Event Agenda
15th – 16th September 2026 // Sydney
15th – 16th September 2026 // Sydney
Theme: The Secure Ecosystem: Aligning People, Standards and Systems in OT
| Day 1 // 15th September 2026 08:45 – 17:10 AEST | |
| 08:50 Opening Address: Lauren Veenstra, CSO, Iberdrola Australia | |
| 09:00 The complex nature of governance in modern industrial environments leaves a critical question unanswered: Who is ultimately responsible for the security of our operational technology? Is it IT, OT, C-suite, or a shared responsibility? In this expert panel discussion, we will dissect the intricate web of governance and accountability in the realm of OT security, exploring the critical need for clear ownership and a unified strategy to defend against escalating cyber threats to critical infrastructure. . ● How is IT/OT convergence impacting security roles and responsibilities? ● What are the best practices for establishing a robust governance framework that defines roles, responsibilities, and accountability for OT security? ● How do we manage cross-departmental collaboration and communication? . – Moderator: Feli Gouw, Senior Central OT Engineer, EnergyAustralia – Siddharth Rajanna, Head of IT Security, Bingo Industries – Rolf Samonte, Head of ICT and Cyber Security, Metro Trains Sydney – Darren Chippendale, Senior Manager – Information Security Management Programme, Powerlink Queensland – Ayman Essmat, CIO, Eurobodalla Shire Council . | |
| 09:50 As IT and OT environments converge, organisations face a growing cyber-attack surface and increased operational risk. This session explores how an integrated IT/OT Security Operations Centre (SOC) provides unified visibility, faster threat detection, and coordinated response across enterprise and industrial environments. Discover how leading organisations are strengthening cyber resilience, protecting critical assets and enabling secure digital transformation. . – Lokesh Kodi, Digital Solutions Business Consultant, Yokogawa – Peter Raven, Senior Alliance Director, Lumen Technologies . | |
| 10:20Networking Break | |
| 11:10 The message: a safe rider does not rely on luck, a helmet, or one pre-ride check. They use a structured programme: training, inspection, situational awareness, protective controls, route planning, maintenance, telemetry, and disciplined response when conditions change. Anyone who rides a motorcycle knows risk is not theoretical. You are exposed, the environment changes quickly, and small mistakes can have physical consequences. But experienced riders do not avoid risk by staying still. They manage it through discipline: checking the bike, reading the road, wearing the right gear, understanding the conditions, and constantly adjusting. CPS protection is the same. We are not trying to stop operations. We are trying to help the organisation move faster, safer, and with more control. . – Jason Pearce, Field CTO, APJ, Claroty . | |
| 11:40 The security and operation of cyber-physical systems depend on a strong foundation of network segmentation. In mission-critical environments, you must continuously verify – 24/7 – that your segmentation is in place and stays effective. This is what SensorFu Beacon delivers – verification that segmentation, isolation strategies are truly working. . – Mal Kelly, Director – ANZ Region, SensorFu . | |
| 11:50 As cyber threats to OT rise, organisations across Australia and New Zealand are under growing pressure to strengthen security. IEC 62443 has become the global benchmark. Regulators across the region, including Australia’s critical infrastructure legislation, are increasingly adopting or aligning with IEC 62443. For OT security teams, applying these standards is now essential for both compliance and resilience. In this session, we share practical guidance on IEC 62443 and how to overcome the challenges of implementation. . ● Gain a practical understanding of IEC 62443 and why it matters ● Learn how to operationalise IEC 62443 in your organisation ● Hear real-world success stories: how enterprises are applying segmentation, defence-in-depth, and secure lifecycle strategies . – John Morcos, Head of Cyber Security Governance and Operations, Blackmores . | |
| 12:20 Lunch hosted by Nozomi/Secolve | |
| 13:20 The promise of Industry 4.0 is to transform OT environments. In this session, we will guide attendees through the critical steps and best practices for adopting new and emerging technologies without compromising the safety and reliability of their operations. A session is designed for anyone involved in the digital transformation of industrial environments, join us to safely maximise your use of the latest tools in an OT context. . ● Get up to speed with the latest technologies suited to your industrial environment ● Address concerns about adopting new tech by prioritising security ● Adopt a framework for safe integration… or develop your own! . – Penny Iverach, Senior Manager – Technology and Transformation, Port of Newcastle . | |
| 13:50 The IT/OT interface is the primary gateway for industrial breaches. This session examines how engineering-themed phishing lures bypass traditional defences to threaten physical operations. Learn to harden the critical juncture between networks, implementing robust identity verification and isolation to ensure a compromised credential never compromises your plant’s safety or productivity. . – Jenny Botton, Senior Manager Cyber Security, ABN Group . | |
