About

Conference

SecurityWeek’s ICS Cyber Security Conference is the conference where ICS users, ICS vendors, system security providers and government representatives meet to discuss the latest cyber-incidents, analyze their causes and cooperate on solutions.

<We_can_help/>

What are you looking for?

>Sessions

Monday, October 5, 2026

Industrial Cybersecurity Launchpad (12PM - 5PM)

(Workshop Registration Fee: $395)

Navigating the complex world of industrial cybersecurity can be daunting for those new to the field. With emerging threats targeting OT, there has never been a more critical time to understand and secure your industrial systems.

Geared towards newcomers but beneficial for all, these sessions cover everything from landscape overviews to emergency response protocols.

Whether you’re new to the field or looking to fill gaps in your existing knowledge, these Launchpad sessions will provide an overview of various elements of industrial cybersecurity. Equip yourself with the foundational tools and skills to secure your industrial systems in today’s ever-evolving cyber landscape. Join us for a full day of learning, practical exercises, and networking opportunities.

The Industrial Cybersecurity Launchpad workshop consists of several sessions that will help you take the next step towards becoming an industrial cybersecurity pro!

Training Room 1 (Studio 1)
Mon 11:45 AM - 12:00 PM

Target Rich, Cyber Poor: Raising the OT Security Baseline As Attacks Get Cheaper

Most OT security guidance is written for organizations that don't exist: well-staffed, well-funded teams with mature programs. The reality for much of critical infrastructure is the opposite. A water district, a rural cooperative, or a regional manufacturer often runs critical processes with a handful of people and a fraction of the baseline controls that frameworks assume. These operators have long been protected less by their defenses than by a simple fact: they weren't worth the effort to attack.

That protection is eroding. As the marginal cost of a capable attack falls, the economics of target selection change with it. Reconnaissance, social engineering, and exploitation are all getting cheaper, and when attacking gets cheaper, attackers cast a wider net. Operators who used to sit below the threshold of attention increasingly won't.

This session makes the case that the right response is not the advanced, expensive tooling the market tends to sell, but getting the fundamentals right first. We'll walk through what a right-sized OT security baseline actually looks like for a resource-constrained operator, including a pragmatic take on defense in depth that fits real staffing and budgets.

We'll then look at how open-source tooling can help teams raise that baseline at little or no cost, focusing on the structural building blocks rather than specific product picks, and being honest about where the gaps are. Attendees will leave with a way to reason about sequencing and spend on their own terms.

Training Room 1 (Studio 1)
Mon 12:00 PM - 12:35 PM

Beyond the Buzzwords: A Practical, Risk-Based Approach to What Actually Matters in OT Cybersecurity

Beyond the Buzzwords: What Really Matters in OT Cybersecurity challenges the industry’s fixation on emerging technologies and reframes the conversation around practical, risk-reducing fundamentals. Drawing on real-world operational technology (OT) environments, this session cuts through hype—such as AI-driven detection, Zero Trust, and advanced analytics—to reveal why many organizations remain vulnerable despite significant investments.
The presentation highlights a critical disconnect: while cyber threats are growing, many OT environments still lack essential capabilities like asset visibility, network segmentation, access control, and tested recovery processes. Attendees will gain a clear, structured model for prioritizing these foundational controls, emphasizing that effective cybersecurity begins with understanding “the minimum required to avoid a major operational incident.”
A core theme of the session is that OT cybersecurity is fundamentally different from IT security. OT systems are designed for safety, uptime, and reliability—not security—and often rely on legacy technologies with limited patching windows and inherent vulnerabilities. The talk provides a pragmatic, risk-based maturity framework that helps organizations align security investments with operational realities, avoiding common pitfalls such as overengineering or copying IT approaches directly into industrial environments.
Most importantly, the presentation underscores the often-overlooked role of human behavior in cybersecurity outcomes. It demonstrates how the majority of incidents stem from simple human actions or omissions, and why awareness, training, and culture are the highest-leverage investments organizations can make. Attendees will learn how to build effective, role-based training programs and foster a reporting culture that improves detection and response.
The session concludes by outlining a maturity roadmap—from foundational controls to advanced capabilities—and identifying the most common mistakes organizations make, including over-reliance on tools and underinvestment in people.
This presentation delivers actionable guidance for security leaders, operations teams, and executives seeking clarity, prioritization, and measurable risk reduction in OT cybersecurity—focusing not on what sounds impressive, but on what actually works.

Training Room 1 (Studio 1)
Mon 12:35 PM - 1:10 PM

From Pumps to PLCs: A Reliability-Centered Approach to Cyber Risk Management

As artificial intelligence accelerates the discovery of vulnerabilities and increases the speed and sophistication of cyber threats, organizations face growing pressure to manage cyber risk across increasingly complex operational technology (OT) environments. Traditional vulnerability management approaches often struggle in OT settings, where safety, reliability, uptime, and operational constraints frequently make patching or remediation impractical. This presentation introduces a risk-based approach to cybersecurity by applying Reliability-Centered Maintenance (RCM) principles—traditionally used to manage critical physical assets such as pumps, turbines, and compressors—to cyber assets including workstations, servers, network infrastructure, and programmable logic controllers (PLCs). Drawing on concepts developed through Mythos and Project Glasswing, this methodology uses the D-I-P-F (Design, Installation, Potential Failure, Failure) lifecycle model to assess cyber assets through a reliability and operational risk lens rather than relying solely on vulnerability counts or compliance-driven metrics. By integrating cybersecurity into established maintenance and asset management practices, organizations can proactively identify potential failure conditions, understand operational consequences, and implement risk-informed controls throughout an asset's lifecycle. Rather than treating all vulnerabilities equally, this approach enables organizations to prioritize resources based on operational impact and business risk. Attendees will gain practical insights into how RCM concepts can be adapted to cybersecurity programs, improve communication between cybersecurity and OT teams, and support more effective risk-based decision making. The session will demonstrate how aligning cybersecurity with familiar maintenance frameworks can strengthen organizational resilience, improve prioritization, and provide a scalable approach to managing cyber risk in the age of AI.

Training Room 1 (Studio 1)
Mon 1:10 PM - 1:45 PM

Cybersecurity Commissioning: The OT Discipline Nobody Owns

Industrial organizations have significantly matured their approach to operational technology (OT) cybersecurity over the past decade. Manufacturers, utilities, and critical infrastructure operators perform risk assessments, deploy segmentation architectures, implement monitoring platforms, and align programs to recognized frameworks. Yet many still face the same operational problem: systems that appear “secure by design” fail to become operationalized.

The gap is rarely caused by technology alone. More often, it exists because OT cybersecurity lacks a formally owned assurance and commissioning discipline.

In industrial projects, commissioning bridges the transition between design, integration, testing, and operations. Mechanical, electrical, and safety systems are commissioned before operational handover. OT cybersecurity, however, is often treated as documentation review or post-deployment validation rather than an engineered operational assurance process.

This presentation introduces “Cybersecurity Commissioning at Scale” as a digital assurance discipline for industrial cybersecurity programs and capital projects.

The session explores why cybersecurity failures frequently emerge during integration and operational handover. Modern industrial environments involve interactions between OEM equipment, industrial networks, remote access platforms, MES systems, cloud integrations, safety systems, and operational workflows. While components may independently meet security requirements, integrated environments often introduce unmanaged trust relationships, insecure interfaces, undocumented dependencies, temporary engineering access paths, unsupported recovery assumptions, and operational workarounds not fully validated before startup.

The presentation examines how cybersecurity commissioning can establish repeatable operational acceptance criteria across the project lifecycle:

* Design validation
* Procurement requirements
* SFAT and SSAT activities
* Integration testing
* Operational readiness reviews
* Recovery and resilience validation
* Security gate reviews before handover

Rather than focusing solely on vulnerabilities or policy alignment, cybersecurity commissioning validates whether operational environments can safely and reliably function under realistic conditions while maintaining cyber resilience objectives.

Key discussion areas include:

* Cybersecurity acceptance criteria for OT
* Integrating cybersecurity into commissioning workflows
* Aligning engineering, operations, and security stakeholders
* Common failures in brownfield and greenfield projects
* Recoverability and operational resilience testing

As industrial organizations pursue digital transformation and AI-enabled infrastructure, cybersecurity can no longer remain a post-deployment validation activity. Like safety and reliability, it must become a formally engineered discipline.

Cybersecurity assurance at scale represents the next evolution in OT cybersecurity maturity.

Training Room 1 (Studio 1)
Mon 2:00 PM - 2:35 PM

Why ICS Cybersecurity Investments Fail in Critical Infrastructure

Despite increased spending on industrial cybersecurity, many critical infrastructure organizations continue to experience preventable incidents, operational disruptions, and delayed risk mitigation. This session presents a data-driven and field-tested perspective on why cybersecurity investments in ICS/SCADA environments often fail to produce the intended outcomes.

Drawing from doctoral research on SME cybersecurity decision-making and over 25 years of real-world experience supporting enterprise and industrial environments, this talk bridges the gap between executive decision-making and operational security execution in ICS settings. While frameworks, tools, and compliance mandates continue to evolve, the underlying issue is not always technical; it is behavioral, organizational, and strategic.

Attendees will gain insight into how risk perception, decision delays, and competing operational priorities directly impact ICS security posture. The session will map these behavioral patterns to real-world ICS/SCADA environments, including energy, utilities, and manufacturing, where safety, uptime, and reliability are critical.

The presentation will also explore how modern challenges such as AI-driven threats, increasing connectivity of OT systems, and third-party risk exacerbate existing gaps in decision-making and investment effectiveness.

Most importantly, this session will provide actionable guidance tailored for ICS practitioners, including:

How to align cybersecurity investments with operational risk and safety outcomes
Techniques to overcome decision paralysis in high-stakes environments
Practical approaches to integrating IT, OT, and executive leadership priorities
A framework for improving ROI on ICS cybersecurity investments

Training Room 1 (Studio 1)
Mon 2:35 PM - 3:10 PM

The Session You Didn't Know Was Open: Remote Access Blind Spots in Critical Infrastructure

Remote access to OT environments expanded massively post-COVID. It never contracted. Most operators don't know who's connected, when, or what they're doing, in real time or after the fact.
This session examines three patterns seen across water, energy, and transportation infrastructure:

Ghost sessions: legacy vendor connections that persist beyond maintenance windows, invisible to both operators and security teams
Credential blur: shared accounts across contractors and OEMs that make attribution impossible after an incident
Audit theater: logging that exists on paper but cannot reconstruct an actual session when regulators or incident responders ask

We'll walk through what these failure modes look like operationally, how they've contributed to real incidents (anonymized), and what a defensible remote access architecture actually requires, independent of any specific vendor or product.
Attendees leave with a maturity framework they can apply to their own environment on Monday morning.

FORMAT: 35 minutes + 10 min Q&A
AUDIENCE: OT security leads, control engineers, plant managers, IT/OT convergence teams

Training Room 1 (Studio 1)
Mon 3:10 PM - 3:45 PM

Espionage vs. Sabotage

What's old is new again. 50 year old (!) cybersecurity theory (Bell/La Padula vs. Biba) teaches us that a detailed asset inventory showing us where is the information we must protect is the wrong first step when we are trying to prevent sabotage vs. prevent espionage. In espionage, information is the asset - we need to know what and where it is to prevent theft and leakage. In sabotage, information is the threat - the first inventory is not of assets and information, but of data flows / attack vectors. The most important such vectors are not internal to the system, but vectors that cross consequence boundaries. When preventing sabotage, securing connectivity across consequence boundaries is not a "compensating measure," but a primary protective measure. The latest cross-agency guidance authored by the UK NCSC "Secure connectivity principles for Operational Technology" makes this distinction clear. The guidance offers strong advice for controlling the movement of incoming information flows, including hardware-enforced / ASIC-based "unhackable" inspection of dangerous incoming information. In this presentation we look at the latest advice in terms of (long forgotten) 50-year-old theory, and look at it in light of the latest threats and attacks highlighted in the (open, public) data set of cyber attacks with physical consequences in 2025.

