Event Agenda

23rd – 24th September 2026 // London, UK

Register Now

Building Intelligence-Driven IT/ OT Resilience in an Era of Increasing Risk

Track A: Strategies For Overcoming The Biggest Cyber Issues of Today
Track B: Proactive Roadmaps for Overcoming Common OT Challenges

Day 1 // 23rd September 2026
08:15 – 05:30 (BST)
08:00Registration & Coffee
08:35Chairman’s Opening Address by Thomas Mortsell, CSO, Aneo
08:45 Keynote Address given by Senior NCSC Representative
09:00

What should be our first steps in the scenario of a cyber attack impacting our OT systems? What should be our priorities in both protection and response?
How can we best prevent panic in such a scenario? What can we do to ensure that downtime is limited and that impact is minimised?
How can we best communicate with our boards in the event of an attack?
What strategies should we have prepared for a disaster? How can threat hunting support in the event of an incident?
What can we do so we are best prepared to respond to a cyber attack?
.
Moderator: Claudio Sangaletti, Corporate Head of Infrastructure & Communication, PERSÁN
Thomas Mortsell, CSO, Aneo
Trish McGill, Sr. SME Cyber Security – Deputy CISO, De Heus Voeders B.V
Adam Paturej, Cyber Security Director, International Centre for Chemical Safety and Security (ICCSS)
.
09:40

.
• Why business continuity is central to our IT and OT strategy
• How continuity planning shaped our response to a cyber incident affecting operations and the supply chain
• How we strengthened disaster preparedness through risk assessment and continuity planning
• Lessons learned from incident response and recovery, from initial handling through to restoration
.
Ramon Serres, CISO, Almirall
.
10:10

Cyber physical systems and OT security is sitting in a precarious halfway house between isolation and connection. In many cases the air gaps that secured the systems that sit at the very heart of industry and CNI have been eroded one use case at a time. How is this happening? Taking a step back for a moment, how should we be balancing risk and competitive advantage? We’ll look at some practical steps to take control of IT/OT convergence, how to get started and how to build the team you need to succeed.
.
Alex Holben, Strategy and Technology Officer, Fortinet

.
10:50Break & Networking
TRACK A
Strategies For Overcoming The Biggest Cyber Issues of Today
Chaired by Thomas Mortsell, CSO, Aneo

11:30

.

    • How we are effectively identifying and quantifying third-party risk in OT, including operational, safety, and regulatory impacts
    • How we are strengthening supply chain security through effective vendor due diligence, contracts, and SLAs
    • What we have done to secure vendor and third party access despite security concerns
    • How we have developed organisational resilience through workforce training and cross-industry collaboration

.
Donatas Vitkus, CISO, Ignitis Group
.

12:00

This session explores key challenges in securing industrial control systems and OT, using real-world insights. It covers organisations under attack, investing in prevention, and navigating regulations like NIS2. Learn practical strategies to manage evolving cyber risks, support digitalisation, and protect critical infrastructure in an increasingly connected environment.
.
– Senior Expert, OTbase
.
12:10

    • Why regulatory compliance should be approached as a long-term security program rather than a checklist exercise.
    • How AI is going to push the depth and complexity of these programs
    • How to build contextual awareness in OT environments by combining asset inventory, operational criticality, vulnerability intelligence, and compensating controls.
    • How contextual risk scoring improves prioritization and helps focus resources on the assets and threats that matter most.
    • How this approach leads to a much more stable foundation upon which to strive towards regulation AND autonomous operations.

.
Rick Kaun, Global Director, Cybersecurity Sales , Rockwell Automation
.

TRACK B
Proactive Roadmaps for Overcoming Common OT Challenges
Chaired by Nuno Teodoro, Global Cybersecurity Director, Hovione

11:30

• How we identified and prioritised vulnerabilities across complex OT environments to build an effective roadmap for OT vulnerability management
• How moving from static asset inventories to dynamic, real-time visibility helped us
• The importance of integrating IT and OT perspectives to create a unified risk picture
• How we can overcome challenges with our legacy systems, vendor patching, and resource constraints and where we can utilise automation and threat intelligence to strengthen our OT vulnerability management
.
Janine Oosthuizen, Director of OT Cybersecurity, CHEP
.
12:00

As IT and OT environments continue to converge, cyber risk increasingly extends beyond the factory floor to the business systems that support critical operations. This session explores how SAP security contributes to operational resilience by improving visibility, strengthening access controls, supporting vulnerability management, and enhancing monitoring. Attendees will gain practical insights into securing the SAP landscape as part of a broader OT cybersecurity strategy.
.
Brian Rosenberger, VP EMEA, SecurityBridge
.
12:10

  • How to overcome IT/OT integration challenges, bridge organisational silos, and prioritise the visibility blind spots that matter most across complex CNI environments.
  • Why behavior-based monitoring outperforms vulnerability-driven risk scoring when protecting legacy devices and safeguarding system uptime.
  • Best practices for prioritising high-impact risks aligned with regulatory frameworks like NIS2 and NCSC CAF, maximising operational resilience without overloading team capacity.

Julian Smith, Principal Solutions Engineer, Claroty
.