| 14:20 IEC 63452 is an emerging international standard under development (expected mid‑2026) that seeks to establish a framework for integrating cyber security activities across the railway system lifecycle. As development of the standard progresses, railway operators, asset owners, engineers, and cyber security practitioners are increasingly interested in its potential application alongside existing safety, engineering, and assurance practices. This presentation will provide an overview of the standard’s objectives and key concepts, its relationship to established railway and cyber security standards, including the IEC 62443 series and AS 7770, and key considerations for future adoption. Attendees will gain insights into how IEC 63452 may influence the future direction of cyber security, risk management, assurance, and operational resilience across the rail sector. . – Christian O’Donnell, Cyber Security Engineer, UGL Transport . | |
| 14:50 As operational technology becomes more interconnected, securing the industrial supply chain has never been more critical. The modern OT ecosystem relies on a complex web of third-party vendors, legacy software, and external integrators, each introducing potential vectors for cyber disruption. This presentation moves beyond the theoretical to deliver actionable, real-world strategies for identifying and mitigating digital supply chain risks without disrupting production. . ● Map your OT supply chain and identify hidden third-party dependencies ● Implement realistic cyber security procurement standards for industrial vendors ● Get practical techniques for monitoring supplier risk and responding to upstream breaches . – Jihad Zein, Global Head of Governance, Risk and Assurance, Group IT, Toll Group . | |
| 15:20 Networking Break | |
| 15:50 With the increased convergence of IT and OT, user access management is now a key aspect of industrial security. Implementing a robust IAM framework is essential for mitigating insider threats to your OT network. This case study outlines our journey from a fragmented, insecure environment to a centrally managed, secure operational network. We will detail the step-by-step process of IAM implementation, highlighting the key decisions and technical solutions deployed. . ● How to conduct a comprehensive assessment of OT assets, user roles, and access requirements to build a foundational understanding of the OT environment ● Hear about the criteria used to select an IAM solution that could handle the unique demands of OT ● Develop strategies for managing access during critical maintenance windows, ensuring production continuity . – Andrew Thyrd, Network and OT Security Manager, Sydney Airport . | |
| 16:20 Coffee Break | |
| 16:20 Plenary – Please Go To ANZ Cyber Summit Room | |
| 16:30 Join experts from the Australian Signals Directorate (ASD) for a practical exploration of Australia’s evolving cyber threat landscape and national defence mechanisms. This session delivers direct operational insights into effective threat mitigation, incident response standards, and actionable advice to safeguard critical infrastructure. Delegates will gain a clearer understanding of how the ASD identifies emerging vulnerabilities and collaborates across industry sectors to build robust digital posture. Whether managing enterprise infrastructure or steering organisational risk, this presentation offers essential guidance on embedding proactive defence measures, enhancing operational readiness, and maintaining compliance within an increasingly complex and dynamic global security environment. . – Assistant Director, National Partnerships NSW, Australian Signals Directorate (ASD) . | |
| 17:00Closing Remarks – Gaurav Vikash, Head of Security and Risk – APAC, Axon | |
| 17:10Drinks Reception | |
| Day 2 // 16th September 2026 08:50 – 17:10 AEST | |
| 08:15Registration & Coffee | |
| 08:50Opening Remarks: Lauren Veenstra, CSO, Iberdrola Australia | |
| 09:00 As the Security of Critical Infrastructure Act develops and shapes the Australian regulatory landscape, the focus for asset owners has shifted from high-level compliance to granular, operational resilience. In this panel session, we explore the future of OT security within this enhanced legislative framework. As the Act develops to include more critical assets, along with changes to how high-risk assets demonstrate their cyber maturity, we want to give today’s OT leaders the tools they need to understand and stay compliant. ● How do we navigate the specific requirements of the SOCI Act and its impact on long-term OT investment and architecture? ● With the 2026 enhancements to the CIRMP rules, how are we moving from ‘check-box’ compliance to demonstrating verifiable maturity in legacy OT environments? ● Does SOCI’s focus on ‘Foreign Ownership, Control, and Influence’ fundamentally change how we procure OT hardware and software in Australia? . – Moderator: Lauren Veenstra, CSO, Iberdrola Australia – Ryan Walker, OT/ICS Manager, Ventia – Dennis Moncrieff, IT Superintendent, Tomago Aluminium – Peter Davidoff, Head of Cyber Security Architecture and Assurance, Department of Defence . | |
| 09:50 Your attack surface is full of computers nobody calls computers: IP cameras, printers, HVAC controllers, PLCs. These 65 billion devices in xOT environments outnumber traditional endpoints 11 to 1, a gap projected to widen to 31x by 2030. They run capable operating systems but are rarely patched, hardened, or monitored, and EDR often can’t be installed. Ransomware operators have noticed: this session reconstructs how an Akira affiliate bypassed EDR entirely by encrypting a network from an unmanaged IP camera. Attendees will leave with practical mitigations for discovering, hardening, and lifecycle-managing the devices they’ve forgotten. . – Alex Nehmy, Field CTO, APAC, Dragos . | |
| 10:20Networking Break – Breakfast hosted by Dull (Invite Only) | |
