The systems that keep the lights on, the water clean, and the fuel moving were engineered for one thing: decades of reliable operation. How do you secure these critical systems that were never designed with security in mind?
Join Jason D. Christopher, SANS certified instructor & course authors as we explore the differences between IT and OT and the trends across both threats and technologies. These systems were built with different priorities, different protocols, and very different consequences when something goes wrong. A security program built for the enterprise will fail on the plant floor, and understanding why is the foundation for responding to cyber incidents in critical infrastructure.
Over the past 20 years, threats have evolved, but the approaches to defend them have stagnated. Today, state actors are pre-positioning inside U.S. infrastructure while the same technology shifts that make operations more efficient— remote access, cloud services, IT/OT convergence— keep expanding the attack surface.
So how do we defend it? The session closes with the SANS ICS Five Critical Controls, a prioritized framework built around how these attacks actually unfold. Attendees will leave with a clear-eyed view of the ICS threat landscape and a defensible place to start