SEC536: Adversarial AI - Penetration Testing AI Systems

The session opens the summit by connecting industrial defenders to a unified framework for threat understanding. It explores how the MITRE ATT&CK for ICS matrix can be transformed from documentation into a daily defensive tool. Attendees will walk through mapping attacker behaviours to real network telemetry, building detections around them, and shaping incident response plans that align to ATT&CK techniques. The session focuses on translating theory into practice, enabling teams to identify, classify, and respond to adversaries with greater precision and speed.
Kai Thomsen, Director of Global Incident Response Services - Dragos Inc
Industrial networks demand visibility that doesn’t interrupt operations. The session focuses on passive monitoring approaches that provide deep insight into control system traffic while maintaining safety. Delegates will learn the technical fundamentals of parsing common ICS protocols (Modbus, DNP3, S7Comm, and CIP), developing traffic baselines, and distinguishing normal process changes from true indicators of compromise. Using real examples, the session demonstrates how anomaly detection enhances situational awareness and supports faster, safer incident response in operational environments.
Michael Hoffman, Field CTO, Oil & Gas – Dragos Inc
Tim Conway, Technical Director of ICS & SCADA Programs – SANS Institute
Every asset owner believes their environment is unique: their plants, their constraints, their threats. After running OT security programs across hundreds of clients, thousands of sites, dozens of countries and every critical-infrastructure sector, I've reached an uncomfortable conclusion: they're nearly identical where it counts. The differences are the surface. The patterns underneath are the structure, and most of them are invisible from inside a single engagement. This session shares what only becomes visible from altitude: the universal truths about how the industry measures the wrong things, buys the wrong capabilities, and overlooks the same scope, every time. We'll trace why maturity is a vanity metric, why the AI era widens OT's exposure precisely where it hurts most, and why the job of cyber has quietly changed: from managing risk to creating operational resilience. You'll leave knowing which of your "unique" problems are actually everyone’s, and what to do about them.
Samuel Linares, Global OT Cybersecurity Lead - Accenture
In April 2026, CISA and federal partners published the first joint guidance explicitly adapting zero trust to OT, organised around six functions – Govern, Identify, Protect, Detect, Respond, Recover – and aligned to NIST CSF 2.0, the CISA Zero Trust Maturity Model, NIST SP 800-82 Rev.3 and IEC 62443. Crucially, the guide itself concedes that IT-centric zero trust cannot be applied wholesale to OT: availability imperatives, decades-long asset lifecycles and legacy protocols with no concept of identity all demand adaptation. This session walks through each of the six functions, shows where current OT security architectures already deliver the intended outcome, and – just as importantly – is candid about where the guidance runs into real operational limits: continuous re-authentication on a serial RTU, identity-based policy on Modbus/TCP, or re-architecting a 25-year-old DCS. Two real-world, phased zero trust adoption examples close the session.
Daniel Buhmann, Senior Consulting Systems Engineer - Fortinet
Many organisations invest significant effort in creating a network zoning plan, defining zones and conduits, and documenting an access matrix. At that point, it can feel as if the segmentation work is finished. But in reality, this is where the real challenge starts. Assets are added, moved or removed. Vendors request remote access. Temporary exceptions appear. Legacy systems remain in place. Engineers need practical solutions. Business processes change. Over time, small unmanaged decisions can slowly break the intended zoning model. This session explains what needs to happen after the network segmentation design is ready. It focuses on how to embed segmentation into daily operations through governance, change management, risk-based access decisions, verification, monitoring, exception handling and continuous improvement. The session also links these operational practices to expectations from NIS2 and IEC 62443, showing how segmentation becomes more than a technical architecture: it becomes a managed cybersecurity control that must be governed, tested, evidenced and maintained.
Dieter Sarrazyn, Industrial Security Advisor & Founder - Secudea
Cybersecurity decisions in operational technology have real-world consequences for safety, reliability, and operational continuity. As IT and OT environments become increasingly connected, security engineers and practitioners must balance cyber risk with the realities of industrial operations. Drawing on real-world experience, Saltanat Mashirova explores practical approaches to cyber-physical risk assessment, identifying critical assets, prioritising security controls, and applying frameworks such as ISA/IEC 62443 to support informed decision-making. Join us to gain actionable guidance for assessing risk, communicating priorities, and making security decisions that strengthen resilience without disrupting operations.
Saltanat Mashirova, Global Cybersecurity Services Product Manager - Eaton
Brad Wilkerson, Director, Decision Science Products – The Walt Disney Company
Tim Conway, Technical Director of ICS & SCADA Programs – SANS Institute