LUNCH
12:40Lunch hosted by Fortinet & Indurex
TRACK A
Developing Comprehensive & Human-Led Strategies To Mitigate Risk
Chaired by Thomas Mortsell, CSO, Aneo

13:40

.
Join Thomas Chappelow, Principal OT Security Specialist and Functional Safety Engineer, as he explores one of the most debated questions in operational technology: can a cyber attack cause a loss of safety? Drawing on real-world examples and industrial control system design, Tom challenges common assumptions, examines the relationship between cyber security and safety, and explains why the answer is often more complex than it first appears. A thought-provoking session for anyone responsible for protecting safety critical environments.
.
Thomas Chappelow, Principal OT Security Specialist and Functional Safety Engineer, Bridewell
.
14:10

• Security-First Culture starts at the top
• Detecting Early Signs of Insider Threats without compromising Privacy and Dignity of individuals involved
• Safety = Security – Safety and Security of Individuals embedded across the business
• Important Link between, IT, OT, HR and Cyber
• External Assurance to Internal Knowledge – relevance of checks and intelligence
.
Marcin Szczepanik, Head of Information Security, SP Electricity North West
.
14:40

As AI empowers attackers to discover vulnerabilities faster than organisations can patch them, the rules of OT cybersecurity are changing. This session explores why resilience, not perfect knowledge, is the foundation of effective risk reduction in industrial environments. Drawing on seven years of OT-focused innovation, TXOne Networks outlines a layered architecture spanning asset visibility, contextual risk prioritisation, virtual patching, and behavioural threat detection, showing how organisations can stay protected even when the threat landscape moves faster than the patch cycle.
.
Ivan Zhekov, Senior Director, TXOne Networks

.
TRACK B
Bridging Strategy and Execution in OT Security Operations
Chaired by Nuno Teodoro, Global Cybersecurity Director, Hovione

13:40

This presentation explores how automated collection into GRC can transform OT cybersecurity audits from a reactive, annual burden into a proactive, continuous process. We will discuss the integration of GRC platforms with OT-specific assets to enable:

  • Automated Evidence Collection: Reducing manual effort by pulling logs and configurations directly from industrial systems.
  • Continuous Controls Monitoring (CCM): Moving beyond periodic snapshots to real-time visibility into control health across multiple sites.
  • Framework Mapping: Efficiently aligning OT operations with standards like IEC 62443-3-3 and NIST SP 800-82.

Bart van der Hoorn, Product Manager for Industrial Cyber Security, Honeywell
.

14:10

When OT endpoints pass end‑of‑support, patching is no longer a control but a risk decision. This session shares a practical, experience‑based lifecycle approach for keeping legacy endpoints in service without pretending they are patchable. We’ll cover triage by consequence and exposure, “safe‑to‑run” baselines, and layered compensating controls—segmentation, constrained remote access, allow‑listing, and monitoring—to reduce attack paths. Governance keeps exceptions explicit, reviewable, and aligned to operational realities.
.
Michel Harthoorn, OT Programme Manager, bp
Rudolph Louw, Industrial Control System Security Specialist, bp
.
14:40

This session explores how an OT Intrusion Detection System (OT IDS) can actively support compliance with key IEC 62443 sections by integrating multiple cybersecurity functions—protocol-aware intrusion detection, continuous asset discovery, vulnerability management, and incident reporting—within a single solution.
.
Markus Westphal, Cyber Security for the Power Grid Specialist, OMICRON Energy
.

15:10

In critical infrastructure environments, every file that crosses a boundary – from a vendor’s USB drive, a remote engineer’s laptop, or an email attachment – carries an implicit assumption: that it is what it claims to be. That assumption is increasingly the weakest link in otherwise well-defended OT and IT networks. We don’t rely on single controls at any other point in our security architecture, yet we routinely accept single AV scan results for files entering critical systems. This session challenges the idea that file trust should ever be implicit. Drawing on real-world incidents where seemingly benign files (firmware updates, PDFs, engineering drawings) became attack vectors, we’ll explore how organizations can extend Zero Trust thinking down to the file level – verifying content, not just credentials or network position.
Attendees will leave with a practical framework for asking the right question of every file entering their environment: not “do we trust the source?” but “have we verified the content?”
.
Steven Broadwell, Director of Solutions Engineering, OPSWAT & Stefan Liversidge, Solution Engineer, OPSWAT.
.
15:40Break & Networking
16:10

T1: Has OT Security Become Too Cyber?
Ric Derbyshire, Principal Security Researcher, Orange Cyberdefense
.
T2: Practical Cybersecurity Baseline: Balancing Protection, Availability and Compliance
Jochen Füllgraf, Product Manager, Security Software, Belden
.
T3: Common Challenges and Solutions in Remote Access for Critical Environments
Jake Leonard-Walters, Sales Director EMEA, XONA Systems
.
T4: Shielding OT Vulnerabilities from AI Attacks with Frontier Virtual Patching
Anurag Thantharate, Global Director of Product GTM, Palo Alto Networks
.
T5: Adopting Effective Zero-Trust Controls to Heighten Our Security Posture
Open Systems
.
T6: Ensuring Security While Utilising Remote Access in OT
.
16:50

  • Who should lead OT Security and what reporting lines work best?
  • How should we drive C-Level engagement in OT security initiatives? How do you turn OT security challenges into strategic board priorities?
  • Can a CISO or equivalent drive OT security across IT and operations? Should all organisations have a CISO at board-level?
  • What can be done to ensure strong security leadership is embedded throughout your organisation?

Moderator: Thomas Mortsell, CSO, Aneo
Alfonso José Álvarez Calderón, Global IT/OT Lead & CIO, Exolum
Nish Sukumaran, Vice-President, Information Security, Worley
Malcolm Xavier, IT Security & Data Privacy Manager, EET Fuels
Knud Kegel, Chief Technology & Product Officer, Secomea
.

17:30 Chairman’s Closing Remarks
17:35 Drinks Reception
19:00 Dinner hosted by Nozomi Networks & ShieldWorkz (Invite-Only)

Join the Line-Up

Submit a Proposal

Request a Sponsor Pack

Submit Here

Register Now

Choose Your Pass