About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

Why OT Johnny Can’t Encrypt

Tuesday, October 28, 2025
2:20 PM - 2:55 PM
Windsor DE (Technical Breakout)

About This Session

CISA, Standard Development Organizations, and OEMs conducted customer research within the control systems community, including water, transportation, chemical , energy, and food & ag operators, with the aim of understanding barriers to secure communication. Secure versions of industrial protocols exist (e.g., DNP3 to DNP3 SAv5); however, the technical maturity of a solution is irrelevant if the solution is not usable by the target audience. Operators often have the technical tools and desire to secure communication but cannot do so due to cost and complexity.

This talk identifies common barriers for operators and highlights ways that OT manufacturers can reduce these barriers. Examples include prioritizing message signing over encryption for easier integrity and authentication, reducing the complexity of secure deployments, and ensuring secure protocols are interoperable to simplify legacy transitions.

Speaker

Matthew Rogers

Matthew Rogers

ICS Cybersecurity Strategy & R&D Lead - CISA

Matthew Rogers, PhD, is a security researcher, with a background in building OT detection systems for planes, trains, and tanks. He leads the Secure by Design for OT initiative at CISA.