OT-ISAC PRESENTS · SINGAPORE 2026
OT-ISAC
SUMMIT
SINGAPORE
2026
“Driving IMPACT in Critical Infrastructure Security”
8 OCT · SUMMIT PROGRAMME
9 OCT · PICKLEFEST
📍 Four Points by Sheraton, Singapore
ABOUT THE SUMMIT
OT-ISAC Summit 2026

Date: October 8–9, 2026  |  Venue: Four Points by Sheraton, Singapore
Theme: Driving IMPACT in Critical Infrastructure Security

As cyber threats targeting operational technology (OT) environments continue to evolve, organizations are increasingly challenged not by a lack of intelligence, but by how effectively it is translated into meaningful outcomes.

The OT-ISAC Summit 2026 brings together industry leaders, operators, and security practitioners to explore how intelligence and collaboration can be applied to reduce real-world risk across critical infrastructure.

Aligned with the theme “IMPACT”, the summit examines how organizations can strengthen their security posture across five key pillars:

⚙️
Engineering & ArchitectureBuilding resilient and secure OT environments
🔍
OT Threat IntelligenceApplying intelligence to support operational decision-making
🛡️
Risk & GovernanceAligning cybersecurity with risk management & regulatory expectations
🧠
Talent & Workforce DevelopmentDeveloping skills required to support OT security
⚛️
Quantum ReadinessPreparing OT environments for the emerging quantum computing threat landscape

The programme focuses on practical approaches, including case studies and peer discussions, designed as a practical forum for discussion, knowledge exchange, and collaboration across the OT security community.

🏓 Beyond the Summit: Community & Networking
We believe strong security is built on strong relationships. To bring the community together beyond the sessions, we’re hosting a Friday Pickle Fest on October 9 — a fun, social pickleball tournament designed for informal networking, cross-sector connection, and community bonding in a relaxed setting. Whether you’re playing or cheering from the sidelines, it’s a great way to connect, unwind, and continue the conversations from the summit.
VISIT OTISAC.ORG →
STRATEGIC FRAMEWORK
IMPACT

Six dimensions guiding every session, discussion, and outcome at the summit.

I
Intelligence
Actionable, shared, and contextual threat intelligence that drives real decisions.
M
Modern Architecture
Secure-by-design, resilient OT systems built for today’s threat landscape.
P
People
Skilled workforce development and community-driven collaboration.
A
Accountability
Governance, metrics, and measurable outcomes that prove security works.
C
Collaboration
ISAC-driven collective defense and cross-sector information sharing.
T
Transformation
Shifting from reactive to proactive security posture.
AFTERNOON PROGRAMME · PICK YOUR TRACK
Grow two dimensions of resilience.

Both tracks are hands-on, peer-driven and built around real scenarios from the OT-ISAC community. Pick the one that grows your team's edge.

MODULE 01  ⚡ 90 MIN
OT Cyber Range
Sharpen the technical side of OT cyber resilience.

Practice in a safe, realistic environment — without deliberately attacking your own production systems. Make mistakes, investigate suspicious activity, test defensive measures and repeat until the right response becomes familiar. It's resilience built by doing, not just discussing.

Over the 90-minute workshop, you'll work through a hands-on, step-by-step OT cyber incident investigation — with full visibility into the network traffic, security logs and OT systems involved in the attack.

YOU'LL WALK AWAY ABLE TO
→ Investigate and respond, hands-on.
MODULE 02  🧠 90 MIN
Predictive Resilience Exercise
Strengthen your decisions before the incident.

Work through an evolving OT scenario alongside fellow practitioners, where information is incomplete and assumptions are put to the test. Build the judgement to recognise weak signals and act early — before disruption occurs.

YOU'LL WALK AWAY ABLE TO
→ Decide earlier, and with confidence.
✓ RESERVE YOUR SPOT — To keep both experiences hands-on and personal, seats are kept small and allocated first-come, first-served. Register early to lock in your preferred track.
EVENT AT A GLANCE
Programme by Day

October 8 is the OT-ISAC Summit programme. October 9 is dedicated to PickleFest, our community networking experience.

OCTOBER 8
OT-ISAC SUMMIT PROGRAMME
Keynotes, leadership panels, technical deep dives, community intelligence, an interactive tabletop exercise and networking drinks.
OCTOBER 9
OT-ISAC PICKLEFEST
A separate day for informal industry networking, community connection, friendly competition and relationship-building.
OCTOBER 8 · SUMMIT PROGRAMME
08:00–09:00
Registration Opens
Arrival, registration and informal networking
09:00–09:15
Welcome Opening Remarks
AJ Eserjose, Regional Director, OT-ISAC
Opening · Main Ballroom
PeopleCollaboration
09:15–09:45
Quantum for Critical Information Infrastructure (CII)
Keynote · Main Ballroom
Modern ArchitectureTransformation
09:45–10:15
Operational Resilience in the Age of AI-Enabled Cyber Attacks
Markus Mueller, Field CISO, Nozomi Networks

