SEC536: Adversarial AI - Penetration Testing AI Systems

Experienced practitioners
This practical workshop focuses on building resilient disaster recovery (DR) plans in Operational Technology (OT) environments through hands-on, scenario-based learning. Participants will be guided through a simulated plant-level outage, where they will assess outages, identify system dependencies, and develop recovery strategies. The workshop emphasises the engineering responsibilities involved in DR, including defining escalation pathways, validating recovery actions, and creating actionable, site-specific DR plans. Targeted at OT professionals, engineers, and security practitioners, the session is designed to provide a structured framework for developing DR strategies. By the end of the workshop, attendees will gain the skills to create effective DR strategies tailored to their organisation’s needs, ensuring a resilient recovery of OT systems and processes.
Saltanat Mashirova, Global Cybersecurity Services Product Manager - Eaton
The session opens the workshop by connecting industrial defenders to a common framework for understanding and acting on cyber threats. It explores how MITRE ATT&CK for ICS can be transformed from a reference framework into a practical tool for assessments, security design, detection and incident response.
Using a realistic industrial scenario, delegates will map adversary behaviours and attack paths to relevant ATT&CK techniques and examine how these can be translated into defensive objectives. Where appropriate, MITRE D3FEND will be used to connect attacker behaviour with potential defensive techniques. Participants will explore how identified threats can drive practical hardening measures, security requirements and detection opportunities. The workshop will also introduce the role of security verification during FAT and SAT: If a defensive measure has been designed or implemented to address a particular threat, how can we demonstrate that it actually works before the system enters operation? Selected examples will connect ATT&CK techniques to controls, FAT/SAT security tests, network or system telemetry and incident-response actions. You will leave with a practical methodology for moving from threat behaviour to defensive action, using ATT&CK as a common language across assessment, hardening, verification, monitoring and response.
Dieter Sarrazyn, Industrial Security Advisor & Founder - Secudea
In-Person
New to ICS/OT cybersecurity & practitioners
ICS network visibility is one of the Five ICS Cybersecurity Critical Controls and a foundation for effective incident response. This live demonstration workshop shows how ICS/OT Network Visibility supports:
Using live demonstrations and real-world ICS traffic, attendees will see how visibility improves detection, investigation to protect ICS/OT environments. Designed for engineers, operators, IT/OT security practitioners, and leaders.
Dean Parsons, SANS Principal Instructor & CEO - ICS Defense Force
Hardening industrial environments requires a careful balance between cybersecurity, operational requirements, vendor constraints and system availability. This workshop provides a practical introduction to systematically reducing the attack surface of industrial control systems while understanding the operational consequences that security changes may introduce. Attendees will work through the hardening process from preparation and backup through host, network, account and policy-level security. Using realistic industrial examples, the workshop examines common hardening opportunities across Windows-based HMIs and servers, Linux systems, network components and industrial control devices. Particular attention will be given to the practical challenges of applying generic security recommendations within operational environments, where unsupported changes or overly restrictive configurations can affect availability or process functionality.
The session will connect hardening decisions to IEC 62443 principles and threat-informed security, demonstrating how identified attack vectors and MITRE ATT&CK techniques can help prioritise which controls matter most rather than applying hardening settings as an undifferentiated checklist.
Participants will then consider how selected hardening requirements can be transformed into verifiable security tests during FAT and SAT. Practical examples will demonstrate how to confirm that unnecessary services have been disabled, communication paths are appropriately restricted, accounts and privileges are correctly configured and required security policies remain effective in the deployed environment. Through guided exercises, attendees will learn how to establish a repeatable hardening approach and how configuration, validation and monitoring can work together throughout the industrial system lifecycle.
Dieter Sarrazyn, Industrial Security Advisor & Founder - Secudea
In-Person
Tim Conway, Technical Director of ICS & SCADA Programs – SANS Institute
Every asset owner believes their environment is unique: their plants, their constraints, their threats. After running OT security programs across hundreds of clients, thousands of sites, dozens of countries and every critical-infrastructure sector, I've reached an uncomfortable conclusion: they're nearly identical where it counts. The differences are the surface. The patterns underneath are the structure, and most of them are invisible from inside a single engagement. This session shares what only becomes visible from altitude: the universal truths about how the industry measures the wrong things, buys the wrong capabilities, and overlooks the same scope, every time. We'll trace why maturity is a vanity metric, why the AI era widens OT's exposure precisely where it hurts most, and why the job of cyber has quietly changed: from managing risk to creating operational resilience. You'll leave knowing which of your "unique" problems are actually everyone’s, and what to do about them.