Training Room 1 (Studio 1)
Mon 3:55 PM - 4:30 PM

ICS / OT Stands the Cybersecurity CIA Triad on Its Head

Three Foundational Pillars have long been referred to as the Cybersecurity TRIAD or more commonly, CIA (Confidentiality, Integrity, and Availability). In Information Technology, which focuses on business applications like email, payroll, and others for which “Confidentiality” is always of utmost importance.

But in ICS/OT environments, the critical piece is likely to be Availability. If industrial systems become unavailable or misbehave, critical operations may cease or cause unintended damage, including some that have life/safety impacts.

Designing for ICS Cybersecurity must still follow Security-by-Design, and Defense-in-Depth. But the approach to defining these must be informed by an understanding of both the control system architecture and the cybersecurity controls required to safeguard ICS from the adjusted CIA viewpoint.

This session will examine this critical shift in the approach to fulfilling the CIA Triad in implementing cybersecurity for ICS / OT.
• Which is more important in the OT environment, confidentiality, availability, or integrity?
• Why is this re-emphasis so critical during the design phase? (Life-safety)
• Examples of real-world impacts from breaches to OT systems
• How does this affect best practices for ICS / OT design?
• What published standards and best practices guide these designs?

Upon completion of this presentation, attendees will:
• Have increased understanding of how the Upside-Down view of the CIA Triad should be considered during design of ICS/OT networks
• Be able to quickly access standards, regulations, and other resources for effective and compliant ICS design
• Have a plan for the integration and coordination of multiple disciplines (HVAC, Electrical, Building Management Automation, Maunfacturing Automation, etc., to facilitate more efficient and robust industrial control systems design.

Training Room 1 (Studio 1)
Mon 4:30 PM - 5:05 PM

Tuesday, October 6, 2026

Welcome Remarks

Main Stage (Great Room 1-3)
Tue 8:45 AM - 9:00 AM
  • Jon "McFly" McEllroy Offensive/Defensive Cyber Engineering Team Lead - Modern Technology Solutions, Inc. (MTSI)

Cyber Attack Methods for Cyber-Physical Systems (3-Day Course)

Fee: $3995 – Includes certificate of course completion, all meals and access to all conference sessions and social functions.

Note: This hands on training will take place Tuesday, October 6th – Thursday, October 8th. Day 1 will be a full day, and Day 2 and 3 will be half days. Students will be able to attend sessions of the core ICS Cybersecurity Conference and access instructors event when the workshop is not in session.

Cyber-physical systems, i.e. systems that bridge the cyber and physical domains, are attractive targets for attack partially due to the possibility of causing real-world physical loss to the victim.

Have you ever wondered how cyber adversaries execute these sort of attacks? Do you see attacks in the news and wonder, “how did the attacker even think to do that?” Do you stay up at night thinking, “could that happen to my system?” Developers want their systems to be secure and need to understand the threat. Unfortunately, broad intel reports and vague proclamations about adversary capability and intent may not give developers a concrete understanding of what they can do to make their systems more secure.

This Cyber Attack Methods course takes a unique approach to meeting this need, putting students into the shoes of an attacker — walking them through the steps of system discovery, exploitation, and delivering a mission-impacting attack against an intentionally vulnerable virtual cyber physical system with their hands on the keyboard. In this course we won’t turn you into a hacker, but you will learn to think like one!

Course Objectives:

Provide an understanding of methods that an attacker may use against cyber-physical systems and their impact on mission readiness, capability, confidentiality, integrity, availability, productivity, or revenue.
With hands-on keyboard, develop and execute attacks against a representative cyber-physical system; discuss and evaluate mitigations against these attacks.
Foster an attacker mindset, enabling participants to think like bad actors, walk through attack methods related to historic exploits, and apply that knowledge to making systems more secure.
What students should know beforehand:

There are no firm prerequisites for the course although it’s primarily aimed towards systems engineers, system security engineers and developers. Students will get the most benefit if they are somewhat familiar with using the Linux command line and have done some programming. That being said, it is a guided tour – student’s hands will be on the keyboard but instructors will lead them all the way through.

What students will learn:

Tangible appreciation for adversary mindset, tactics, techniques and procedures related to enumerating and exploiting weaknesses in cyber physical systems. They will also learn to think through real-world mitigations and design choices to reduce attack surface and provide greater protections in the systems they design, build, or oversee.

Training Room 1 (Studio 1)
Tue 10:10 AM - 5:10 PM

Building AI Agents for ICS/OT Security: From Zero to Orchestrator

(Full day (8 hours with breaks - $495 Fee)

AI agents are transforming how we approach critical infrastructure security, but most teams are still using basic chatbots, not even realizing the full potential of what AI agents can really do. In this hands-on workshop, you’ll build real AI agents that can reason about ICS/OT and cybersecurity, remember context across engagements, coordinate multi-step workflows, and more. You’ll learn to do it safely and securely.

Starting from scratch, participants will:

• Set up and agent environment
• Build agents that understand ICS/OT protocols, threat landscapes, regulatory frameworks, and more
• Create persistent memory systems so agents learn from every engagement instead of starting fresh
• Test their agents against realistic scenarios
• Learn how to use AI agents to be more efficient with your time, save time on tasks, improve time to delivery, and supercharge just about every task you do

No prior AI engineering or programming experience required, just a laptop and curiosity. You’ll leave with a working agent framework you can customize for your own environment.

What Makes This Different

We’re not teaching prompt engineering. We’re teaching agent engineering — how to build AI systems that think, remember, and coordinate like a seasoned security team. Using Claude Code sub-agents as the foundation, you’ll learn the safest, most practical path to deploying AI in critical infrastructure environments.

Prerequisites

Laptop with terminal access, GitHub account, Anthropic API key (free trial available). Basic command-line familiarity helpful but not required.

Training Room 2 (Studio 2)
Tue 10:10 AM - 5:10 PM
  • Rina Rakipi Operations Coordinator, Threat Hunting - CISA
  • CISA Speaker CISA - U.S. Cybersecurity and Infrastructure Security Agency (CISA)

CISA Threat Briefing: Lessons From Recent Critical Infrastructure Incidents

CISA’s threat hunters have a rare view across cyber incidents affecting critical infrastructure organizations throughout the United States. Recent activity, including more than 100 incidents observed during a single month over the summer, offers an urgent look at how adversaries are gaining access, where defensive controls are failing, and which recurring weaknesses continue to place essential operations at risk.

In this featured session, CISA’s threat-hunting team will share insights from recent engagements across critical infrastructure environments. Drawing on anonymized, real-world observations, the discussion will examine common intrusion paths, attacker behaviors, visibility gaps, configuration weaknesses, and missed opportunities for earlier detection.

More importantly, the session will translate those findings into practical lessons for owners, operators, and OT cybersecurity teams. Attendees will learn what CISA’s hunters are seeing now, how organizations can identify similar exposure within their own environments, and which defensive actions can make the greatest difference before suspicious activity escalates into operational disruption.

Main Stage (Great Room 1-3)
Tue 11:00 AM - 11:35 AM

AI Found It & We Stopped It: Live OT Virtual Patching Demo

Abstract: A live demonstration of the full OT virtual patching cycle—from vulnerability discovery through risk prioritization to network-level enforcement—on industrial devices including PLCs, HMIs, and engineering workstations. The scenario centers on two cases representing challenging problems in OT vulnerability management today: a known, exploitable CVE on a legacy device that cannot be patched, and a pre-disclosure vulnerability for which no CVE or patch exists.
The demonstration will walk through:
Asset identification: How industrial devices are automatically discovered and classified across IT/OT environments using passive monitoring and deep packet inspection
AI-driven risk prioritization: Moves beyond static CVSS scores by incorporating EPSS probability, active threat campaigns, asset criticality, and existing security control coverage to surface the vulnerabilities that actually matter—live
Attack path context: How the platform visualizes multi-hop attack paths to crown-jewel OT assets—and applies virtual patches at the right enforcement point without touching the sensitive device
Known CVE virtual patching: The guided workflow from vulnerability identification to firewall policy enforcement—with zero downtime, no device changes, and automatic risk score adjustment to reflect the reduced exposure
Pre-disclosure protection: Identify and block exploitation of a vulnerability before it has been publicly disclosed or assigned a CVE, without exposing the nature of the underlying vulnerability to potential adversaries

Focus Track (Strategy Room)
Tue 11:00 AM - 11:35 AM
  • Pavlo Chernikov Critical-Infrastructure Cybersecurity Researcher & Practitioner (former Director, SME "Kyivteleservis") - Independent Researcher

OT Resilience Under Cyber-Kinetic Attack: Lessons from a Wartime Capital

When the power grid is under physical attack and the network is under cyberattack at the same moment, continuity stops being a tabletop exercise. This vendor-neutral, practitioner session draws on three years directing the municipal enterprise responsible for a capital city's critical-infrastructure networks, operational telemetry, alarms, command-and-control, and essential-service continuity through sustained, simultaneous cyber and kinetic attack - directly relevant to energy, water, utility, and transportation operators preparing for hybrid threats.

It covers real operational decisions and the lessons that proved decisive: telling a kinetic-caused outage apart from a cyberattack in real time (so response isn't wasted on the wrong failure mode); prioritizing scarce resources when not every system can be protected; treating redundancy - backup power, diverse routing, alternative communications such as TETRA and LoRaWAN, distributed workloads - as a governance and budget decision rather than an engineering afterthought; sustaining human-capital and command continuity when staff are mobilized or displaced; and running essential services in deliberate "degraded mode." Sensitive operational details are generalized.

What attendees will learn:
- How to distinguish, operationally, whether a control-system or telemetry outage is cyber or physical - and why that determination changes the response.
- A practical model for prioritizing critical OT and essential services when you cannot protect everything at once.
- Concrete redundancy and degraded-mode patterns that sustained critical city services through combined attack.
- How to architect human-capital and command-structure continuity for critical-infrastructure operations under sustained crisis.
- Transferable resilience principles US utility and critical-infrastructure operators can apply to hybrid-threat preparedness.

Main Stage (Great Room 1-3)
Tue 11:35 AM - 12:15 PM
  • Glen Combe Fortinet, OT Specialist Systems Engineer - Foritnet

Solutions Theater (Demo): Secure Remote Access for Operational Technology

The ability to securely support remote employees and contractors is essential for OT business continuity. OT organizations need to secure remote access to commission new equipment, apply critical patches, and perform repairs or troubleshooting activities remotely. This can also include remote monitoring and diagnostics, or the use of remote operations centers to cost-effectively manage geographically distributed assets.

Join this demonstration to understand the risks associated with unsecured remote access, the impact of regulations and security standards related to remote access requirements, and key security considerations when implementing remote access in OT environments.

Focus Track (Strategy Room)
Tue 11:40 AM - 12:10 PM

Panel: Building a SOC That Can Defend Both IT and OT

As IT and OT environments converge, the security operations center can no longer treat them as separate worlds. yet the two domains speak different languages, prioritize different outcomes, and often report through different teams.

This panel brings together security leaders from government and the energy sector to discuss what it actually takes to build a SOC that defends both, where IT's focus on data confidentiality meets OT's non-negotiable demands for uptime and safety. Panelists will share hard-won lessons on unifying visibility across IT and OT assets, tuning detection for industrial protocols and behaviors, and coordinating incident response when a single event can span the corporate network and the plant floor.

The discussion will also tackle the organizational realities — staffing, skills, governance, and trust between security and engineering teams — that ultimately decide whether a converged SOC succeeds. Attendees will leave with practical models for closing the IT/OT gap in their own operations.

Tech Track (Great Room 1)
Tue 1:30 PM - 2:15 PM

Panel: From Warning to Action - Defending Critical Infrastructure in Real Time

As geopolitical tensions increasingly translate into cyber activity targeting operational technology, critical infrastructure defenders may have only hours or minutes to interpret a warning, identify exposed systems, and protect physical operations. Yet turning government intelligence into effective action remains difficult, particularly when advisories must reach operators across multiple sectors, jurisdictions, and levels of cybersecurity maturity.