Frontier AI models are beginning to change the economics of offense — accelerating vulnerability discovery, generating exploit paths, automating reconnaissance and reducing the expertise needed to move from disclosure to exploitation. For critical infrastructure operators this has immediate implications for patch prioritization, exposure management, incident readiness, threat hunting and executive-level resilience planning. This session explores what AI-enabled cyber operations mean for OT environments, where security decisions must account for safety, availability, process integrity and physical consequences, and argues that defenders must use AI and automation to compress analysis, improve prioritization and accelerate response without introducing unsafe or poorly governed actions into production environments.
Case Study · Main Ballroom
TransformationAccountability
10:15–10:45
The Resilient CISO: From Cyber Metrics to Operational Outcomes
Moderator: Thian Chin Lim, Director · GovTech. Panellists: Colin Choo, Director Cyber for Operations · Kenvue; Christina Hoefer, VP OT & IoT Strategy (and Global Principal Systems Engineer) · Forescout Technologies; Shih Hsien Lim, CISO · Seatrium

A practitioner-led discussion examining what successful cybersecurity leadership should look like when cyber risk intersects with safety, production, service continuity and physical operations. The panel explores whether today's CISO incentives, reporting structures and measures of success are aligned with meaningful risk reduction and long-term operational resilience, and how organisations can measure outcomes beyond compliance and traditional cybersecurity metrics.
Panel Discussion · Main Ballroom
AccountabilityCollaboration
10:45–11:10
Coffee Break
Room: TBC
11:10–11:50
What Does CVSS Really Mean to OT Security?
David Ong

CVSS is widely used to prioritise cybersecurity vulnerabilities, but does a high CVSS score necessarily mean high operational risk in an OT environment? Vulnerability severity is only part of the picture — asset function, exposure, process consequence, existing protection layers and the operational risk of remediation can all change what should be addressed first. Drawing on practical OT experience and ISA TR84 cybersecurity guidance, this session explores how organisations can move from vulnerability scores to consequence-based decisions, and why "patch immediately" is not always the safest response.
Session · Main Ballroom · 11:10–11:40
Modern ArchitectureTransformation
CISO Roundtable Session
Hosted by Trellix
Roundtable Discussion · Track A · 11:10–11:50
CollaborationIntelligence
11:50–12:20
Dam Takeover or Little Annoyances?
Michele Campobasso, Senior Security Researcher, Forescout Technologies, Inc.

Sifting through hacktivist attack claims to extract relevant threat intelligence: how hacktivism evolved from a grassroots movement to a façade for state-aligned attacks; the current TTPs used by hacktivist groups and why they matter; recognising which groups can realistically pose a threat versus which are just noise; and how to track these groups, use that data in a threat intelligence program, and mitigate the risks to critical infrastructure.
Community Discussion · Main Ballroom
IntelligenceCollaboration
12:20–12:30
Signing MoU with Singapore University of Technology and Design
With Mark Goh
Signing Ceremony · Main Ballroom
CollaborationPeople
12:30–14:00
Lunch
14:00–14:30
Design of Software Based OT CI Cyber Twin For Cyber Exercise
Liu Yuancheng, Head of Technology, National Cybersecurity R&D Laboratory

This share session will introduce the design of several Software-based Critical Infrastructure OT Cyber Twin for supporting cyber exercises, security training, and research. The proposed system digitally replicates the physical processes, OT devices, communication networks, control logic, and supervisory systems of critical infrastructure environments, enabling realistic interaction between cyber attacks and simulated physical processes. The cyber twin adopts a modular architecture that integrates physical-world simulation, virtual PLCs/RTUs/IEDs, industrial communication protocols, SCADA/HMI systems, network services, and cybersecurity monitoring components. Three different cyber twins system will be introduced, including:

· Mini OT Aviation CAT-II Airport Runway Lights Cyber Twin System
· Land Based Railway OT Cyber Twin System
· Power Grid OT-Energy-System Cyber Security Cyber Twin System

The software-based CI simulation approach enables rapid deployment, repeatable scenarios, safe attack experimentation, and scalable multi-user exercises without affecting real-world infrastructure. The proposed design provides a flexible foundation for developing realistic OT cyber ranges and cyber exercises, helping organizations evaluate defensive capabilities, train cybersecurity personnel, and study the impact of cyber attacks on critical infrastructure operations.
Technical Deep Dive · Main Ballroom
Modern ArchitectureIntelligence
14:30–15:00
From AI Experiments to Trusted AI in OT
Simeon Tan, Protos Lab

AI and AI agents are opening new possibilities for OT security, from accelerating threat intelligence and investigations to helping analysts make sense of increasingly large and fragmented datasets.