Samuel Linares, Global OT Cybersecurity Lead - Accenture
In April 2026, CISA and federal partners published the first joint guidance explicitly adapting zero trust to OT, organised around six functions – Govern, Identify, Protect, Detect, Respond, Recover – and aligned to NIST CSF 2.0, the CISA Zero Trust Maturity Model, NIST SP 800-82 Rev.3 and IEC 62443. Crucially, the guide itself concedes that IT-centric zero trust cannot be applied wholesale to OT: availability imperatives, decades-long asset lifecycles and legacy protocols with no concept of identity all demand adaptation. This session walks through each of the six functions, shows where current OT security architectures already deliver the intended outcome, and – just as importantly – is candid about where the guidance runs into real operational limits: continuous re-authentication on a serial RTU, identity-based policy on Modbus/TCP, or re-architecting a 25-year-old DCS. Two real-world, phased zero trust adoption examples close the session.
Daniel Buhmann, Senior Consulting Systems Engineer - Fortinet
Many organisations invest significant effort in creating a network zoning plan, defining zones and conduits, and documenting an access matrix. At that point, it can feel as if the segmentation work is finished. But in reality, this is where the real challenge starts. Assets are added, moved or removed. Vendors request remote access. Temporary exceptions appear. Legacy systems remain in place. Engineers need practical solutions. Business processes change. Over time, small unmanaged decisions can slowly break the intended zoning model. This session explains what needs to happen after the network segmentation design is ready. It focuses on how to embed segmentation into daily operations through governance, change management, risk-based access decisions, verification, monitoring, exception handling and continuous improvement. The session also links these operational practices to expectations from NIS2 and IEC 62443, showing how segmentation becomes more than a technical architecture: it becomes a managed cybersecurity control that must be governed, tested, evidenced and maintained.
Dieter Sarrazyn, Industrial Security Advisor & Founder - Secudea
Cybersecurity decisions in operational technology have real-world consequences for safety, reliability, and operational continuity. As IT and OT environments become increasingly connected, security engineers and practitioners must balance cyber risk with the realities of industrial operations. Drawing on real-world experience, Saltanat Mashirova explores practical approaches to cyber-physical risk assessment, identifying critical assets, prioritising security controls, and applying frameworks such as ISA/IEC 62443 to support informed decision-making. Join us to gain actionable guidance for assessing risk, communicating priorities, and making security decisions that strengthen resilience without disrupting operations.
Saltanat Mashirova, Global Cybersecurity Services Product Manager - Eaton
As cyber threats against critical infrastructure continue to evolve, the energy sector remains a key target for increasingly sophisticated attacks. In this session, CERT Polska will present updated findings from its investigation into recent attacks on Poland's energy sector, sharing the latest technical insights, lessons for securing Industrial Control Systems and Operational Technology, and the critical role of timely information sharing in strengthening cyber resilience across the critical infrastructure community.
Radoslaw Dumanski, Chief Information Security Officer - Polish Power Grid
Sylwia Kornaczewicz-Pieczoro - Polish Power Grid
Building resilience in an OT environment requires more than a recovery plan. Legacy systems, undocumented configurations, vendor dependencies and physical processes make business continuity and disaster recovery uniquely challenging. Testing and exercising continuity and recovery plans without disrupting live environments is one of the toughest aspects of building genuine OT resilience. Tobias Kiesling explores how organisations can prepare for, respond to and recover from an OT cyber incident while maintaining the safety and continuity of critical operations. He will examine how to determine what can be trusted, restore and validate essential systems, and decide when operations are safe to restart.
Tobias Kiesling, Head of Cyber Technical Office - Airbus
In-Person
Brad Wilkerson, Director, Decision Science Products – The Walt Disney Company
Tim Conway, Technical Director of ICS & SCADA Programs – SANS Institute