Event Agenda

23rd – 24th September 2026 // London, UK

Register Now

Building Intelligence-Driven IT/ OT Resilience in an Era of Increasing Risk

Track A: Strategies For Overcoming The Biggest Cyber Issues of Today
Track B: Proactive Roadmaps for Overcoming Common OT Challenges

Day 2 // 24th September 2026
08:15 – 05:30 (BST)
08:15Registration & Coffee
08:50Chairman’s Opening Address by Thomas Mortsell, CSO, Aneo
09:00
.

  • How is cyber threat intelligence different in OT compared to IT or is it just applied differently in practice?
  • Where do traditional IT threat intelligence approaches fail when applied to OT environments?
  • How does IT-OT convergence influence the need for a holistic approach between the two? Should this be the case?
  • What makes threat intelligence truly actionable in OT where safety and uptime are critical?
  • How should organisations balance integration versus separation of IT and OT threat intelligence strategies?.

Alfonso José Álvarez Calderón , Global IT/OT Lead & CIO, Exolum
Paul Mackie, Group CISO, Fern Trading Limited
Sarah Hadfield, Head of Energy System Risk, National Energy System Operator
Damien Ploix, Head of Infrastructure and Cybersecurity Services, Endis
Alex Fold, OT Cybersecurity Specialist, Fortinet
.

9:40

  • How we built a framework of continuous monitoring for real-time anomaly detection and rapid incident response
  • How we leveraged automation to neutralise threats before they could disrupt critical OT operations
  • Where we applied zero trust principles to control access, verify identities, and contain risks proactively
  • How we utilised strengthened collaboration between IT and OT teams to ensure unified visibility, faster decision-making, and sustained resilience

Jonathan Sinclair, Head of Cyber Security for Pharma Technical Operations (PT), Roche
.

10:10

Industrial environments are being asked to meet modern security expectations while relying on legacy control systems that were never designed for today’s threat landscape. This session will focus on practical, high-impact controls that can be introduced without disrupting safety, availability or production. We will look at where to start, including visibility, network segmentation, identity, monitoring, incident preparedness and response. We will also explore how security operations can support OT environments around the clock, combining specialist expertise with managed detection and response. The emphasis will be on realistic steps organisations can take now to reduce risk and build resilience safely over time.
.
Jon Cranton, Security Specialist, Quorum Cyber
.
10:40Break & Networking – Breakfast Hosted by Cyro Cyber (Invite-Only)
TRACK A
Developing Comprehensive Business Cases for OT Cyber
Chaired by Thomas Mortsell, CSO, Aneo
11:20

.
Hacktivism is increasingly merging with cybercriminal and state interests, expanding beyond defacements and DDoS to more advanced operations, including attacks on critical infrastructure. Understanding the current tactics, techniques and procedures of the most relevant hacktivist groups provides insight into the modern threat landscape. In this talk, we will review some of the most relevant groups, alliances and attacks we have followed to distill lessons learned, including the need to eliminate default credentials, segment OT networks rigorously, and deploy deep-packet inspection for threat detection.
.
Daniel dos Santos, Vice President of Research, Forescout
.
11:50

  • How best to build a framework of continuous monitoring for real-time anomaly detection and rapid incident response
  • How you can leverage automation to neutralise threats before they could disrupt critical OT operations
  • Where Zero-Trust principles can be applied to control access, verify identities, and contain risks proactively
  • How strengthened collaboration between IT and OT teams can ensure unified visibility, faster decision-making, and sustained resilience

Matilda Rhode, Head, Security Operations, Dŵr Cymru Welsh Water
.

12:20

Cyber resilience is no longer just about preventing breaches or recovering after an incident. The board-level question is: Can the organisation keep its critical business services operating within agreed risk and impact tolerances while an attack is actively underway? The Minimum Viable Digital Enterprise (MVDE) provides a practical model for answering this question. The session explores how organisations can move from recovery-centric resilience to operational survivability- designing the enterprise to survive an active breach, not simply recover from one.
.
Adrian Young, Regional Vice President – EMEA, Color Tokens
.
12:30

Traditional security methods like perimeter walls and binary access choices fail to protect operational technology (OT) from supply-chain risks, with vendor remote access posing a significant threat to production systems. This session outlines a practical framework to move from broad network access to least-privilege, identity-based connectivity, allowing teams to limit the blast radius of potential breaches.
.
Adam Gurney, Sr. Solutions Engineer, Cyolo
.
TRACK B
Strategies for Building Holistic Cyber Defence
Chaired by Nuno Teodoro, Global Cybersecurity Director, Hovione
11:20

.
Operational technology (OT) security requires more than segmentation and monitoring. Effective cyber defence combines asset visibility, network awareness, policy enforcement, threat detection, and resilient operations. Zero Trust is increasingly viewed as a target state for OT security, but many organisations struggle to move beyond theory. This session explores how OT SDN supports a holistic defence strategy through deny-by-default communications, simplified network monitoring, deterministic traffic control, and alignment with Zero Trust and IEC 62443 principles.
.
Sagar Dayabhai, Principal Engineer, Schweitzer Engineering Laboratories
.
11:50

  • How we established meaningful, quantifiable risk metrics across complex OT environments
  • How we translated technical OT vulnerabilities into business-relevant risk scores and insights
  • The key actions we utilised to create measurable OT risk management metrics we can present to board-level executives

Emyr Thomas, Head of Cyber Futures, National Highways
.

