About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Event Session

Why the “C” of AIC for OT/ICS is becoming more critical in the age of industrial modernization

Wednesday, October 7, 2026
11:40 AM - 12:15 PM
Strategy Track (Great Room 3)

About This Session

My session will focus on the AIC vs CIA Triad and how organizations protect and view the data within their industrial environments differently than the data within their IT environments. Overall, OT areas traditionally are focused on maintaining Uptime and Safety as their primary concerns. Availability (A) comes first in AIC Triad. Integrity (I) is secondary and Confidentiality (C) is tertiary. In IT areas it is the opposite, with Confidentiality (C) as the primary goal, Integrity (I) secondary and Availability tertiary.
With attacks to OT environments on the rise, and with organizations sending more and more data to the cloud to be analyzed by AI platforms, the need for truly protecting operational data is now more important than ever.
Hackers are no longer just looking to disrupt OT systems; they are seeing the value of stealing operational data and selling it to companies and countries engaged in industrial espionage. Being able to extract data from a pharmaceutical companies control systems, as example would allow another company to start producing the exact same products. This would have devasting consequences on many levels. Unfortunately, this “as example” above is something that I worked on in my recent past.
I will present about why it is difficult to get funding to safeguard data properly because individuals within the C suite do not truly understand the data that traverses OT networks even if data is deemed worthy of protection.
I also will address the people and process challenges including the ability to implement encryption, concerns of increased overheard on computational resources, rearchitecting of legacy networks and applications and the human knowledge needed to implement it properly.
Lastly, I will speak about how organizations can safely and securely meet these concerns above and still embrace the cloud, AI, data analytics / modeling, etc. while improving operational efficiency, uptime, ROI / RTO and drive more business value across the organization.
This will not be a talk on AI. It will showcase how data can be analyzed, parsed, modeled and interpreted by a myriad of analytical / modeling tools to show business and operational value.

Speaker

Kevin Kumpf

Kevin Kumpf

Chief OT Strategist / Consultant - Kasm Technology

I am currently an industry consultant and the Chief OT Strategist, for Kasm Technology.

With more than 20 years of IT / OT experience I have worked as a true problem solver at some of the top vendors in the OT realm helping define product strategy, addressed challenging customer safety and security issues and building programs to meet regulatory and compliance challenges.

Past roles have also included Director of OT Security at Iberdrola N.A., and as the lead strategist and consultant for manufacturing, energy and cloud service providers, where I built their threat and vulnerability programs as well as built incident response teams.