This public-private panel will examine what happens between the moment a threat is identified and the moment meaningful protections are implemented. Government representatives, infrastructure operators, and cybersecurity experts will discuss how threat intelligence is shared, how organizations determine whether an advisory applies to their environments, and where coordination can break down during an active campaign.

The conversation will explore reporting and information-sharing challenges, incident-response responsibilities, government support for resource-constrained operators, and the difficult decisions organizations face when cybersecurity, operational continuity, and public safety converge. Panelists will also identify practical ways to improve collaboration before the next warning arrives, so critical infrastructure organizations can move faster from awareness to mitigation, response, and resilience.

Strategy Track (Great Room 3)
Tue 1:30 PM - 2:15 PM

The Cyber-Physical Balance Sheet: Managing OT Cyber Risk, Insurance, and Resilience

OT cyber incidents are no longer just security events; they are balance-sheet events. As industrial organizations increase connectivity and modernize operations, they face a wider range of cyber-physical losses: business interruption, equipment damage, environmental liability, contractual penalties, and, in the worst cases, safety impacts. This session connects current OT threat patterns with their financial consequences and explains why many organizations still face a cyber-physical insurance gap between traditional cyber and property coverage. Using a practical risk-quantification lens, it describes the financial benefit of avoiding cyber risk (with techniques like CIE), it shows how to move from technical indicators to loss distributions, evaluate the financial benefit of mitigation, make better retain-versus-transfer decisions with insurers, and achieve the eventual state of being able to accept current OT cyber risk and answer "we've spent enough for now". This talk is about risk management, using financial loss to make better decisions about avoiding, mitigating, transferring, and accepting cybersecurity risk.

Tech Track (Great Room 1)
Tue 2:20 PM - 2:50 PM
  • George Urling Intelligence Analyst - West Virginia Department of Homeland Security - West Virginia Fusion Center

The Need for OSINT in OT Security

This session will explain how Open Source Intelligence (OSINT) can be leveraged in OT security, as well as the increasing importance of it. Due to more widespread information sharing and AI, previously low level threat actors such as Hacktivists now pose a significant threat to OT, however, many of these groups are not secretive and rather post their TTPs, objectives, and targets on social media such as Telegram, Twitter (formerly X), and Facebook. By leveraging OSINT, security stakeholders can gain insight into these emerging threats. OSINT also plays a critical role in the physical security of critical infrastructure, and may be used to identify would be threats. All of the methods I will discuss in my session are completely free and can be done by anyone with a computer and the internet, making this easily accessible to large scale and small scale OT operations. In my experience as an intelligence analyst, I have observed groups who could wreak havoc to OT systems, and post much of their information online to brag or promote a message. OSINT seems to be a widely overlooked resource as it may seem basic at first due to its ease to attain, however its mastery is where security teams can truly shine.

Strategy Track (Great Room 3)
Tue 2:20 PM - 2:50 PM

Zero Trust Remote Access for OT: Connecting Vendors and Operators Without Expanding Risk

Remote access is one of the most common entry points into OT environments, yet legacy VPNs grant broad, persistent connectivity that attackers exploit. This session examines how Zero Trust access models, including moving target defense and just-in-time, least-privilege connections, let third-party vendors, OEMs, and operators reach critical systems without standing exposure. It covers isolating remote sessions, brokering access without flattening the network, and maintaining an auditable record of who touched what. Attendees will learn how to scale secure remote access across sites while shrinking the attack surface. (#SSD)

Tech Track (Great Room 1)
Tue 2:55 PM - 3:25 PM
  • Hector Perez Head of Strategy, Global Industrial Cybersecurity - Black & Veatch

Cyber Risk Quantification for Critical Infrastructure: Moving Beyond ROI to Risk-Informed Decisions

As critical infrastructure systems become more connected and digitally enabled, industrial control system (ICS) environments are facing a growing gap between operational investment decisions and cyber risk exposure. While organizations rigorously evaluate return on investment (ROI) for modernization, automation and digital transformation initiatives, cybersecurity is often assessed using qualitative metrics that fail to capture true business impact. This disconnect leaves critical infrastructure operators exposed to risks that are not fully understood, prioritized, or funded.

This session introduces a practical approach to cyber risk quantification (CRQ) tailored for ICS environments, one that translates cybersecurity from a technical discipline into a financial decision-making tool. Grounded in established methodologies, this approach quantifies cyber risk in terms of probability and financial consequence, enabling organizations to estimate annualized loss exposure and evaluate mitigation strategies in dollars rather than subjective ratings.

We will explore how this model supports a shift from traditional ROI to Return on Mitigation (RoM), allowing operators to measure how effectively cybersecurity investments reduce financial risk. In critical infrastructure, where low-probability events can result in high-impact consequences such as operational downtime, safety incidents, regulatory penalties and long-term service disruption, this distinction is essential. Quantifying these outcomes provides a common language for aligning cybersecurity with engineering, operations and executive leadership.

This session equips critical infrastructure leaders and professionals with a framework to make informed, risk-based decisions, ensuring that cybersecurity investments are aligned with operational priorities, financial performance and the long-term resilience of essential services.

Attendees will learn how to identify high-risk transformation moments, compare competing investments and prioritize actions that deliver the greatest reduction in risk exposure. The session will also highlight how integrating CRQ into planning processes improves funding justification, strengthens cross-functional alignment and supports more resilient system design.

Strategy Track (Great Room 3)
Tue 2:55 PM - 3:25 PM

From Crash to Code Execution: Inside an AI-Assisted PLC Exploit Port

Forescout’s Vedere Labs set out to answer a practical question: how effectively can today’s AI tools help an experienced researcher adapt a working exploit from one industrial device to another?

This technical session walks through the team’s experiment porting a remote code execution exploit for CVE-2021-31886 from a WAGO 750-852 PLC to the related WAGO 750-831. The presentation will examine the research workflow, including the use of Claude Code, Ghidra, firmware analysis, live probing, and direct access to the physical PLC.

Rather than focusing on AI hype, the session will explore what actually happened during the experiment: where the AI identified useful paths, where it pursued incorrect assumptions, what technical context researchers had to provide, and how the team progressed from simply crashing the PLC to achieving controlled code execution.

The session will also examine the subsequent attempt to extend the exploit into a command-and-control implant, which ultimately resulted in a bricked device, along with the time, cost, and level of human expertise required throughout the process.

Attendees will leave with a clearer understanding of the current capabilities and limitations of AI-assisted exploit development and what increasing automation of this work could mean for industrial device manufacturers, OT security researchers, and defenders as similar techniques become easier to scale across related devices.

Tech Track (Great Room 1)
Tue 3:30 PM - 4:00 PM

East - West Detection Engineering in OT Environments

Most industrial organizations are operating with a dangerous blind spot at the heart of their OT security programs: their IT SOC and OT monitoring teams are working in complete isolation from one another, managing risk signals from disconnected platforms with under-qualified resources lacking the cross-domain context needed to recognize a coordinated attack in progress.

This session examines the structural maturity gap in OT Detection Engineering through the lens of two distinct ** and equally critical ** visibility domains: North - South detection at the IT/OT boundary, and East - West detection within the OT environment itself. Attendees will learn how sophisticated threat actors exploit the seam between these domains, why OT-native monitoring platforms routinely underperform even when deployed correctly, and what a unified, cross-domain detection engineering model looks like in practice.

Drawing on real-world practitioner experience across industrial environments, this session delivers a concrete framework for building detection capability that spans OT telemetry, mapped to MITRE ATT&CK for ICS, allowing your organization to move beyond vendor default alerting toward a governed, environment-specific detection use case library.

Strategy Track (Great Room 3)
Tue 3:30 PM - 4:00 PM

Breaking Threat Intel Silo: Cryptographic Threat Hunting in OT Environments

Operational Technology (OT) environments face a critical paradox: sophisticated attacks like TRITON, CRASHOVERRIDE, and INCONTROLLER routinely target multiple facilities, yet operators remain blind to cross-site attack patterns due to strict privacy regulations, competitive secrecy, and an inherent lack of trust. The current "share after detection" model—where threat intelligence is exchanged only after a breach is confirmed—creates a deadly information asymmetry. Attackers see the entire battlefield, while defenders fight isolated skirmishes.

This talk introduces a cryptographic framework that flips this paradigm to "share to detect." Aligned with OWASP's focus on Privacy Controls and IoT/OT Threat Intelligence, this session will demonstrate how multiple OT sites (refineries, power plants, water utilities) can collaboratively identify globally significant threats before individual sites recognize them as localized attacks. Crucially, this is achieved without exposing sensitive operational data, process telemetry, or revealing which facility discovered the threat.

By deploying autonomous "hunter agents" at historian databases and SCADA systems, the proposed architecture leverages commutative encryption and secure multi-party computation (SMC). It safely answers the question: "Is this anomalous PLC behavior a coordinated, industry-wide attack?"

We will walk through a practical scenario demonstrating how an alliance of sites can collectively validate a suspicious Modbus command sequence. We will show how a weak signal—appearing at only 15% local prevalence—can be cryptographically verified as a global Indicator of Compromise (IoC) active across 87% of participating sites. This validation triggers an immediate, coordinated defense while mathematically guaranteeing that Site A never learns Site B's process parameters, alarm rates, or asset inventory.

Target Audience: Security architects, OT/ICS defenders, and threat hunters looking to implement privacy-preserving intelligence sharing without centralizing sensitive telemetry.

Attendees will learn:

The Pitfalls of Centralization: Why traditional, centralized threat intel sharing and data lakes fail in highly regulated OT environments (and the lessons learned from those failures).

Applied Cryptography for Blue Teams: A functional breakdown of the cryptographic primitives enabling "origin-anonymous" threat artifact exchange.

Practical Deployment: How to deploy autonomous threat-hunting agents directly within existing ICS historian infrastructure.

Measurable Impact: Real-world attack scenarios where cryptographic collaborative detection provides 10-100x faster response times.

Tech Track (Great Room 1)
Tue 4:00 PM - 4:35 PM

Wednesday, October 7, 2026

Breakfast Panel Session: Evolutionary Resilience

As the critical infrastructure threat landscape evolves, organizations must continuously adapt how they prepare for, withstand, and recover from cyber incidents. This panel will explore how asset owners and operators can build resilience amid expanding attack surfaces, increasingly connected IT and OT environments, emerging technologies, supply chain dependencies, and rapidly changing adversary tactics. Panelists will discuss practical approaches to identifying critical operational risks, strengthening incident response and recovery capabilities, and evolving security strategies without disrupting essential services.

Attendees will gain insights into balancing immediate security priorities with long-term resilience and maintaining safe, reliable operations in an increasingly complex environment.

Tech Track (Great Room 1)
Wed 8:10 AM - 8:55 AM

Can This Happen to Us? Using Free Resources to Turn OT Threat Awareness Into Action

The biggest mistake we make in managing OT/ICS cybersecurity is not taking a little time to look around and see what is happening outside our own environments. Everyone is busy, especially in OT/ICS where we're asked to do A LOT more with A LOT less. It's easy to get caught up in the day-to-day, literally just trying to keep the lights on, the clean water flowing, and safe food on the table.

But if we only took just a few minutes each day to look around and see what is happening, to ask, "Can this happen to us?" And if so, ask, "What can we do about it?" If our teams just took those few minutes each day, even just each week, the world would be a much more secure and safer place.

And yet, in 2026, we still see Internet-facing PLCs being compromised for impact; we're seeing vibe-coded tools used to target OT; we're seeing not only a growing number of attacks, but also increasing impacts. The vast majority of which could be avoided if we just took a few minutes to look around.

In this session, OT/ICS cybersecurity educator Mike Holcomb demonstrates how to build a program using freely available tools and resources to help organizations raise awareness of the developing threats around them. And that greater awareness can lead to more leadership support, a better understanding of true risk in the OT/ICS world, and safer, more reliable critical infrastructure.

Attendees will learn practical ways to quickly monitor relevant developments, evaluate whether an external incident could affect their own operations, and translate intelligence into meaningful defensive action - all without having to be an OT/ICS threat analyst. The session will provide an accessible approach for organizations of any size or maturity level, proving that better situational awareness does not always require a large budget or an expensive threat intelligence platform.