Drawing on lessons from building and deploying Protos AI in high-trust environments, this session explores where AI genuinely adds value, where it can fail, and what it takes to use it responsibly in operational settings. It will cover practical lessons around agent reliability, hallucination, cost, human oversight, evidence and provenance, as well as deployment considerations such as private, sovereign and on-premise AI.

The session will offer a practical perspective on how OT security teams can adopt AI without compromising trust, control or operational resilience.
Executive Briefing · Main Ballroom
Modern ArchitectureTransformation
15:00–15:15
Coffee Break
15:15–16:45
Module 1: OT Cyber Range
Sharpen the technical side of OT cyber resilience in a safe, realistic environment — without deliberately attacking your own production systems. Make mistakes, investigate suspicious activity, test defensive measures and repeat until the right response becomes familiar. Over the 90-minute workshop, you'll work through a hands-on, step-by-step OT cyber incident investigation with full visibility into the network traffic, security logs and OT systems involved in the attack. You'll walk away able to investigate and respond, hands-on. MoU signing after the exercise.
Workshop · Main Ballroom
PeopleAccountability
Module 2: Predictive Resilience Exercise
Strengthen your decisions before the incident. Work through an evolving OT scenario alongside fellow practitioners, where information is incomplete and assumptions are put to the test. Build the judgement to recognise weak signals and act early — before disruption occurs. You'll walk away able to decide earlier, and with confidence.
Workshop · Small Room
PeopleAccountabilityCollaboration
16:45–17:15
From CVEs to ICS Tactics: Automated Mapping to MITRE ATT&CK for ICS
Daisuke Mashima — Mapping CVEs to MITRE ATT&CK techniques transforms vulnerability records into actionable threat intelligence by linking known weaknesses to potential adversarial behaviors. While automated CVE-to-ATT&CK mapping has been studied for enterprise IT, equivalent approaches for ICS remain limited despite the growing number of disclosed industrial vulnerabilities. This session introduces an LLM-based approach for automatically mapping ICS-related CVEs to MITRE ATT&CK for ICS techniques.
Workshop · Main Ballroom
IntelligenceModern Architecture
From Login Page to Engine Room
Karan Sajnani — Chaining vulnerabilities to reach maritime OT systems.
Technical Deep Dive · Track A
IntelligenceModern Architecture
17:15–17:45
OT-ISAC Member Sharing
Ronald Chan, Head of OT Security, Aboitiz Power

A member-led session bringing real-world perspectives from the OT community. Members share practical experiences, lessons learned, challenges encountered and approaches that have worked in strengthening OT cybersecurity and operational resilience.
Community Discussion · Main Ballroom
CollaborationIntelligence
17:45–18:00
Recognition of Advisory Committees and OT-ISAC Members
Awardees: EMA, Aboitiz Power, YTL PowerSeraya, PUB
Recognition · Main Ballroom
PeopleCollaboration
18:00–18:15
Closing Remarks
Mark Orsi, CEO, Global Resilience Federation
Closing · Main Ballroom
AccountabilityPeople
18:15–20:00
Networking Drinks
Ground Floor Bar
CollaborationPeople
OCTOBER 9 · OT-ISAC PICKLEFEST
BEYOND THE SUMMIT
PickleFest is a separate community experience focused on informal networking, relationship-building, friendly competition and continued conversations beyond the Summit programme.
PeopleCollaboration
EXPLORE PICKLEFEST

Programme and session timings are subject to change.

OUR COMMUNITY
Past Summits & Community Moments

From keynote stages to rooftop receptions — a glimpse of the people, energy, and connections that make OT-ISAC Summit special.

BEYOND THE SUMMIT
Friday
Pickle Fest 🏓

Swap your badge for a paddle. On Day 2, we take community spirit off the conference floor and onto the court.

Complimentary for all summit participants. Limited slots — register early!

9 OCT 2026
SINGAPORE
🏓
Pickleball Tournament
🤝
Informal Networking
🌏
Cross-sector Play
🎉
Community Bonding
OFFICIAL SPONSOR
DRAGOS
JOIN THE FEST →
GET YOUR TICKET
Ready to drive
IMPACT?
Join the OT security community in Singapore. Register your interest today.
ACCESS EXPERIENCE COMMUNITY DELEGATE
  • Summit Programme
  • Keynotes & expert sessions
  • Hands-on workshop
  • Networking Night
  • Complimentary Pickle Fest entry
Registration & Delegate Approval

Please note that OT-ISAC events have limited capacity. Registration does not automatically guarantee a delegate place.

To maintain a relevant and valuable audience, delegate applications may be reviewed based on role, organisation, industry relevance, and alignment with the intended event audience.

OT-ISAC and the Organiser reserve the right to approve or decline registrations at their discretion. Confirmed delegates will receive a registration confirmation by email.
ECOSYSTEM
Partners & Associations
Organisations and associations supporting OT-ISAC Summit 2026.
Become a Partner
Interested in sponsoring or partnering with OT-ISAC Summit 2026? Get in touch.
Reach out to events@otisac.org