Event Agenda
28th February – 1st March 2023 // Munich, Germany
| Day 1 // 28th February 2023 08:00 – 19:00 | |
| 08:00Registration & Coffee | |
![]() | 08:50Chair’s Opening Address: Erik Södergren, Director Information Security, DeLaval |
| 09:00 . IT/OT convergence has been on the mind of most manufacturing security professionals for years. In this panel discussion, our experts talk about common issues in moving towards convergence and what we need to consider. Join this talk to hear how we can increase collaboration and cooperation between all sides of the plant. . • How do we bring OT on board with our security and training strategies? • How do we apply an established process on the OT side to ensure proper governance? • What are the key takeaways from what we see already? . – Ricardo Hormann, OT Security Specialist, Volkswagen – Anderson Goebel, Head of Cyber Security – Healthcare, Merck KGaA – Steffen Siguda, CISO, Osram – Marcus Helmke, Director of Software Development, Schuler Group – Adam Boulton, VP, Security Technology and Innovation, Cybellum | |
![]() | 09:40 . Risks to industrial and operational security only continue growing. That is why industrial manufacturers and critical infrastructure organisations are requiring their production operations to be ransomware-ready, secure, and uninterrupted to protect business continuity. . • How can industrial organisations close gaps and eliminate blind spots in asset visibility? • How can you empower IT and OT teams to be truly connected and streamlined for security collaboration? • How does creating a digital twin of your IT-OT network let you safely conduct breach and attack simulations? . – Kay Ernst, Regional Sales Director DACH, OTORIO |
![]() | 10:20Networking Break |
| TRACK A | |
![]() | 11:00 A session on Zero Trust and how manufacturing companies can build a Zero Trust Enterprise to improve operational efficiency, enhance customer experience and unlock digital revenue.. . – Dharminder Debisarun, Cyber Security Strategist / WW Manufacturing Industry Security Architect, Palo Alto Networks |
| 11:30 The increasing interconnectivity of OT systems makes them an attractive target for cyber attacks. These attacks can have serious consequences, as the OT systems often are critical to the operation of organisations. The current state of OT security is challenging, with many organisations facing complex environments and fast evolving threats. During this talk, we shed light on how we have started to attack the challenge, ensuring the security of our OT environment, as we are connecting more and more machines and IoT devices in our factories and warehouses. Our journey has just started but we feel comfortable that we have a good plan to achieve our goals, both from a business and from a security perspective. Participants will get an introduction to our approach when embarking the journey to smart manufacturing. . Erik Södergren, Director Information Security, DeLaval | |
![]() | 12:00 Overview of the Recent Threat Landscape Against OT Environments and How to Improve the ICS/OT Security Posture This talk will present an overview of recent threats against industrial environments the Dragos team analysed. Based on threat scenarios against various industry verticals, we will focus on the five critical security controls that really matter in ICS/OT environments and how to apply them to improve the security posture in OT to counter the threat scenarios that matter. . – Kai Thomsen, Director of Global Incident Response Services, Dragos |
![]() | 12:30 How to describe the process by which an organisation handles a data breach or cyberattack, including the way the organisation attempts to manage the consequences of the attack or breach (the “incident”) in an OT environment. An incident response contract offers peace of mind to organisations, offering support before and after cyber security incidents. With an incident response contract in place, organisations can prepare for cyber threats and respond quickly should they be compromised. . – Stefan Turi, Business Development Lead – Network & Security Services, Rockwell Automation |
| TRACK B | |
![]() | 11:00 .