Tech Track (Great Room 1)
Wed 9:00 AM - 9:35 AM

Securing Connected OT Across Cloud, Vendors, Robotics, and AI

We've Been Converging IT and OT for 20 Years. Are We Done Yet?

For two decades, the story of industrial security has been merging IT and OT into a single, connected environment. By most measures, that project succeeded: OT now interacts constantly with enterprise systems, cloud platforms, third-party vendors, robotics, and increasingly AI.

So are we done? Not quite. The challenge has simply shifted. The question is no longer whether IT and OT should connect, but how to enable all these new capabilities without converging trust along with them. Drawing on real-world architecture experience, this talk makes the case that neither the traditional Purdue model nor zero trust alone is sufficient for OT today, and that the two must work together: Purdue's zone-based segmentation as the structural foundation, and zero trust to govern who and what is trusted as connections cross those boundaries.

Attendees will leave with a clear view of what a combined "Purdue-plus-zero-trust" strategy looks like in practice and why it's the right architecture for an OT world now defined by connection rather than isolation. (#PHGRNG)

Strategy Track (Great Room 3)
Wed 9:00 AM - 9:35 AM

Secure Remote Maintenance for OT: Balancing Uptime, Access, and Protection

Industrial operations depend on remote programming and troubleshooting to minimize downtime, but each remote connection can become an attack path if poorly controlled.

This session examines how integrated remote access architectures let engineers maintain equipment across distributed sites while keeping OT networks protected and segmented. It covers controlling and monitoring vendor and technician sessions, capturing data for operational decisions, and enforcing security without slowing maintenance work.

Attendees will learn how to deliver reliable remote maintenance that supports both availability and defense.

Focus Track (Strategy Room)
Wed 9:00 AM - 9:35 AM

Testing Your DERs Before an Attacker Does: Fuzzing DNP3, SunSpec, and IEEE 2030.5

As DER deployments expand across the grid, asset owners need practical tools to understand their own security exposure. Specifically, which device commands and registers are reachable by an unauthenticated attacker on their network? As part of a DOE-funded research effort, we built a protocol fuzzing toolkit targeting DNP3, SunSpec Modbus, and IEEE 2030.5, designed to help operators map their unauthenticated attack surface and identify protocol implementation vulnerabilities before someone else does.

Building and using these tools surfaced a consistent and counterintuitive finding: the newer, better-designed protocols are in some ways easier to attack. Legacy Modbus creates friction for the attacker by hiding behind opaque register addresses, forcing an attacker to obtain vendor documentation to know what register 10000 controls. SunSpec Modbus changes this entirely: its self-describing model registers let any client walk the register space and immediately know what each control point represents, without documentation or prior reconnaissance. IEEE 2030.5 adds TLS and client certificates, but presents the same fully self-describing surface the moment a certificate leaks or validation is misconfigured, collapsing instantly to the same exposed state. The interoperability properties that make modern DER protocols easy to integrate also make them easy to target.

In this talk, we'll walk through the attack surface exposed by each protocol, what the fuzzer targets and why, and what the output looks like in practice, including how the self-description properties of SunSpec and IEEE 2030.5 change both the depth of the findings and the speed at which an attacker (or defender) can act on them. We'll then show how we layered AI on top to make the tooling more accessible and the results more actionable, closing with a recorded demonstration of the full pipeline against a simulated DER cluster.

Tech Track (Great Room 1)
Wed 9:40 AM - 10:10 AM

Quantifying OT Cyber Risk: Translating Threats Into Financial Exposure for the Board

Boards and investors increasingly expect OT cyber risk to be expressed in the language of financial impact, not just technical severity. This session explores how to quantify industrial cyber risk, linking specific threats, vulnerabilities, and asset criticality to potential loss, so leaders can prioritize investment where it matters most. It covers frameworks for modeling exposure across energy and critical infrastructure operations and communicating that risk to non-technical stakeholders. Attendees will learn how risk quantification helps operators act before a threat becomes a costly incident. (#SSCTRI)

Strategy Track (Great Room 3)
Wed 9:40 AM - 10:10 AM

Securing the Connected OT Ecosystem

As industrial environments become more connected, the boundaries of OT security are rapidly expanding. Cloud platforms, third-party vendors, robotics, AI, and remotely connected systems are creating new capabilities, but also new dependencies, attack paths, and operational risks.

In this session, an OT security architect from a leading global manufacturer will examine how organizations can secure this increasingly interconnected ecosystem without impeding modernization. The discussion will explore practical considerations for managing access, visibility, trust, and risk across traditional plant environments and the technologies now transforming them.

Focus Track (Strategy Room)
Wed 9:40 AM - 10:10 AM

Your Control Network Is Already Exposed, and Attackers Are Just Waiting

Your control network is already exposed, and you may be the last to know it. When a water utility, a manufacturer, or a rural co-op gets compromised, the cause is rarely an exotic zero-day. It is a device that should never have been reachable from the public internet: a PLC running default credentials, an HMI indexed by a search engine, a serial-to-IP converter quietly bridging the plant floor to the world.

This session takes the adversary's first move, reconnaissance, and hands it to the defender. Using real, passively-collected exposure data across critical-infrastructure sectors, we will look at what is actually reachable from the open internet right now: the device classes, the protocols, the recurring mistakes, and the recently weaponized examples, from Unitronics PLCs in the water sector to the actively-exploited Lantronix serial-to-IP flaw added to CISA's KEV list this month. No agents, and no scanning of anyone's network. Just what a browser already sees.

Then we get practical. Most of this risk collapses under a short, cheap checklist any operator can run Monday morning: get it off the internet, kill the defaults, segment, and patch the handful of CVEs that adversaries are truly using. You will leave able to find your own exposed assets and close the gaps before someone else finds them first.

Tech Track (Great Room 1)
Wed 10:15 AM - 10:45 AM

OT/IOT in CMMC

Scoping for CMMC Level 2/3 presents many challenges, and OT/IOT feature prominently in those conversations. This session will explore what you need to know for your org to be prepared for official L2/L3 assessment,

Strategy Track (Great Room 3)
Wed 10:15 AM - 10:45 AM
  • Glen Combe Fortinet, OT Specialist Systems Engineer - Foritnet

Solutions Theater(Demo): Seeing Clearly Through Segmentation: Strengthening Industrial Cybersecurity

In today’s converged IT‑OT environments, visibility is the new perimeter. As industrial networks expand to include sensors, controllers, and smart devices never designed for modern threat landscapes, traditional flat architectures leave defenders blind to lateral movement and hidden vulnerabilities.

This session demonstrates how network segmentation and microsegmentation transform vulnerability management from reactive patching to proactive risk containment. Attendees will see how granular segmentation policies reveal communication patterns between non‑traditional endpoints—such as PLCs, HMIs, and building management systems—while isolating critical assets from opportunistic threats.

Through live examples and architectural walkthroughs, we’ll explore:
- How segmentation enables continuous asset discovery and contextual vulnerability mapping across mixed IT‑OT networks.
- Practical approaches to microsegmentation that secure legacy systems without disrupting uptime.
- The role of segmentation in compensating controls when patching isn’t possible.
- Real‑world outcomes: improved visibility, faster incident response, and measurable risk reduction.

Whether you’re modernizing a plant network or defending a distributed industrial operation, this demo will show how segmentation isn’t just containment—it’s clarity.

Focus Track (Strategy Room)
Wed 10:15 AM - 10:45 AM

Closing the Control-Layer Visibility Gap

Cyber defenders are often asked a critical question: Are your controllers compromised, and has their logic or configuration been tampered with? If someone were to ask you these questions right now, would you have a good answer? What tools would you reach for to answer it?

The control layer remains a major visibility gap, and process logic and device configurations are rarely verified against a trusted baseline, if a reliable baseline even exists. Although vendor software can interact with these devices, it is frequently heavyweight, expensive, proprietary, and difficult to scale for continuous or fleet-wide assessment.

This session examines the challenge of data collection from the control layer, followed by a deep dive into an open-source tool to help address that challenge: the Process Extraction and Analysis Tool (PEAT).

https://github.com/sandialabs/peat

Tech Track (Great Room 1)
Wed 11:00 AM - 11:35 AM

Engineering Out the Adversary: Applying Consequence-Driven Cyber-Informed Engineering (CCE)

Industrial control system security teams talk in CVEs, APTs, and threat models. Mechanical and electrical engineers talk in FMEA, margins, and safety factors. Value engineers track line items and budgets. Risk owners demand defensible compliance records. Each discipline does the right work in its own language, and the consequences that matter most sit at the blind handoffs between them.

Consequence-driven Cyber-informed Engineering (CCE) is Idaho National Laboratory's methodology for working backwards from the worst-case engineered consequence. It asks a singular question: can an adversary trigger that specific consequence through cyber means? CCE assumes breach by design. It prioritizes engineered and procedural protections that take the consequence out of cyber reach. Once those protections are in place, they hold whether the trigger is an adversary, an operator, a software bug, or an AI agent acting outside its envelope.

To demonstrate this, the session runs an accelerated CCE tabletop on a representative ICS system selected by the room from a curated list. The audience works through Phase 1 consequence prioritization and Phase 2 system-of-systems analysis, as we map the process from both sides of the aisle. We take the physical failure modes engineers care about and connect them to the attack paths security uses to reach them. By the end of the exercise, we produce what every CCE engagement yields: a functional block diagram highlighting choke points and engineered protection candidates.

The resulting diagram gives every discipline the same reference to work from. Each team sees functional blocks, trust boundaries, and attack paths without needing to be an expert in everything. The same artifact carries into traditional IT penetration testing, design review, and cost decisions, because it ties the argument to consequence rather than tool findings alone. The analysis handles the parts of OT where ownership and visibility break down, including the closed-source vendor devices the architect can only engineer around. The steps don't change. What changes the outcome is running them early enough to influence design, with the right people in the room.

Strategy Track (Great Room 3)
Wed 11:00 AM - 11:35 AM

From Secure Remote Access to Autonomous OT Security: How One Global Manufacturer Got It Right

Managing third-party access across global manufacturing is no longer just about secure connectivity - it's about creating the operational foundation for modern OT security.

In this session, we'll follow the real-world journey of one of the world's largest manufacturers as they standardized secure remote access across more than 100 production sites, 90+ suppliers, and operations in 70 countries. What began as an initiative to replace fragmented remote access solutions evolved into a global operating model for governing third-party access.

More importantly, we'll explore what that standardization unlocked:

- Federated control – Govern vendors globally while preserving local plant autonomy.
- Third-party access governance – Gain visibility, accountability, and compliance with frameworks such as IEC 62443 and NIS2.
Cyber resilience – Reduce risk and enable faster, more coordinated response during incidents.
- Agentic SOC – Provide the operational context AI needs to distinguish approved maintenance from real threats and enable trusted autonomous security operations.

Join us to discover why the future of OT security doesn't start with AI—it starts with standardizing how people, vendors, and machines connect. Because before security operations can become autonomous, they need a trusted foundation of governance, visibility, and context.

Focus Track (Strategy Room)
Wed 11:00 AM - 11:35 AM

Faster Than You Can Watch: Why Agentic AI Breaks the OT Visibility Model

Most OT security programs have spent the last several years chasing one goal. Visibility. ICS asset inventories, passive taps at the Purdue Level 2/3 boundary, IPS/IDS tuned to known-bad Modbus, DNP3, or OPC traffic patterns. The assumption has always been that if you can see it, you can stop it.

Agentic AI breaks that premise. In our threat research we have identified AI-driven reconnaissance and attack tooling that can chain together legitimate-looking engineering workstation commands, pivot from IT to OT, and probe PLCs, RTUs, and HMIs for weaknesses faster than any analyst watching a SIEM dashboard.

Faster detection won’t fix this. That’s a race defenders keep losing. What has to change is what the architecture assumes in the first place, containment that doesn’t depend on catching someone in time, a definition of “normal” that doesn’t rely on pattern-matching bad behavior fast enough, and incident response model that doesn’t compromise human safety or plant shutdown.

