Agenda Day 2
9:00 am - 9:10 am CHAIRMAN’S RECAP OF DAY 1
9:10 am - 9:50 am ASSESSING THE POTENTIAL PHYSICAL AND CONSEQUENTIAL IMPACTS OF AN ATTACK ON CYBER-PHYSICAL SYSTEMS
- Physical impacts encompass the set of direct consequences of ICS failure, including personal injury and loss of life, the loss of property (including data) and potential damage to the environment
- Economic impacts are a secondary effect from physical impacts ensuing from an ICS incident, inflicting a greater economic loss on the facility, organisation, or others dependent on the ICS
- The consequence from the loss of national or public confidence in an organisation is, at times, overlooked. However, it is a very real consequence that could result from an ICS incident
9:50 am - 10:30 am Cybercrime – The Real Deal - Why do cyberattacks still succeed?
- Impact of latest ICS cyberattacks
- Why do cyberattacks succeed?
- What can we do about it?
- Preview of what will happen the next years
10:30 am - 11:00 am MORNING COFFEE AND NETWORKING
11:00 am - 11:40 am HOW TO BUILD AND TRAIN A CROSS-FUNCTIONAL TEAM WITHIN YOUR ORGANISATION
How can cross-functional information security teams be encouraged to share their varied domain knowledge and experience to evaluate and mitigate risk in the ICS?
Encouraging control engineers to take a larger role in the security of ICS, and providing them with ease of collaboration and support from both the IT department and management
Implementing an effective reporting structure, and understanding where the ultimate authority and responsibility lie
Haya Shulman
Department Head Cybersecurity Analytics and DefencesFraunhofer Institute for Secure Information Technology SIT
11:40 am - 12:20 pm TOWARDS SAFER PLANTS – FINDING OT CYBER SECURITY
- Translating cyber security measures effectively into the OT world
- Understanding what the roles and responsibilities of the OT team are
- Anticipating the factors affecting project execution
- An analysis of the difficulties integrating IT and OT into an Integrated Cyber Security Solution
12:20 pm - 1:20 pm NETWORKING LUNCH
1:20 pm - 2:00 pm WHAT EUROPE IS DOING TO SUPPORT THE EUROPEAN CYBERSECURITY MARKET
- The creation and the priorities of the European Public Private Partnership between the European Commission and ECSO (European Cyber Security Organisation)
- How the discussion on Industrial Control Systems is taking place in ECSO
- What is the expected contribution from users operators and suppliers of Industrial Control Systems; what is their interest in participating in a common market development?
2:00 pm - 2:40 pm IDENTIFICATION AND AUTHENTICATION: PREPARING FOR CHALLENGES FACED WITH ICS USER’S ABILITY TO RECALL AND ENTER A PASSWORD MAY BE IMPACTED BY THE STRESS OF THE MOMENT
- Considering the security needs and the potential ramifications of the use of authentication mechanisms on these critical systems
- Providing an equivalent security capability or level of protection for the ICS situations where the system cannot support authentication mechanisms
- Implementing special considerations when pushing down policies based on login password authentication within the ICS environment
Christoph Riedmann
Senior Adviser - Digitisation, Cyber Security, Industrial PolicyFachverband Metalltechnische Industrie
2:40 pm - 3:10 pm AFTERNOON TEA AND NETWORKING
3:10 pm - 3:50 pm THE PHYSICAL PROTECTION OF THE CYBER COMPONENTS AND DATA ASSOCIATED WITH THE ICS THAT MUST BE ADDRESSED AS PART OF THE OVERALL SECURITY OF A PLANT
- Mitigating the risk of physical modification, manipulation, theft or other removal, or destruction of existing systems, infrastructure, communications interfaces, personnel, or physical locations impacting the security of these systems
- Preventing unauthorised observation of sensitive informational assets through visual observation, note taking, photographs, or other means
- Blocking the ability of new systems, communications interfaces, or other hardware being introduced to the infrastructure
- Creation of a policy that prevents installation of devices intentionally designed to cause hardware manipulation, communications eavesdropping, or other harmful impact
Thomas Usländer
Head of Department, Information Management and Production ControlFraunhofer IOSB
3:50 pm - 12:00 am UNDERSTANDING HOW TO IMPLEMENT EFFECTIVE MONITORING, LOGGING, AND AUDITING SOLUTIONS, AND ASSESSING THE BENEFIT OF DOING SO TO YOUR SECURITY PROCEDURES
- Creating an ICS security architecture that can incorporate mechanisms to monitor, log, and audit activities occurring on various systems and networks
- Understand the importance of monitoring, logging, and auditing activities validating that the system is operating as intended, and that no policy violations or cyber incidents have hindered the operation of the system
- Strong system monitoring, logging, and auditing is necessary to troubleshoot and perform any necessary forensic analysis of the system