| 11:00 For OT teams, uptime and safety are non-negotiable. To an engineer on the plant floor, IT-driven cyber security protocols can feel like a bureaucratic roadblock—patches that threaten stability or passwords that delay emergency response. To bridge this cultural chasm, cyber professionals must stop treating security as an IT compliance exercise and start speaking the native language of industrial operations: Risk Management. In this session, we explore how to build a collaborative “Risk Mindset” that empowers OT teams to champion security. . • Reframe cyber security as a component of functional safety rather than an IT overhead • Introduce patching and vulnerability management without risking 100% uptime • Create successful ‘Quick Wins’ for creating a unified response team . – Alfredo Urdaneta,Control System and SCADA Specialist Engineer – Utilities, Rio Tinto . | |
| 11:40 Security policy is often written in a boardroom, but it’s executed on the factory floor. In this session, we move beyond high-level strategy to provide an actionable playbook for embedding cyber security into daily maintenance, vendor management, and control system operations. Learn practical tools for managing contractor access, securing removable media, triaging low-level incidents, and building a strong, security-aware culture within your technical teams. Empower your front line to become the first and most effective layer of defence. . • Translate high-level security policies into practical, documented work instructions for maintenance crews • Implement robust processes for managing contractor access, temporary credentials, and USB/removable media usage • Develop effective, role-specific training programs to establish a proactive, cyber-resilient operations team . – David Petzer, Senior Operational Technology Engineer, Glencore Coal . | |
| 12:20Lunch hosted by Dragos | |
| 13:20Plenary – Please Go To ANZ Cyber Summit Room | |
| 13:20 As industrial environments grow in complexity, traditional signature-based detection is no longer sufficient to stop sophisticated actors. This session explores the transition to Digital Twin-enhanced monitoring. We will discuss how, by comparing real-time SCADA data against the expected behaviour of a digital twin, operators can identify subtle, non-linear deviations that indicate a cyber-attack or mechanical compromise. . • Hear practical steps to integrate high-fidelity process data into your security stack • Enable a proactive defence posture that identifies threats before they result in physical damage or operational downtime • Align engineering maintenance data with security monitoring to reduce false positives and improve incident response triage . – Amish Patel, Former Director for OT Security, Transport for NSW . | |
| 13:50 AI is changing the cyber threat landscape not necessarily by creating new vulnerabilities, but by making existing ones easier and faster to discover, understand and exploit. In OT environments, where legacy systems, long remediation cycles and operational constraints are common, this acceleration creates a significant challenge. Our own Mythos program has demonstrated how automation and AI-assisted approaches can accelerate vulnerability discovery and analysis. The same capabilities, however, are increasingly available to attackers. This session explores how AI is shifting the balance between attacker and defender, and more importantly, what organisations can do about it. It will provide practical guidance on reducing exposure, prioritising vulnerabilities, strengthening segmentation and access controls, and using AI defensively to improve detection, vulnerability analysis and response. The question is no longer just whether you can find and fix the vulnerability — but whether you can do it before an AI-assisted attacker does. . – Gursimran Tiwana, Head of Cyber Security, Lumus Imaging . | |
| 14:20 Managing cyber security across different eras of infrastructure is a high-stakes balancing act. In this session, our expert speaker explores the realities of parallel-tracking OT security across generations of technology, delving into the challenges of maintaining OT security at a 30-year-old brownfield site, while preparing to launch a brand-new greenfield site fit with the latest tech. We will discuss practical strategies for retrofitting legacy systems, alongside the unique opportunities of baking robust cyber resilience into a modern asset from day one. . • Balance legacy asset preservation with cutting-edge greenfield security design • Implement pragmatic security controls on 1990s hardware without disrupting uptime • Learn the lessons of preparing operations for a state-of-the-art launch . – Ryan Walker, OT/ICS Manager, Ventia . | |
| 14:50Networking Break | |
| 15:20 The disconnect between IT Operations (uptime) and Security (risk) often creates friction, delays, and critical vulnerabilities. In this session, our speaker offers a practical blueprint for transforming security into an integrated, shared responsibility across your organisation. We explore how to dismantle silos and implement a true SecOps culture. . • How do we establish unified communication and collaborative workflows, and align KPIs so both teams own cyber risk and efficiency? • What methods have you found to integrate security testing and response directly into IT deployment pipelines? • How can we train IT staff on security principles and SecOps staff on operational constraints? . – Pratik Waghela, BISO, Ventia – Sanja Petrovic, General Manager, Cyber Security & Governance, HUB24 . | |
| 15:50Closing Remarks – Lauren Veenstra, CSO, Iberdrola Australia | |
| 16:00End of Conference | |