This session breaks down what’s actually changing in OT attacker tradecraft, and what that means for how teams need to architect detection and response on the plant floor going forward.

Tech Track (Great Room 1)
Wed 11:40 AM - 12:15 PM

Why the “C” of AIC for OT/ICS is becoming more critical in the age of industrial modernization

My session will focus on the AIC vs CIA Triad and how organizations protect and view the data within their industrial environments differently than the data within their IT environments. Overall, OT areas traditionally are focused on maintaining Uptime and Safety as their primary concerns. Availability (A) comes first in AIC Triad. Integrity (I) is secondary and Confidentiality (C) is tertiary. In IT areas it is the opposite, with Confidentiality (C) as the primary goal, Integrity (I) secondary and Availability tertiary.
With attacks to OT environments on the rise, and with organizations sending more and more data to the cloud to be analyzed by AI platforms, the need for truly protecting operational data is now more important than ever.
Hackers are no longer just looking to disrupt OT systems; they are seeing the value of stealing operational data and selling it to companies and countries engaged in industrial espionage. Being able to extract data from a pharmaceutical companies control systems, as example would allow another company to start producing the exact same products. This would have devasting consequences on many levels. Unfortunately, this “as example” above is something that I worked on in my recent past.
I will present about why it is difficult to get funding to safeguard data properly because individuals within the C suite do not truly understand the data that traverses OT networks even if data is deemed worthy of protection.
I also will address the people and process challenges including the ability to implement encryption, concerns of increased overheard on computational resources, rearchitecting of legacy networks and applications and the human knowledge needed to implement it properly.
Lastly, I will speak about how organizations can safely and securely meet these concerns above and still embrace the cloud, AI, data analytics / modeling, etc. while improving operational efficiency, uptime, ROI / RTO and drive more business value across the organization.
This will not be a talk on AI. It will showcase how data can be analyzed, parsed, modeled and interpreted by a myriad of analytical / modeling tools to show business and operational value.

Strategy Track (Great Room 3)
Wed 11:40 AM - 12:15 PM

Seeing the Unseen: Asset Visibility and Exposure Management Across Cyber-Physical Systems

You cannot protect what you cannot see, and industrial environments are full of unmanaged cyber-physical assets spanning OT, IoT, and the extended internet of things. This session explores how deep asset discovery and passive monitoring build a complete inventory across converged environments without disrupting sensitive processes. It covers using that visibility to prioritize exposures, drive network segmentation, and detect anomalies across utilities, manufacturing, and healthcare settings. Attendees will learn how comprehensive cyber-physical visibility forms the foundation for exposure management and threat detection. (#SSCLT)

Focus Track (Strategy Room)
Wed 11:40 AM - 12:15 PM
  • Daniel Paré Principal Product Manager, Industrial OT Security - Palo Alto Networks

AI-Accelerated Exploits and the Case for Pre-Disclosure Virtual Patching in OT

Nearly one in four vendor vulnerability advisories publish with no patch available at all, and 85% of OT organizations do not patch regularly even when patches exist.

Virtual patching against known CVEs addresses the patch window problem. It does not address the window before the CVE exists.

AI-powered vulnerability research has fundamentally changed how quickly vulnerabilities are discovered and weaponized.

How do critical infrastructure organizations protect their OT assets from a vulnerability that has been discovered privately before disclosed publicly?

We will walk through the mechanics of pre-disclosure virtual patching protection—how vulnerability intelligence shared ahead of public disclosure can be translated into network-level enforcement that protects critical assets before a patch is available, without exposing details that could enable a malicious actor to develop an exploit during the pre-disclosure window. This includes the “vaulted protection” model, where detection logic is delivered to enforcement points in a way that prevents adversaries from reverse-engineering the coverage to learn what vulnerability they are up against.

Tech Track (Great Room 1)
Wed 1:30 PM - 2:00 PM
  • Carlos Sanchez Fortinet, Director, OT Systems Engineering Specialist - Fortinet

Applying Network Detection and Response in OT without Breaking Operations

Most industrial organizations have invested for years in asset inventories, segmentation, and monitoring. Yet many still struggle to answer one critical question: what is happening on the wire inside the plant right now?

In OT, endpoint agents often cannot be deployed. Logs are incomplete or unavailable. And the activity that matters most — controller-to-controller traffic, unexpected engineering workstation access, unauthorized protocol commands, and lateral movement across flat networks — can remain invisible until it becomes an incident.

This session explains where Network Detection and Response fits in an industrial cybersecurity strategy, and where it does not. We will cover how NDR complements segmentation, SIEM, and EDR without disrupting safety-critical operations. Attendees will learn how to evaluate NDR for real OT environments, including passive monitoring, tap and SPAN placement, Purdue model visibility, protocol coverage, data residency, and integration requirements.

We will close with three practical OT use cases: passive asset discovery, baseline-driven anomaly detection, and threat hunting for lateral movement in legacy or flat networks.

Learning Objectives:
- Explain how NDR differs from EDR, SIEM, and segmentation in an OT architecture.
- Apply a vendor-neutral checklist for evaluating OT NDR solutions before procurement.
- Identify three high-value industrial use cases for NDR and recognize environments where it may not provide sufficient value.

(Sponsored Session by Fortinet)

Strategy Track (Great Room 3)
Wed 1:30 PM - 2:00 PM

Frontier vs. Local LLMs for OT Security - Considerations & Use Cases

Besides enthralling people with easy-to-generate funny images & videos, LLMs and AI have made significant inroads in enterprise use cases the past 3-4 years. Several IT Security tools have an AI component, be it a chatbot or some kind of model based analytics. While OT Security software too is adding some of that functionality, the real difference will be made when more OT datasets are analyzed, likely on-prem due to various constraints including data aggregation challenges, ingress/egress costs to the Cloud, infrastructure & compute, knowledge & skillsets (new lingo - harness, prompt engineering) etc.
For some, the best way to take advantage of AI developments is to run local models (e.g., Qwen, Gemma), extract as much as value as possible on local HW, and supplement it with Frontier models when able to query without sending sensitive data to the Cloud. This presentation outlines the current state of the union, HW & SW availability & requirements based on use cases, efficacy, confidentiality, decision making process in building out the tech stack including what tools are currently available for local inference & reasoning, and things to consider when adding Frontier models in OT Security projects.

Tech Track (Great Room 1)
Wed 2:05 PM - 2:35 PM

Practical Implementation of IEC 62443 in Cyber-Physical Systems: Bridging Compliance and Real-World

This session addresses the critical challenge of translating IEC 62443 cybersecurity requirements into practical, deployable controls within real-world cyber-physical systems. It begins by examining the gap between compliance frameworks and implementation realities, particularly in OT environments where constraints such as system availability, legacy devices, and safety requirements complicate security integration. The talk then introduces an architecture-centric approach, showing how IEC 62443 concepts like zones and conduits can be mapped to actual OT system designs. Key implementation areas are explored in depth, including access control models, secure remote access through jump host architectures, network segmentation strategies, PKI-based trust establishment for OT devices, and effective logging and monitoring practices aligned with audit expectations. Drawing from field experience, the session highlights common failure points observed during system integration, FAT/SAT testing, and audits, such as misconfigured access controls, ineffective segmentation, and incomplete certificate lifecycle management. It concludes with practical guidance on developing repeatable validation procedures and generating audit-ready evidence, enabling organizations to move beyond theoretical compliance and achieve secure, resilient, and verifiable OT deployments in critical infrastructure environments.

Strategy Track (Great Room 3)
Wed 2:05 PM - 2:35 PM

Quantifying OT Cyber Risk in Financial Terms: Executive Action in Critical Energy Infrastructure

As energy systems become more distributed, digital and interconnected, operational technology is now central to the resilience of critical infrastructure. Wind, solar, battery storage, grid-connected assets, gas, data centres and other energy environments depend on complex OT ecosystems that were often not designed with today’s cyber risk in mind.

For many operators, the challenge is no longer whether cyber risk exists. The challenge is understanding what is connected, where exposure sits, which risks could affect operations, and how to translate technical findings into decisions that boards, investors, compliance teams and asset managers can act on.

This session will present a practical, vendor-neutral approach to OT cyber risk management across critical energy infrastructure. It will explore how organisations can move from fragmented asset lists and one-off assessments towards continuous visibility, risk prioritisation, compliance evidence and executive reporting.

The presentation will focus on the operational realities of energy infrastructure: distributed sites, mixed vendor environments, limited local cyber expertise, evolving regulation and the need to protect uptime, safety, compliance and business continuity. Rather than focusing on a single technology or product, the session will give attendees a repeatable framework for connecting OT visibility with cyber resilience and business action.

Focus Track (Strategy Room)
Wed 2:05 PM - 2:35 PM

Photonics for Resilient OT Security

Operational technology security is usually approached through firewalls, identity, endpoint monitoring, remote access, and policy enforcement. These controls are essential, but they do not address the full picture. In industrial environments, the physical communications layer also affects segmentation, availability, recovery, and incident response.

This session examines how photonic technologies and optical infrastructure can support more resilient OT security. It does not present fiber as inherently secure or as a replacement for established controls. Instead, it shows how the optical layer can add visibility, control, and operational assurance when integrated into an OT architecture.

OT environments often include legacy systems, fragile protocols, limited endpoint visibility, and systems that cannot be routinely patched, scanned, or restarted. Availability and safety are critical because poorly implemented controls can interrupt production or affect physical processes.

These constraints make segmentation especially important, but segmentation often degrades over time. Temporary connections become permanent, vendor access remains enabled after maintenance, engineering workstations gain access across multiple zones, and undocumented changes undermine the approved architecture. This creates segmentation drift, where the real network no longer matches the intended design.

The session will explore how fiber-based designs can support more durable OT zones and conduits. It will also examine optical switching as a way to create temporary, authorized paths for maintenance, contractor access, diagnostics, and OT-to-enterprise transfers. When the task is complete, the path can be removed instead of remaining continuously available.

Another focus will be optical-layer telemetry. Signal strength, link state, error conditions, component health, and path changes can provide valuable context during an incident. When correlated with network, security, and process data, this information can help teams distinguish malicious activity from physical damage, equipment failure, environmental conditions, or configuration errors.

The presentation will connect these capabilities to Zero Trust by asking practical questions: What assets are communicating? Who authorized the connection? Which path is being used? Is that path still required? Can it be observed and removed?

The session will also address limitations. Fiber can still be tapped, damaged, misconfigured, or connected to compromised equipment. Optical switching can introduce management and control-plane risks. Photonics cannot replace identity, access control, logging, monitoring, incident response, governance, or sound cyber hygiene.

Attendees will leave with a practical framework for evaluating where photonic technologies can improve OT segmentation, visibility, controlled connectivity, and recovery without creating unnecessary operational risk.

Tech Track (Great Room 1)
Wed 2:40 PM - 3:10 PM

AI-Augmented Attacks on Industrial Control Systems and the Road Ahead

When John Matherly presented Shodan at DEF CON 18 in 2010 he highlighted a world of exposed industrial infrastructure. It was a surreal moment as he navigated through the engine to interact with web-connected ICS/OT devices. While we think of that as the past critical infrastructure assets still populate the tool and it provides enumeration and reconnaissance for security professionals and threat actors even today.

Similar to this famous presentation 15 years ago, the community is starting to witness the rise of AI-assisted threat actors. In an intrusion against a municipal water and drainage utility in Monterrey, Mexico, an adversary used commercial AI tools to carry out core intrusion activities with no prior knowledge of or intent to target OT infrastructure. What distinguished this campaign was not the novelty of its techniques, publicly available offensive methods, but the speed and autonomy with which AI operationalized them.

While making predictions about the future of technology is always a dubious task, there is a short runway of action to take in the near time to harden security controls against the weaponization of AI by adversaries. AI is being used to shorten that time from IT compromise to weaponization of stage 2 ICS-capable attacks that can have a direct impact on the operations of the victim’s organization.