– Jasmin Steinhoff, Pre-Sales Manager DACH, TXOne Networks |
![]() | 11:30 The constantly increasing networking of production in the context of digitization and the integration of cloud platforms leads to major challenges for protection against cyber attacks. Originally almost isolated production areas encounter highly networked IT areas and thus a changed threat situation also for production reliability. In order to meet the challenges with new protection technologies and collaboration models, the two worlds of production and cybersecurity must grow together. . – Ricardo Hormann, OT Security Specialist, Volkswagen |
![]() | 12:00 In this session we are exploring the best practices for implementing a defence-in-depth strategy for the Industrial Control Environment, what security controls can be implemented and the holistic approach OPSWAT takes in order to make this possible. . – George Chereches, Sales Engineering Team Lead EMEA, OPSWAT |
![]() | 12:30 In addition to the core ERP functionality provided by SAP, manufacturing companies rely on SAP to execute manufacturing processes, analyse manufacturing and business data, and integrate systems with a cost-effective, high-quality, and resource-efficient method based on Industry 4.0. Onapsis provides information security teams the ability to quickly manage, measure, and minimise risk within their SAP environments and streamline remediation efforts to ensure the security and compliance of their systems. Come join our session to learn how! . – Jan Hubicka, Director of Sales Engineering EMEA & APAC, Onapsis |
| Lunch | |
| 12:40Lunch hosted by OTORIO | |
| TRACK A | |
![]() | 13:40 Engineers and cyber security personnel face a difficult challenge getting a good understanding of the risks that exist in their OT environment. Traditional methods for performing security assessments, such as penetration testing, site questionnaires or passive network monitoring all have their significant drawbacks. Join Nouryon in their journey to explore what it takes to build a better risk picture of their industrial control systems, and discover if the benefits of active monitoring outweigh the risks. . – Randy Conner, CISO, Nouryon – Rutger Hendriks, OT Security Lead EMEA, Nouryon |
![]() | 14:10 Cyber security has become a top concern due to the rise in attacks targeting industrial end users. This presentation will show how the adoption of Zero Trust as a defensive measure generates a two-fold impact: Improving security by acting as a digital gatekeeper between the ICS networks and the parties interested to establish communications with it, and filling all the security gaps of an entire plant and move into a passwordless environment. The adoption of such technology also puts an end to all concerns that still slow down the digital transformation journey. . – Rami Raulas, Head of EMEA Region, SSH Communications |
![]() | 14:40 OT security is a multidimensional challenge. Enabling over 100 factories around the globe to secure infrastructure by rolling out globally standardised tools is a wonderful journey. Adding complexity with hundreds of associates and 3rd party vendors can become a nightmare. In this session we´ll hear about one approach to drive a corporate program in a scattered OT landscape. It will reflect some learnings from a corporate decision down to a local implementation. . – Frank Polky, Director OT Security, Mars |
| TRACK B | |
![]() | 13:40 The Purdue Model created in the 90s where factories were isolated from the outer world fitted a perfect role at that time. Nowadays, the situation has changed significantly and hyperconvergence now dominates. Systems and devices connectivity needs are across layers within the same factory, to other factories, to the enterprise, to the cloud or other organisations. Clearly the Purdue Model was not created with this scenario in mind. Without discarding it, this presentation will analyse the current situation and present an approach where the OT cyber security posture could be kept at the same level or even be improved in this new situation.. . – Josep Román, Associate Director Global Cyber Security, Coca-Cola Europacific Partners |
![]() | 14:10 OT environments are monitored for security purposes using only passive traffic observation. This is done to determine asset inventory and vulnerability information. Passive traffic observation is also useful to baseline the asset set, and look for attack activity. While traffic observation is valuable, it’s simply not enough. |
| 14:40 Join us for this interview-style chat with Stefan Wenigmann, Group CISO at Bucher Industries as he discusses his experience of a recent cyber incident and the lessons learned since. Trish McGill will be moderating, with time for a Q&A with Stefan towards the end of the session. . Moderator: Trish McGill, Sr. Subject Matter Expert Cyber Security IT/OT – Stefan Wenigmann, Group CISO, Bucher Industries AG | |
| – | |
![]() | 15:10Networking Break |
| 15:50 Table 1: Are You in Control of Your OT, or Is It Controlling You? Let’s Discuss – Ben Barker, Manufacturing Systems Architect EMEA, ServiceNow . Table 2: Anatomy of Boom Event: Effective Line of Defense Against OT Cyber Attacks – Serkan Yusuf, Global Director – OT Security Services, OTIFYD . Table 3: Challenges of Access & Concrete Steps to Manage Them Safely – Andreas Kuemmerling, Regional Sales Director DACH, Cyolo . Table 4: Proven Implementation Approaches for Cyber Security Solutions in OT – Christian Koch, Senior Vice President Cybersecurity – IoT/OT, Innovations & Business Development, NTT DATA – Daniel Buhmann, Principal Systems Engineer and Subject Matter Expert for Operational Technology & IoT, Fortinet . Table 5: – Prevent! Don’t detect. Zero-Trust PLC Protection from Insiders, Third-Party Providers, and Human Errors – Thierry Kolton, General Manager Europe, Nanolock – David Assayag, Senior Product Manager, Nanolock | |
![]() | 16:30 As the OT threat landscape reshapes into its third transformation, defined by what we call “Industrial-Grade Ransomware” – and with the Industrial sector remaining the most targeted sector throughout 2022, proper incident response in the industrial space today requires a holistic approach, across the enterprise’s digital estate – IT and OT. In this session we will take you through one such ‘heavyweight’ attack we responded to, and share what we learned on the journey, to help you proactively enhance your cyber resilience, enterprise-wide. . – Rafael Maman, VP, Operational Technology Security, Sygnia – David Warshavski, VP, Enterprise Security Sygnia – David Gray, Director Cyber Security Services EMEA, Sygnia |
| 17:00 With many countries feeling the brunt of financial uncertainty, we’re asking what impact this could have on our security systems and what we should be doing to prepare. Our expert panellists will discuss this and more during our discussion.
Moderator: Stefan Wenigmann, Group CISO, Bucher Industries AG | |
![]() | 17:40Chair’s Closing Remarks: Erik Södergren, Director Information Security, DeLaval |
| 17:50Drinks Reception by Xona Systems | |
| 18:30Dinner Sponsored by Palo Alto Networks | |