12:20

This session explores how critical infrastructure operators can strengthen their OT cyber security posture against an evolving landscape of threats. Through proven defence frameworks, advanced monitoring approaches, and real-world case examples, attendees will gain insights into how to safeguard critical operations while maintaining productivity. The discussion will also highlight the importance of vendor–operator collaboration in building long-term resilience, offering practical guidance for both technical teams and decision-maker.
.
12:30

OT security has focused on protecting industrial systems from cyber threats. Yet the most resilient organisations are discovering that security controls alone cannot adequately protect critical operations. The future lies in Cyber-Informed Engineering (CIE): an approach that assumes cyber compromise is inevitable and focuses on engineering systems that can continue operating safely, reliably, and recover quickly when attacks occur. The key message is: We cannot patch our way to operational resilience. We must engineer resilience into industrial systems from the start.
.
Amer Kayyal, Principal OT Security Consultant, NCC Group
.
13:00Lunch hosted by Quorum Cyber
TRACK A
Developing Effective Outlooks for OT Governance
Chaired by Thomas Mortsell, CSO, Aneo

14:00

  • Are regulations like NIS2 improving real OT security outcomes or just adding compliance burden taking away time from key issues?
  • Is inconsistent implementation and regulations across Europe weakening a unified OT security baseline?
  • Are current regulations realistic for legacy OT environments and operational constraints?
  • What should OT Security regulation look like?

Moderator: Nuno Teodoro, Global Cybersecurity Director, Hovione
Marta Majtenyi, Director of Information Security Office, Norsk Hydro
Paul Mackie, Group CISO, Fern Trading Limited

14:40
.

  • How we overcame governance challenges through our IT-OT Convergence
  • How establishing a joint IT-OT Security Operations Center (SOC) has helped us to centralise monitoring and response
  •  How we overcame cultural differences between IT-OT professionals

.
Kevin White, Head of Cyber Security, SSE PLC
.

TRACK B
Tackling The Issues of Tomorrow, Today
Chaired by Nuno Teodoro, Global Cybersecurity Director, Hovione

14:00
.

  • What are the fundamentals of quantum computing that organisations need to understand today?
  • Where are AI and quantum computing being practically applied right now?
  • How are AI and quantum computing expected to impact cyber security?
  • What key takeaways and actions should organisations be considering today to prepare for the risks of tomorrow?

Moderator: Emyr Thomas, Head of Cyber Futures, National Highways
Trish McGill, Sr. SME Cyber Security – Deputy CISO, De Heus Voeders B.V.
David Souto, CISO, Exolum
Matt White, Cyber Advisory and App Security Director, Royal Mail
.

14:40
.

  • How we utilised AI to stay one step ahead of new AI threats in light of increasing use of ransomware-as-a-service and geopolitical threats
  • How we operationalised AI across our OT environments to improve detection, response, and resilience
  • A deep-dive into how we adapted technically through a holistic new strategy

Claudio Sangaletti, Corporate Head of Infrastructure & Communication, PERSÁN
.


15:10Break & Networking
Developing Effective Outlooks for OT Governance
Chaired by Thomas Mortsell, CSO, Aneo
15:40

  • Are we overemphasising human behaviour in cyber security at the expense of technical and systemic controls?
  • Should IT systems be designed to be resilient to human error rather than relying on users as the first line of defence?
  • What lessons can we learn from different sectors in balancing human and technical security? How can we ensure we are getting the basics right?

Moderator: Nish Sukumaran, Vice-President, Information Security, Worley
Marta Majtenyi, Director of Information Security Office, Norsk Hydro
Ramon Serres, CISO, Almirall
Vikram Jeet, Senior OT Security Architect, Thames Water
David Souto, CISO, Exolum
.

16:20
.
T1: Building a Culture of Security Throughout Our Enterprise
Paul Holland, Cyber Capability Manager, Royal Mail
.
T2: Developing Quantifiable Narratives for Board Level Buy-In
Adam Paturej, Cyber Security Director, International Centre for Chemical Safety and Security (ICCSS)
.
T3: How Can We Build the Next Generation of Cyber Experts?
Thomas Mortsell, CSO, Aneo.
.
17:00Closing Remarks by Thomas Mortsell, CSO, Aneo
17:05End of Conference

Join the Line-Up

Submit a Proposal

Request a Sponsor Pack

Submit Here

Register Now

Choose Your Pass