Strategy Track (Great Room 3)
Wed 2:40 PM - 3:10 PM
  • Domenic Busa Senior Manager, Solutions Engineering - Johnson Controls

Reconnaissance Denial in OT: Using the Host Identity Protocol to Deny Asset Discovery

Many OT security programs assume that reconnaissance will succeed. An attacker gains a foothold through an IT workstation, vendor laptop, jump host, or flat engineering network. From there, they scan for reachable systems, identify PLCs, HMIs, historians, remote access services, file shares, or building automation devices, and then decide where to pivot.
This session asks a different architectural question: what changes when unauthorized systems cannot discover the OT assets in the first place?
The session introduces the Host Identity Protocol, defined in IETF RFC 7401, as a practical foundation for identity-based OT communication. HIP separates a host’s identity from its network location and uses a cryptographic exchange to mutually authenticate peers before a communication session is established. Paired with default-deny admission control, where a host declines to engage any identity that is not already authorized, this produces an important defensive property: protected systems can remain unreachable to hosts that cannot present an authorized identity. Because field controllers do not speak HIP natively, this protection is delivered by HIP-capable endpoints and gateways that authenticate on the device’s behalf.
We will walk through how HIP works at the protocol level, including the base exchange, host identity model, locator/identity separation, and the puzzle mechanism used to shift denial-of-service cost back to the initiator. We will be precise about where the reconnaissance-denial property actually comes from: cryptographic identity plus admission policy, not the bare protocol. We will also discuss the data-plane implications and compare HIP-based communication with approaches OT teams already use, including VPNs, IPsec and WireGuard tunnels, firewall ACLs, and Purdue-model segmentation.
The session places HIP in the context of familiar OT security frameworks, including NIST SP 800-207 zero trust principles and the IEC 62443 conduit model. The goal is not to position HIP as a replacement for visibility, monitoring, EDR, vulnerability management, or incident response. It does not stop an attacker who has already compromised an authorized identity or endpoint, where the protected assets become reachable as designed. It changes where network monitoring happens, since encrypted conduits move inspection to the endpoint or gateway rather than a passive midpoint. And it introduces real design considerations around identity lifecycle, key management, endpoint trust, physical access, and broadcast-dependent industrial protocols.
Attendees will leave with a practical framework for evaluating where HIP-based reconnaissance denial belongs in an OT security architecture, especially for legacy assets, remote sites, mobile systems, vendor access, and environments where patching or network redesign is difficult.

Tech Track (Great Room 1)
Wed 3:15 PM - 3:45 PM

Cyber Attack and Process Safety

Operation technology (OT) cyber incidents from the past have demonstrated that attacks on industrial automation control systems (IACS) are no longer limited to data loss or operational downtime. These cyber incidents can have direct and consequential impacts on process safety. Events such as TRITON/TRISIS, the Colonial Pipeline ransomware incident, and disruptions to critical infrastructure worldwide highlight how cyber threats can propagate into unsafe process conditions, challenge operator decision-making, and degrade or disable critical protection layers.
This presentation examines several historical industrial cyber incidents through a process safety lens, focusing on how each event impacted core safety functions: loss of control, loss of view, and loss of protection. Some common patterns emerge of these historical industrial cyber event, including breakdowns in system segmentation, nonverified digital information, and the erosion of independence between protection layers.
Attendees will gain:
• A clear understanding of how cyber incidents translate into process safety risks
• Practical lessons learned from real-world events and their implications for safety-critical systems
• Insight into how traditional safety assumptions (e.g., independence of protection layers) can be invalidated by cyber compromise
• Ideas on how to use cybersecurity risk assessment information for safety risk assessments
Putting cyber risk processes to work for safety risk analysis, through all levels of the OT network and not just below Level 3.5, can ultimately benefit both areas of domain knowledge and create synergistic practices.

Strategy Track (Great Room 3)
Wed 3:15 PM - 3:45 PM

Ghost in the Grid: Hijacking AI Agents Through Hidden Channels in OT/ICS Networks

AI agents are now operating inside the Purdue Model. At Levels 2 and 3, they are reading SCADA outputs, interpreting HMI screens and camera feeds, and issuing commands to supervisory systems and controllers. The security community has not caught up. No existing OT security layer watches what these agents perceive or act on.

This session presents original research into a new class of attack: steganographic prompt injection against Vision Language Models operating in live industrial environments. Attackers embed hidden instructions inside camera frames, HMI screenshots, maintenance PDFs, and sensor data visualizations using techniques. The agent extracts the payload, interprets it as a legitimate operational instruction, and acts on it. No network anomaly. No signature match. No alert.

We walk through three attack vectors mapped to the Purdue Model:

Steganographic injection into camera feeds at Level 3, targeting a Vision Language Model processing quality control imagery in a simulated manufacturing environment.
Trust laundering across a multi-agent supervisory chain at Level 2, where a poisoned input to Agent A propagates as trusted context to Agent B without ever appearing in a single suspicious message.
Adversarial audio perturbations targeting voice-enabled autonomous systems on the factory floor.
Each vector is demonstrated live, followed by a detection and mitigation walkthrough using a perception-layer security architecture that intercepts agent inputs before inference. The architecture integrates into existing OT network designs without requiring changes to PLC, historian, or SCADA configurations.

We close with a mapping of these attack patterns to MITRE ATT&CK for ICS and the NIST AI Risk Management Framework, giving asset operators a compliance-ready vocabulary for communicating risk to leadership and auditors.

Tech Track (Great Room 1)
Wed 3:50 PM - 4:20 PM

Fortifying the Front Lines: Public-Private Readiness for an OT Crisis

In a true critical infrastructure crisis, familiar communications, remote access, vendor support, and internet-based tools may be unavailable. Preparing for that moment requires more than an individual organization’s incident response plan. It demands coordinated action across government, infrastructure operators, security providers, equipment manufacturers, and local communities.

In this featured session, representatives from the Cybersecurity and Infrastructure Security Agency (CISA) will explore how CI Fortify brings public- and private-sector partners together to strengthen the resilience of operational technology and critical infrastructure. The discussion will examine the distinct but interconnected roles each community must play: owners and operators conducting isolation exercises and building regional resilience; cybersecurity vendors providing “watch and warn” capabilities; and OEMs helping customers prepare to operate, recover, and obtain support during a severe communications outage.

Attendees will learn how these groups can establish relationships before a crisis, exercise realistic worst-case scenarios, clarify responsibilities, and create resilient communities capable of sustaining essential operations when normal systems and assumptions no longer apply.

(Learn more about CI Fortify: https://www.cisa.gov/topics/industrial-control-systems/ci-fortify)

Strategy Track (Great Room 3)
Wed 3:50 PM - 4:20 PM

Turning Industrial Threat Intelligence Into Action

OT networks face targeted adversaries that specifically study industrial protocols and processes, yet many operators lack the visibility to detect them. This session examines how continuous OT monitoring, asset inventory, and industrial threat intelligence combine to surface malicious activity across IT, OT, and IoT. It covers building detection use cases around known adversary behaviors and operationalizing incident response tailored to plant environments, where uptime and safety constrain traditional playbooks. Attendees will learn how to translate threat intelligence into practical detection and response for industrial systems. (#SSDGS)

Tech Track (Great Room 1)
Wed 4:20 PM - 4:55 PM

Closing the OT Recovery Gap: Backup and Source Control for Industrial Code

When a PLC fails, is misconfigured, or is compromised, the speed of recovery depends on having a known-good version of industrial code, something many operators lack.

This session explores the OT recovery gap and how automated backups and version control for controller logic reduce downtime and support faster restoration. It covers monitoring changes to industrial code, enforcing approval workflows, and maintaining a reliable source of truth across control systems. Attendees will learn how disciplined code management strengthens both resilience and change accountability in OT.

Strategy Track (Great Room 3)
Wed 4:20 PM - 4:55 PM

Thursday, October 8, 2026

Actioning Threat Intelligence: Tuning Intrusion Detection Systems for Nation State Attacks

Recent joint alerts from the FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command warn of active cyber exploitation of internet connected operational technology (OT) devices across U.S. critical infrastructure. Iranian advanced persistent threat (APT) actors—linked to prior IRGC associated CyberAv3ngers activity—are actively targeting PLCs supporting government, water, and energy sectors.

This presentation analyzes the observed OT attack kill chain, from initial access to operational impact, and maps adversary behavior to the MITRE ATT&CK® for ICS framework. We'll also delve into how OT-aware Intrusion Detection Systems (IDS) can help to mitigate each stage of the kill chain. OT IDS identified anomalous remote desktop activity, unauthorized protocol access retrieving PLC attributes, exposed device vulnerabilities, threat actor IP addresses and C2 communications, and unauthorized PLC command and control state changes in near real time.

Tech Track (Great Room 1)
Thu 9:00 AM - 9:30 AM
  • Ian Bramson Vice President, Global Industrial Cybersecurity - Black & Veatch

Agentic AI in Critical Infrastructure: Redefining OT Cybersecurity in ICS Environments

Critical infrastructure is entering a new phase of digital transformation as artificial intelligence (AI) moves from analysis to action. The emergence of agentic AI —systems capable of autonomously perceiving, reasoning and executing decisions— represents a step change for industrial control systems (ICS) environments. From power generation and water treatment to manufacturing and transportation, these technologies promise improved efficiency, resilience and operational performance. However, they also introduce an unprecedented cybersecurity challenge: AI as an embedded insider threat.

Unlike traditional cyber risks that originate externally, agentic AI operates within the control environment, directly influencing physical processes, equipment and networks. This shift fundamentally changes the scope of OT cybersecurity, from securing systems against intrusion to governing the behavior, integrity and decision-making of autonomous entities. As autonomy increases, so does the risk of unintended or unsafe actions, particularly in safety-critical ICS environments.

This session explores how agentic AI is reshaping cybersecurity across critical infrastructure. We will examine emerging risk categories, including model drift, hallucinations, training data poisoning, unauthorized or “shadow” agents and cascading impacts across interconnected systems. These risks challenge conventional security architectures and raise new questions around accountability, trust and operational control.

As ICS environments evolve toward greater autonomy, cybersecurity must evolve with them. This session equips attendees with the insights needed to safely harness agentic AI, ensuring that innovation enhances, rather than compromises, the resilience, reliability and safety of critical infrastructure.

Attendees will gain a practical framework for addressing these challenges. Key topics include establishing governance models for AI in OT, enforcing bounded autonomy and least privilege, ensuring human oversight and implementing independent monitoring and safety controls. We will also outline a structured path for adoption, from readiness assessment and use case prioritization to implementation and continuous risk management.

Strategy Track (Great Room 3)
Thu 9:00 AM - 9:30 AM

Why Securing the OT Value Chain Is the Next Critical Challenge for Global Manufacturers

For years, cybersecurity programs have focused primarily on protecting enterprise IT systems and production environments independently. However, modern manufacturing organizations now operate through highly interconnected ecosystems where Information Technology (IT), Operational Technology (OT), cloud platforms, third-party vendors, research and development facilities, distribution centers, and critical infrastructure systems are increasingly converging.

Based on more than 13 years of experience supporting IT, OT and ICS cybersecurity programs across global manufacturing operations, this session introduces the concept of the Secure OT Value Chain and explains why organizations must move beyond traditional site-centric and siloed security approaches.

Join this session lead by an OT Cybersecurity Architect from Esee Lauder for practical lessons learned from:
• Managing cybersecurity risk across manufacturing plants, R&D facilities, distribution centers, and critical infrastructure environments
• Securing third-party vendor and contractor access to critical operational assets
• Implementing secure remote access governance and role-based access control models
• Addressing emerging risks introduced through IT/OT convergence, cloud connectivity, industrial IoT, and digital transformation initiatives
• Building OT asset intelligence and visibility programs to support risk-based decision making
• Strengthening OT vulnerability management and risk prioritization across global operations
• Applying Zero Trust principles within interconnected IT and OT environments
• Developing governance frameworks that align cybersecurity, operations, engineering, supply chain, and business objectives

Tech Track (Great Room 1)
Thu 9:35 AM - 10:05 AM
  • Hazel Cerra Director of Digital Security Convergence - BlackCloak

From Presidential Protection to Digital Executive Protection: Convergence of Physical and Digital

For decades, cybersecurity programs have focused primarily on protecting systems, networks, and infrastructure. But sophisticated adversaries have long understood a different reality: the fastest path to compromise is often through people.

