Preliminary Agenda - Melbourne
times and content subject to change
| Wednesday, August 26, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 8:15 AM - 8:50 AM | Registration & Breakfast | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 9:00 AM - 9:15 AM | Welcome & Opening Remarks Hayley Turner, VP, APAC Sales | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 9:15 AM - 10:00 AM | Regional Threat Landscape: What You're Facing & How Governments are Responding This session provides a grounded view of the current OT cyber threat landscape, combining regional adversary activity with the regulatory and compliance pressure shaping industrial security programs. Attendees will learn how threat groups are targeting critical OT infrastructure, how those risks manifest across industries, and how governments are responding through evolving policies, standards, and enforcement. The session connects threat activity to regulatory expectations, helping attendees understand not just what they are up against, but how requirements are shifting in response. Robert M. Lee, Co-Founder & CEO | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 10:00 AM - 10:30 AM | From Global Threats to Local Impact: OT Risk in the APAC Context Building on the regional threat landscape Rob Lee sets out, this session brings the picture sharply into focus for the APAC region. They move from the global view to the ground truth, drawing on real adversary activity observed across the region and the case studies that reveal how those threats actually play out inside industrial environments. Attendees will get an unflinching look at the specific threat groups and campaigns targeting OT in APAC, including emerging XOT (cross-domain IT/OT) threats, and the operational consequences when defenses fall short. Where the preceding session frames what's coming and how governments are responding, this one shows what it looks like when it lands close to home — turning abstract risk into concrete, sometimes uncomfortable, lessons that defenders can act on. Lesley Carhart, Principal Industrial Incident Responder Nicholas Tangey, Senior Manager, OT Threat Hunting | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 10:30 AM - 11:00 AM | Networking Break | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 11:00 AM - 11:45 AM | From Compliance to Capability: Mapping IEC 62443 and Regional Mandates to the SANS Five ICS Critical Controls In this session, SANS Fellow Tim Conway — Technical Director of the SANS ICS and SCADA programs and co-author, with Robert M. Lee, of the Five ICS Cybersecurity Critical Controls — shows practitioners how to bridge the gap between regulatory compliance and genuine operational security. Drawing on analysis of real-world attacks against critical infrastructure, Conway demonstrates how requirements spanning IEC 62443 and various industry and regional regulations map directly onto the SANS 5 Critical Controls: an ICS-specific incident response plan, defensible architecture, network visibility and monitoring, secure remote access, and risk-based vulnerability management. Attendees will learn how to "ladder up" from foundational principles to practical implementation, building a compliance strategy that strengthens their security posture and protects safety and operational continuity rather than simply checking regulatory boxes. Tim Conway, SANS Fellow & Technical Director of the SANS ICS & SCADA Program | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 11:45 AM - 12:45 PM | OT Maturity: Benchmarking Your Journey With a clear picture of the threat landscape in place, this session turns to the question of program readiness. Attendees work through a structured self-assessment of their OT cybersecurity program against the SANS ICS 5 Critical Controls. Starting with a practical overview of the Five Critical Controls and the OT Maturity framework, participants will benchmark where their program stands today. The goal is give you an honest picture of where progress is being made, where gaps exist, and what to prioritise next — and a foundation for the sessions that follow, where those insights will be put to work. Rowan Macfarlane, Senior Manager, Consulting | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 12:45 PM - 1:45 PM | Networking Lunch | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 1:45 PM - 2:30 PM | Real Clients. Real OT Journeys. Warts & All Hear directly from Dragos customers as they share their OT cybersecurity journey—the challenges they faced, the lessons they learned, and the successes they achieved along the way. This candid discussion and live Q&A delivers real-world insights into securing industrial environments, with practical takeaways from organisations that have navigated the complexities of OT security firsthand. Moderated by Volven D'Souza, Director - CX APAC | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 2:30 PM - 3:00 PM | Government Panel Moderated by Hayley Turner, VP APAC Sales | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3:00 PM - 3:30 PM | Networking Break | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3:30 PM - 3:55 PM | The Camera That Encrypted the Network: Inside an Akira Attack on xOT When EDR blocked Akira on the servers, the affiliate didn't give up — it pivoted to an unmanaged IP camera, mounted the company's file shares to it, and ran the encryption from a device no one was watching. This session walks the kill chain step by step, then asks the uncomfortable question - does your security program reflect the environment you're actually running? We'll show how Dragos and Phosphorus now close the gap that made this attack possible. Alex Nehmy, Regional CTO | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3:55 PM - 4:50 PM | The Dragos Platform: Built for the Realities of OT Environments Whether you are building the foundations of your OT security program or looking to accelerate an established one, this session takes participants inside the Dragos Platform to explore its purpose-built capabilities for OT environments. Attendees will see how the platform turns raw industrial data into actionable intelligence, powered by the Dragos Intelligence Fabric and how new AI capabilities help security teams investigate threats faster and prioritize with confidence. The session closes with a forward look at the product roadmap and where the platform is headed to meet the evolving requirements of securing OT infrastructure. Nick Shaw, VP, Product | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 4:50 PM - 5:15 PM | When the Cost of Doing Northing Becomes Calculable - Fireside Chat - Rob Lee & Marsh For years, OT cybersecurity has lived in the grey zone between technical risk and business consequence. That changes here. In this session, Dragos CEO Robert M. Lee and Marsh McLennan's Cyber Risk Intelligence Centre bring together threat intelligence and a decade of insurance claims data to put a dollar figure on what's at stake — and a clear framework for what to do about it. This is not a conversation about whether OT risk is real. It's a conversation about how much it costs, why most organisations are less prepared than they think, and what the SANS ICS 5 Critical Controls can do — measurably — to change that equation. Robert M. Lee, Co-Founder & CEO | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 5:15 PM - 5:30 PM | Open Q&A Session Open Q&A session with speakers from the day. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 5:30 PM - 6:15 PM | Optional - Inside Tour of MCG - register at registration desk by lunchtime | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 6:30 PM - 9:00 PM | Networking Event at Australian Sports Museum, MCG hosted by Dragos & SANS | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thursday, August 27, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 9:00 AM - 11:00 AM | Business Stream: Dragos Capability Showcase | Technical Stream: Implementing OT Cyber Workshop | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 11:15 AM - 1:15 PM | Business Stream Benchmarking Deep Dive | Technical Stream: Scenario based Platform Training | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 1:15 PM - 2:15 PM | Networking Lunch | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 2:00 PM - 5:00 PM | Technical Stream : SANS hosted Table Top Exercise Join a hands-on tabletop exercise led by SANS Institute on Day 2 of the Forum led by Tim Conway. This interactive session is designed for technical practitioners, as well as senior leaders, operational planners, and communications stakeholders, and will walk participants through a realistic OT cyber incident scenario, challenging you to assess, respond, and make critical decisions in real time. Guided by SANS experts, you’ll gain practical experience in incident response, strengthen your understanding of OT-specific threats, and explore how different functions coordinate during a crisis, leaving with actionable insights to enhance your organisation’s security posture. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||

COPYRIGHT © 2026 DRAGOS, INC., ALL RIGHTS RESERVED.
For information about how we collect, use, share or otherwise process information about you, please see our privacy policy.