2026 Session
Desoto 1-2
11 am - 11:40 am, Wednesday, October 14
Beyond Compliance - Building Cyber Resilience for Critical Infrastructure
About
Passing an audit doesn't mean an operation can survive an attack. This practitioner session argues that critical infrastructure operators should treat frameworks like NERC CIP, IEC 62443, and NIST CSF as the floor, not the goal, and design for the assumption that compromise will happen. Using recent incident data and real-world supply chain attacks, Dr. Ed Harris will show how to model cyber-physical risk, prioritize systems by safety and business impact, manage third-party exposure, and prepare executives for the first four hours of a crisis. Attendees also work through a live ransomware scenario in an OT environment.
Key takeaways:
  • How to measure resilience, not just compliance. Time-to-recover and impact radius reveal more about readiness than the number of controls passed.
  • How to prioritize by consequence. Put life-safety systems first, then mission-critical operations, and give every critical system a documented recovery time and recovery point objective.
  • How to treat vendors and dependencies as entry points. This includes third parties with privileged OT access and open-source components, so tighten access, segmentation, and oversight.
  • How to pre-authorize crisis decisions. Decide in advance who can isolate systems, who gets notified, and how operations shift to manual mode, so leaders can act in minutes rather than hours.
  • How to build partnerships before an incident. Free resources from CISA, sector ISACs, and sector-specific agencies are far more useful when the relationships already exist.
Get in touch
Get in touch
Customer Service
For any and all inquiries please click the button below
Speaking Opportunities

Interested in speaking at the event?

InfoSec World
Stay
Informed
Join our mailing list for the latest news on InfoSec World 2026.