Event Agenda
23rd – 24th September 2026 // London, UK
23rd – 24th September 2026 // London, UK
Track A: Strategies For Overcoming The Biggest Cyber Issues of Today
Track B: Proactive Roadmaps for Overcoming Common OT Challenges
| Day 2 // 24th September 2026 08:15 – 05:30 (BST) | |
| 08:15Registration & Coffee | |
| 08:50Chairman’s Opening Address by Thomas Mortsell, CSO, Aneo | |
| 09:00 .
– Alfonso José Álvarez Calderón , Global IT/OT Lead & CIO, Exolum | |
9:40
– Jonathan Sinclair, Head of Cyber Security for Pharma Technical Operations (PT), Roche | |
| 10:10 Industrial environments are being asked to meet modern security expectations while relying on legacy control systems that were never designed for today’s threat landscape. This session will focus on practical, high-impact controls that can be introduced without disrupting safety, availability or production. We will look at where to start, including visibility, network segmentation, identity, monitoring, incident preparedness and response. We will also explore how security operations can support OT environments around the clock, combining specialist expertise with managed detection and response. The emphasis will be on realistic steps organisations can take now to reduce risk and build resilience safely over time. . – Jon Cranton, Security Specialist, Quorum Cyber . | |
| 10:40Break & Networking – Breakfast Hosted by Cyro Cyber (Invite-Only) | |
| TRACK A Developing Comprehensive Business Cases for OT Cyber Chaired by Thomas Mortsell, CSO, Aneo | |
| 11:20 . Hacktivism is increasingly merging with cybercriminal and state interests, expanding beyond defacements and DDoS to more advanced operations, including attacks on critical infrastructure. Understanding the current tactics, techniques and procedures of the most relevant hacktivist groups provides insight into the modern threat landscape. In this talk, we will review some of the most relevant groups, alliances and attacks we have followed to distill lessons learned, including the need to eliminate default credentials, segment OT networks rigorously, and deploy deep-packet inspection for threat detection. . – Daniel dos Santos, Vice President of Research, Forescout . | |
11:50
– Matilda Rhode, Head, Security Operations, Dŵr Cymru Welsh Water | |
| 12:20 Cyber resilience is no longer just about preventing breaches or recovering after an incident. The board-level question is: Can the organisation keep its critical business services operating within agreed risk and impact tolerances while an attack is actively underway? The Minimum Viable Digital Enterprise (MVDE) provides a practical model for answering this question. The session explores how organisations can move from recovery-centric resilience to operational survivability- designing the enterprise to survive an active breach, not simply recover from one. . – Adrian Young, Regional Vice President – EMEA, Color Tokens . | |
| 12:30 Traditional security methods like perimeter walls and binary access choices fail to protect operational technology (OT) from supply-chain risks, with vendor remote access posing a significant threat to production systems. This session outlines a practical framework to move from broad network access to least-privilege, identity-based connectivity, allowing teams to limit the blast radius of potential breaches. . – Adam Gurney, Sr. Solutions Engineer, Cyolo . | |
| TRACK B Strategies for Building Holistic Cyber Defence Chaired by Nuno Teodoro, Global Cybersecurity Director, Hovione | |
| 11:20 . Operational technology (OT) security requires more than segmentation and monitoring. Effective cyber defence combines asset visibility, network awareness, policy enforcement, threat detection, and resilient operations. Zero Trust is increasingly viewed as a target state for OT security, but many organisations struggle to move beyond theory. This session explores how OT SDN supports a holistic defence strategy through deny-by-default communications, simplified network monitoring, deterministic traffic control, and alignment with Zero Trust and IEC 62443 principles. . – Sagar Dayabhai, Principal Engineer, Schweitzer Engineering Laboratories . | |
11:50
– Emyr Thomas, Head of Cyber Futures, National Highways | |
| 12:20 This session explores how critical infrastructure operators can strengthen their OT cyber security posture against an evolving landscape of threats. Through proven defence frameworks, advanced monitoring approaches, and real-world case examples, attendees will gain insights into how to safeguard critical operations while maintaining productivity. The discussion will also highlight the importance of vendor–operator collaboration in building long-term resilience, offering practical guidance for both technical teams and decision-maker. . | |
| 12:30 OT security has focused on protecting industrial systems from cyber threats. Yet the most resilient organisations are discovering that security controls alone cannot adequately protect critical operations. The future lies in Cyber-Informed Engineering (CIE): an approach that assumes cyber compromise is inevitable and focuses on engineering systems that can continue operating safely, reliably, and recover quickly when attacks occur. The key message is: We cannot patch our way to operational resilience. We must engineer resilience into industrial systems from the start. . – Amer Kayyal, Principal OT Security Consultant, NCC Group . | |
| – | |
| 13:00Lunch hosted by Quorum Cyber | |
| TRACK A Developing Effective Outlooks for OT Governance Chaired by Thomas Mortsell, CSO, Aneo | |
14:00
– Moderator: Nuno Teodoro, Global Cybersecurity Director, Hovione | |
| 14:40 .
. | |
| TRACK B Tackling The Issues of Tomorrow, Today Chaired by Nuno Teodoro, Global Cybersecurity Director, Hovione | |
| 14:00 .
– Moderator: Emyr Thomas, Head of Cyber Futures, National Highways | |
| 14:40 .
– Claudio Sangaletti, Corporate Head of Infrastructure & Communication, PERSÁN | |
| – | |
| 15:10Break & Networking | |
| Developing Effective Outlooks for OT Governance Chaired by Thomas Mortsell, CSO, Aneo | |
15:40
– Moderator: Nish Sukumaran, Vice-President, Information Security, Worley | |
| 16:20 . T1: Building a Culture of Security Throughout Our Enterprise – Paul Holland, Cyber Capability Manager, Royal Mail . T2: Developing Quantifiable Narratives for Board Level Buy-In – Adam Paturej, Cyber Security Director, International Centre for Chemical Safety and Security (ICCSS) . T3: How Can We Build the Next Generation of Cyber Experts? – Thomas Mortsell, CSO, Aneo. . | |
| 17:00Closing Remarks by Thomas Mortsell, CSO, Aneo | |
| 17:05End of Conference | |