Drawing on more than 25 years as a U.S. Secret Service Special Agent protecting high-risk individuals and investigating cyber-enabled financial crimes, Hazel Cerra will explore how modern attackers identify, study, and exploit human vulnerabilities, particularly those surrounding corporate executives and other high-value targets.

Long before “Zero Trust” became a cybersecurity framework, executive protection teams were already operating with similar assumptions: trust must be continuously evaluated, exposure is constant, and attackers will seek the least protected path to a target.

This session examines how principles traditionally associated with presidential and executive protection, including layered defense, protective intelligence, behavioral risk assessment, advance preparation, and continuous threat evaluation, now directly apply to modern cybersecurity strategy.

Attendees will also learn why cybersecurity, physical security, and executive protection teams can no longer operate independently as attackers increasingly blend digital, physical, and psychological tactics to exploit executive exposure outside the enterprise perimeter.

From this session, attendee will learn:
• How attackers identify and exploit human vulnerabilities
• Why executives represent a growing enterprise attack surface
• How personal digital exposure can escalate into organizational risk
• What CISOs and CSOs can learn from high-risk protective operations
• How organizations can better align cyber, physical, and executive protection strategies in an AI-enabled threat landscape

Rather than focusing solely on technology, this session provides a real-world perspective on how adversaries operate and how security leaders must adapt their defensive mindset to meet a rapidly evolving threat environment.

Strategy Track (Great Room 3)
Thu 9:35 AM - 10:05 AM
  • Glen Combe Fortinet, OT Specialist Systems Engineer - Foritnet

Solutions Theater (Demo): Using the Right Signals to Protect and Manage OT Network Traffic

Despite consensus on attack surface expansion and shared management challenges responding to attacks, there remains high degree of variation in security practices and capabilities, including practices for securing legacy and modern equipment. To protect the critical infrastructure in OT, industrial organizations need to harness the power of segmentation to secure their resources, systems, and users, as well as minimize the risk of attackers gaining access to their critical infrastructure. Join this demonstration to experience how the Fortinet OT Security Platform removes the risks associated with flat network architectures and supports operationalizing NIST, IEC 62443 and other cybersecurity frameworks to secure network traffic.

Focus Track (Strategy Room)
Thu 9:35 AM - 10:05 AM

23 Attacks. 3 Controls. A Decade of OT Breaches and the Pattern Nobody Talks About

Colonial Pipeline. NotPetya. The Oldsmar water treatment hack. Ukraine's power grid blackouts. Triton/TRISIS at a Saudi petrochemical facility. Jaguar Land Rover ransomware. The list of high-profile OT cyberattacks grows every year — and with it, an industry assumption that these incidents require sophisticated adversaries exploiting novel vulnerabilities. That assumption is wrong, and the data proves it.This session presents a structured analysis of 23 major OT cyberattacks drawn from public incident reports, government advisories, forensic analyses, and security research published between 2014 and 2026. The analysis identifies the specific failure mode that enabled each breach. The finding is consistent and, once you see it, impossible to unsee: fewer than two of the 23 attacks involved a genuine zero-day exploit against a core OT system. The vast majority succeeded through one of three failure modes: (1) internet-exposed systems with known CVEs that remained unpatched, (2) stolen, default, or phishable credentials used to gain authorized-looking access, or (3) lateral movement through flat, unsegmented networks that allowed initial access to escalate into plant-wide compromise. The session walks through selected case studies in detail — showing exactly how each failure mode played out in practice, what defenders saw (or didn’t see) at each stage, and how the attack would have been interrupted if the relevant control had been in place. It then addresses the uncomfortable question this analysis raises: if three controls had stopped virtually every major OT breach over the past decade, why are those breaches still happening? The answer has as much to do with organizational decision-making, regulatory timing, and budget cycles as it does with technical capability — and this session addresses all three dimensions.
KEY AUDIENCE TAKEAWAYS
-Review the specific failure modes (exposed systems, stolen credentials, lateral movement) that enabled 23 documented OT breaches — and understand why novel zero-days were rarely the root cause
-Identify which of the three recurring failure modes is most likely to be present in your own environment based on asset profile and architecture
-Understand the organizational and budgetary dynamics that allow known, preventable failure modes to persist in well-resourced OT environments
-Apply the case study framework to communicate breach risk to leadership using documented, real-world outcomes rather than hypothetical threat scenarios
-Leave with a prioritized defensive checklist based on frequency and impact of each failure mode across the 23-breach dataset

Tech Track (Great Room 1)
Thu 10:10 AM - 10:40 AM

Dual-Scope Defense: A Six-Year Municipal IT + OT Engagement and What It Became

By summer 2019, Atlanta was still absorbing a SamSam ransomware attack that cost more than seventeen million dollars to recover from. Baltimore had refused a ransom at a recovery cost of over $18 million. Riviera Beach and Lake City had each paid six-figure ransoms in weeks. More than fifty U.S. local governments had been hit the preceding year. WaterISAC had issued updated cybersecurity fundamentals for water utilities. Illinois had added cybersecurity to its state Compliance Examination program under Public Act 100-914.

The City of Aurora, Il was watching. Illinois's second-largest city operates a water treatment plant, a municipal traffic management network, CJIS-obligated police systems, and administrative IT serving nearly two hundred thousand residents. The question was not whether to stand up full security operations. It was how to do it on the staff and budget of a city, against a threat already stopping municipal services for weeks.
This session walks the audience through what was built in response.

In August 2019, the city engaged a full-spectrum managed security operation covering not only enterprise IT but operational technology, including the water treatment plant and the traffic management network. Dual IT and OT scope inside a single managed engagement was uncommon for municipal deployments of that period, and it is the feature that distinguishes this case. The operation delivered continuous detection and response, vulnerability management, penetration testing, a SIEM platform, threat intelligence, incident response, and a governance-risk-compliance policy layer. A CISO consultant embedded alongside the city's Director of Cyber and Technology Risk, giving the engagement its governance structure in practice.

Across the engagement's six-year arc, August 2019 through December 2025, the operation captured and reported mitigating 35,331 threats across IT and OT, eliminating 351 high-severity threats before they produced incidents, zero major security incidents declared, and annualized cost 77% below an equivalent in-house SOC.

The session examines the three decisions that shaped the engagement.
First, the governance split between city authority and partner operational execution, instantiated by the embedded CISO consultant.
Second, treating water treatment and traffic management as first-class defensive domains rather than extensions of municipal IT.
Third, the cost and staffing structure that delivered dual-scope coverage on a municipal budget envelope.

The session closes on what the model became. The architecture that defended a single city can operate as a shared cybersecurity utility across jurisdictions, governed under intergovernmental agreement and funded through pooled contribution. Small water systems, regional transit authorities, rural electric cooperatives, and tier-2 manufacturers face the same resource architecture Aurora faced in 2019. The pattern translates with the same three decisions.

Strategy Track (Great Room 3)
Thu 10:10 AM - 10:40 AM

Building Cyber Resilient OT Networks with 5G

Critical infrastructure is rapidly connecting mission-critical IoT assets across expansive, remote environments. However, extending OT to the mobile edge dramatically broadens the attack surface, exposing high-value infrastructure to severe cyber and physical threats.

This session presents a practical, architectural blueprint for securing field-deployed with 5G networks, featured alongside an interactive demonstration using the PA-54R-POE-D-5G.

Attendees will observe how physical cabinet access alerts are tied directly into SOC workflows via built-in Digital I/O ports, how real-time device identification immediately isolates unapproved hardware, and how inline edge inspection detects and blocks malware injections before threats can move laterally into critical OT environments.

In this presentation, we will demonstrate:
• How to Eliminate Field Complexity via Edge Convergence: Discover how unifying active/active 5G SD-WAN, full IP routing, PoE switching, and OT-aware NGFW capabilities into a single ruggedized appliance lowers power and space footprints, simplifies maintenance, and enables rapid field deployment via Zero Touch Provisioning (ZTP).
• Methods for Unifying Cyber and Physical Edge Defense: Learn how integrating physical operational telemetry—such as cabinet door tamper sensors using native Digital I/O ports—directly into the security platform enables instant, automated visibility and alerting for the Security Operations Center (SOC).
• Practical Zero Trust Enforcement at the 5G Edge: Explore live mitigation techniques for granular device authorization and inline malware prevention at the field layer, ensuring robust OT asset protection across both air-gapped locations and AI-driven, cloud-connected topologies.

Focus Track (Strategy Room)
Thu 10:10 AM - 10:40 AM

Using AI to Automate Exposure Assessment in OT sites

With the recent launch of Claude Mythos tool, the risk of new vulnerabilities being found in significantly increased. For IT networks that means increased use of exposure assessment tools for rapid deployment of patches for new critical vulnerabilities.
In OT networks such rapid patching is very problematic so alternative compensating methods should be used.
This session explores how Artificial Intelligence can be used to optimize Vulnerability management and Exposure Assessment in OT networks and makes it a practical yet effective task in-line with the operational constraints.
We will examine how AI-driven models can ingest disparate data points - such as asset criticality, network telemetry, and real-time threat intelligence about recent exploits - to provide a context-aware risk score. The AI models will then be used to plan patches to high-risk assets and evaluate the effectiveness of compensating security controls.
Key takeaways will include:
• Contextual Prioritization: How AI identifies which vulnerabilities pose a risk to your specific production environment vs. those that are logically isolated.
• Virtual patching analysis : Using AI to analyze multiple data-sources (research papers, vendor advisories, etc.) for optimizing proposal of patches vs compensating controls as well as using customer feedbacks to tune the future proposals for patches and other compensating controls.
• Automating the "False Positive" Filter: Leveraging Natural Language Processing (NLP) to parse updated information – attack tactics, exploits in the wild, vendor advisories and CVEs, against specific OT configurations.
• Predictive Maintenance vs. Patching: Using AI to align security updates with scheduled downtime, minimizing operational impact.

Tech Track (Great Room 1)
Thu 10:55 AM - 11:25 AM

The Cyber Resilience Act as a Catalyst for OT Cybersecurity Modernization

The EU Cyber Resilience Act (CRA) introduces a major shift in how industrial organizations must design, secure, and maintain Operational Technology (OT) systems. Taking effect in 2026, (vulnerability reporting from September 2026, full applicability from December 2027), the CRA mandates security by design engineering, continuous vulnerability management, and 24-hour reporting of actively exploited vulnerabilities. These requirements drive significant changes to organizational processes, including formalized vulnerability intake, standardized triage workflows, coordinated disclosure procedures, and updated risk reporting policies that align engineering, security, and compliance teams.
For OT environments—where legacy systems, long equipment lifecycles, and limited patching windows have historically constrained security—the CRA acts as both a catalyst and a compliance driver. This session explores the CRA’s strategic impact on industrial cybersecurity/automation solutions and outlines the governance, engineering, and process transformations needed to build a resilient, future ready OT ecosystem.

Strategy Track (Great Room 3)
Thu 10:55 AM - 11:25 AM

Designing Zero-Trust Cross-Domain Identity Architectures for Converged IT/OT Active Directory

Industrial networks have widely adopted Microsoft Active Directory (AD) to manage authentication for Level 2/3 HMIs, Historians, and engineering tools. However, the misconfiguration of trust relationships between enterprise IT domains and industrial OT domains remains the single most common vector for ransomware propagation into critical physical environments. In corporate IT/OT AD trust configurations, we must analyze the structural failure modes that enabled ransomware to cascade into complete operational shutdowns in major historical incidents such as Colonial Pipeline and Norsk Hydro.

This presentation advances beyond generic best practice recommendations by dissecting the structural failure modes inherent in modern IT/OT AD trust configurations. It presents scenarios illustrating how a compromise of the enterprise domain can escalate into full administrative control of the OT domain through mechanisms such as Kerberos delegation abuses, insufficient security identifier (SID) filtering, and trusted domain bypasses. Following such a compromise, attackers may gain control over systems hosting engineering software, enabling them to alter programmable logic controller (PLC) logic or manipulate operator HMIs, thereby posing direct risks to plant safety and operational reliability.

