniques to overcome decision paralysis in high-stakes environments
Practical approaches to integrating IT, OT, and executive leadership priorities
A framework for improving ROI on ICS cybersecurity investments
Speaker
Dr. Ken Reaves
Managing Director - Relate Central
Dr. Kenneth Reaves is a cybersecurity executive and researcher with 25+ years of experience leading technology, security, and digital transformation initiatives. He is the Founder of Relate Central, delivering cybersecurity, risk management, and AI-driven solutions. Dr. Reaves earned his DBA from Georgia State University – J. Mack Robinson College of Business, where his research examines why cybersecurity investments fail. His work bridges executive decision-making and operational security, with a focus on critical infrastructure resilience. He is a frequent speaker at academic and industry conferences, known for delivering practical, real-world insights.
