Cyber threats are driving the need for robust resilience strategies. This talk introduces the concept of Cyber Conservative Operations, a proactive approach to manage risk and maintain resilience in the face of imminent, but not yet occurring, cyber events. Leveraging Cyber-Informed Engineering (CIE), with the practice of conservative operations, this approach for planning and deploying…
As cyber threats targeting Operational Technology accelerate, utilities must adopt deeper visibility into their OT environments to detect anomalous behavior, strengthen defenses, and support operational reliability. Journey to OT Visibility explores how modern monitoring capabilities—such as passive network analysis, behavioral analytics, and protocol‑aware inspection—provide the real‑time situational awareness needed to counter advanced adversaries. The session…
A Cold War handshake that compromised global cryptography – and a modern reminder that in connected systems, unverified trust is the most dangerous vulnerability of all. Through the lens of the Friedman–Hagelin cryptographic agreement, this talk explores how a secret handshake led to decades of compromised encryption, and what Cold War deception can teach today’s…
AbstractAcross critical industries, cyber threats are escalating in scale and sophistication, leveraging advanced intrusion and lateral movement techniques to disrupt core operations. As these attacks target critical industries, such as energy, manufacturing and healthcare, the impact extends beyond IT downtime to degraded OT. In this context, traditional perimeter-based defenses and OT security methodologies are no…
Derek and Patrick close out Day 1 sessions with an introduction to Beer ISAC
In this session, we’ll pull back the curtain on our 2025 audit. We’ll walk through the specific strategies we used to organize our initial evidence submittals to minimize downstream friction and how we managed the weeks of RFI’s (Request for Information) leading up to the off-site/on-site. Passing a NERC audit is rarely about the audit…
OT Security is still a young discipline that’s evolving. While everyone understands that OT is different from IT, the OT Security responsibilities are driven by or inherited from IT Security. Therefore the purpose-built products for OT Security try to meet IT Security’s expectations while avoiding a conflict with operations or causing downtime. E.g., a vulnerability…
NEW DoD Cyber Work Role “Control Systems Security Specialist.“ Responsible for device, equipment, and system-level cybersecurity configuration and day-to-day security operations of control systems, including security monitoring and maintenance along with stakeholder coordination to ensure the system and its interconnections are secure in support of mission operations. How many are needed in operational testing? How…