To address these challenges, this presentation introduces a mathematically validated structural framework for Zero-Trust OT Directory Isolation. The proposed model employs directed acyclic graphs (DAGs) to continuously audit authentication path safety and to formally verify the absence of authentication pathways from untrusted corporate assets to Level 2/3 control systems. The implementation of this framework is demonstrated through cryptographically isolated, unidirectional trust relationships utilizing disconnected identity providers, offline Security Assertion Markup Language (SAML) tokens, and rigorously enforced tiering policies.

Target Audience & Sector Focus:

Primary Focus: OT System Administrators, IAM (Identity and Access Management) Architects, and Network Security Engineers.

Target Sectors: Cross-sector (applicable to Oil & Gas, Power Generation, Water Utilities, and general industrial infrastructure).

Tech Track (Great Room 1)
Thu 11:30 AM - 12:00 PM
  • Juan Lopez JR Lead Technical SME, Critical Infrastructure Security & Resilience Research - Oak Ridge National Laboratory

AI-Powered Attacks on ICS SBOMs

Findings, the Limits of De-Identification, and a Call to Action

SBOM sharing is becoming an expectation across critical infrastructure, and for good reason — visibility into third-party and open-source components is the foundation of modern vulnerability management. But the same transparency creates a disclosure surface that did not previously exist. In early 2026 we presented AI-driven re-identification of ICS SBOMs to the Cybersecurity Developmental Test Cross‑Service Working Group (CyberDT XSWG) and Software Assurance communities as an emerging threat. Since then, we have built the attack and run it.

This presentation reports what we found. An AI adversary can attribute an SBOM to its manufacturer with high accuracy from component data alone and can narrow further to a specific firmware build. Partial redaction of the fields carrying that signal does not resolve that threat: leaving even a small fraction of them intact preserves most of the adversary's advantage. In our experiments the attacker was rarely constrained by the data available to them. The binding constraint was the sophistication of their method. Most consequentially, our results speak to the scope of de-identification rather than to its value. De-identification is a necessary control, and in our modeled deployment environment the redaction we applied performed exactly as designed. What we observed is that protecting the document alone does not by itself avert the threat that attackers can successfully discover device locations, link to vulnerabilities, and plan their attacks — because those findings can be obtained along adjacent paths as well. The implication is not that de-identification is ineffective. It is that its coverage must be measured and deliberately extended across the full set of routes available to an adversary if it is to deliver the protection it promises.

This session will present these findings, be explicit about what we have measured on real SBOM corpora versus what we have measured in a modeled environment, and translate the results into practical guidance for manufacturers, integrators, asset owners, and policymakers. We close on the work that still needs to be done, and on the specific ways ICS manufacturers can help make it real.

Strategy Track (Great Room 3)
Thu 11:30 AM - 12:00 PM

When Vulnerability Discovery Outpaces Patching: AI-Assisted Research in ICS Protocol Libraries

The timeline for finding vulnerabilities in C/C++ protocol software is compressing. The timeline for safely remediating them in industrial environments is not.

This session examines that discovery–remediation gap through human-led, AI-assisted vulnerability research in open-source ICS and critical-infrastructure libraries. It draws on 2026 CERT/CC-coordinated disclosures covering 18 CVEs across o6 Automation open62541, MZ Automation libIEC61850, OFFIS DCMTK, and GDCM. The core ICS case studies focus on OPC UA and IEC 61850/MMS software; the DICOM cases are used as adjacent examples of the same supply-chain pattern in safety- and availability-sensitive environments.

The practical issue for asset owners is not that “AI can hack ICS.” It is that AI can accelerate the front end of vulnerability research while the back end remains constrained by vendor triage, safety validation, maintenance windows, incomplete asset inventories, and hidden third-party dependencies inside commercial products, gateways, engineering tools, and test systems.

I will explain the human-led review process behind the findings, including Refute-or-Promote — an adversarial validation workflow that filters candidate findings before disclosure. The methodology is documented in arXiv:2604.19049 and is designed to separate plausible-looking defects from reproducible, operator-relevant vulnerabilities before reports reach vendors, maintainers, or CERTs. That distinction matters in OT: the cost of being wrong is wasted triage, but the cost of being slow is prolonged exposure in environments where patching may depend on safety validation and outage windows.

Attendees will leave with a practical framework for reducing time to understand exposure when patching cannot happen in time: demanding protocol-library coverage in vendor SBOMs, prioritizing compensating controls for protocol-facing attack surfaces, and building faster coordination among researchers, CERTs, vendors, and asset owners.

The session closes with a structured approach for acting on disclosed vulnerabilities when industrial remediation timelines are measured in quarters, not weeks.

Tech Track (Great Room 1)
Thu 12:00 PM - 12:30 PM

From Dwell Time to Dollars: Quantifying the Financial Value of Faster OT Incident Recovery

OT incident response is moving in the wrong direction. The SANS 2025 ICS/OT survey data shows that detection, containment, and recovery timelines are getting longer, not shorter. In an industrial environment, that decline is not just a security problem; it becomes lost production, safety validation, customer impact, and executive scrutiny.

This practical session shows how to turn that problem into a defensible funding case. Using a representative manufacturing facility and the response stages of compromise-to-detection, detection-to-containment, and containment-to-remediation, we will quantify how OT incident response maturity changes expected loss, severe-event exposure, and residual risk.

Risk is delivered as a dollar value, that can be used with leadership to secure real funding to improve OT incident response.

Attendees will see how response-time improvements can be modeled as financial risk reduction, why containment often delivers strong early value, and why trusted recovery still determines resilience. The goal is simple: give ICS/OT practitioners a hands-on example, supporting data, and a reusable technical paper they can take back to leadership to justify improved OT incident response before the next incident proves the need the hard way.

Strategy Track (Great Room 3)
Thu 12:00 PM - 12:30 PM

Preparing Your ICS Forensic Toolkit

Industrial Control System (ICS) and Operational Technology (OT) environments present unique challenges for digital forensics and incident response. Unlike traditional IT systems, these environments prioritize safety, reliability and operations continuity, making intrusive forensic techniques impractical or even dangerous. This presentation provides a practical, vendor-neutral approach to preparing an effective ICS forensic toolkit, focusing on low-risk, non-disruptive methods that enable investigation without compromising critical processes.

This session will guide attendees through the essential tools and concepts required to perform forensic analysis in OT environments. It emphasizes the use of mostly open-source, portable utilities and native operating system capabilities that eliminate the need for installation, reduce system impact and support rapid deployment during incident response. Attendees will gain a clear understanding of how to collect and preserve evidence safely while working within the constraints of live industrial systems.

Key data sources critical to ICS investigations will be explored in depth, including operating system persistence mechanisms, file system artifacts, system and security logs and network packet captures. Each source will be examined in the context of known adversary behaviors within ICS environments, enabling participants to better identify indicators of compromise and suspicious activity. Guidance will also be provided on prioritizing logs and telemetry to build a coherent picture of adversary actions while minimizing alert fatigue.

The presentation will also show strategies for deeper forensic analysis using backups and disk images, allowing investigators to analyze systems that cannot be taken offline. Attendees will understand how to assemble a practical ICS forensic toolkit, both hardware and software, and how to use it to incrementally reconstruct adversary activity. This foundation enables more informed decision-making and supports the development of effective, context-aware response strategies.

Tech Track (Great Room 1)
Thu 1:45 PM - 2:15 PM

Joint Industry Project - OT Cybersecurity for Offshore Wind

Last year, we launched a Joint Industry Project to develop a practical “how-to” guide for implementing IEC 62443 in the offshore wind sector. The initiative brings together key industry stakeholders to collaboratively address cybersecurity challenges specific to offshore wind.

The work is structured across dedicated workstreams covering areas such as network architecture, cybersecurity governance, supply chain security, and related topics. This talk will provide an overview of the work as it has evolved—focusing on the journey, key decisions, and how the collaboration has taken shape in practice.

The project began in September 2024 with the recruitment of industry participants and the establishment of a collaborative framework. An early milestone was our first in-person workshop in Paris, where we revisited and adapted a delivery model previously used in the oil and gas sector. Rather than immediately addressing technical challenges, we chose to step back and build a shared understanding of the offshore wind lifecycle. This allowed us to redefine both the scope and structure of the final deliverable.

With that foundation in place, we progressed into the core workstreams, working collectively to shape the content of the guide.

This presentation is intended to take place towards the later stages of the project, ahead of the planned release of the document in early 2027. It will reflect on the journey from September 2024 through to October 2026—what has been developed, what we have learned, and what remains ahead.

Strategy Track (Great Room 3)
Thu 1:45 PM - 2:15 PM
  • Keon McEwen Head of Solutions Development, Global Industrial Cybersecurity - Black & Veatch

Operational Data Meshing for Critical Infrastructure: Advancing OT Detection and Response in ICS Env

Industrial control system (ICS) environments support critical infrastructure sectors, from power generation and water systems to oil and gas, transportation and manufacturing. As these systems become increasingly connected and data-driven, traditional approaches to OT cybersecurity monitoring—primarily focused on network traffic analysis—are no longer sufficient. While network visibility remains essential, it provides only a partial view of system behavior and often lacks the operational context required to accurately detect and respond to evolving threats.

In reality, critical infrastructure operators generate vast amounts of operational data across their environments, including sensor readings, control system logs, maintenance records, engineering changes and physical security inputs. Yet much of this data remains siloed, underutilized, or disconnected from cybersecurity workflows. Operational data meshing introduces a new model: integrating cyber, operational and contextual data sources to create a unified, intelligence-driven view of risk.

This session explores how data meshing reshapes detection and response in ICS environments. By correlating network activity with process conditions and equipment behavior, organizations can more accurately distinguish between cyber incidents and normal operational anomalies, validate alerts across multiple data sources and uncover attack techniques that would otherwise remain undetected. This approach enhances visibility, reduces time-to-detection and response and improves decision-making during incident handling.

The discussion will explore the benefits of data meshing implementation across critical infrastructure environments, leveraging existing data assets, adopting an intelligence-led approach and evolving from a traditional security operations center (SOC) to a broader operational intelligence capability.

Attendees will leave with a clear understanding of how to move beyond isolated monitoring tools toward a more adaptive, context-rich cybersecurity model, one that strengthens resilience, supports operational continuity and enables more proactive and predictive defense across modern ICS environments.

Strategy Track (Great Room 3)
Thu 2:20 PM - 2:50 PM
  • Dylan Hinz Associate Principal Cyber Analyst, Darktrace - Darktrace

How Cloud Expansion and AI‑Driven Threats Are Reshaping Cyber Risk in the U.S. Energy Sector

The U.S. energy sector is rapidly adopting cloud services, IoT technologies, and integrated IT/OT architectures. Changes that have significantly widened the attack surface. Recent research shows a sharp increase in cloud‑borne intrusions, identity compromise, exploitation of internet‑exposed assets, and phishing campaigns that frequently target high‑value individuals within energy organizations. These pressures are compounded by over‑reliance on a small number of critical vendors and unmanaged assets throughout the supply chain, creating dependencies that attackers increasingly exploit.

At the same time, U.S. critical infrastructure continues to attract interest from both financially motivated groups and nation‑state actors conducting reconnaissance and positioning for future disruption. This includes early‑stage activity that blends cloud identity misuse, low‑signal lateral movement, and OT‑adjacent probing that may not register on traditional tools.

This talk provides a focused look at how these attack patterns are evolving and how detection strategies must adapt. Based on analysis of North American energy sector incident trends based on Darktrace telemetry, the session will break down the behaviors most indicative of early‑stage compromise, outline key telemetry required for high‑fidelity detection in cloud‑enabled environments, and provide practical guidance for identifying subtle attacks before they impact reliability or operations.

Tech Track (Great Room 1)
Thu 2:55 PM - 3:25 PM