Preliminary Agenda - Melbourne
times and content subject to change
| Wednesday, August 26, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 8:15 AM - 8:50 AM | Registration & Breakfast | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 9:00 AM - 9:15 AM | Welcome & Opening Remarks Hayley Turner, VP, APAC Sales | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 9:15 AM - 10:00 AM | Regional Threat Landscape: What You're Facing & How Governments are Responding This session provides a grounded view of the current OT cyber threat landscape, combining regional adversary activity with the regulatory and compliance pressure shaping industrial security programs. Attendees will learn how threat groups are targeting critical OT infrastructure, how those risks manifest across industries, and how governments are responding through evolving policies, standards, and enforcement. The session connects threat activity to regulatory expectations, helping attendees understand not just what they are up against, but how requirements are shifting in response. Robert M. Lee, Co-Founder & CEO | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 10:00 AM - 10:30 AM | From Global Threats to Local Impact: OT Risk in the APAC Context Building on the regional threat landscape Rob Lee sets out, this session brings the picture sharply into focus for the APAC region. They move from the global view to the ground truth, drawing on real adversary activity observed across the region and the case studies that reveal how those threats actually play out inside industrial environments. Attendees will get an unflinching look at the specific threat groups and campaigns targeting OT in APAC, including emerging XOT (cross-domain IT/OT) threats, and the operational consequences when defenses fall short. Where the preceding session frames what's coming and how governments are responding, this one shows what it looks like when it lands close to home — turning abstract risk into concrete, sometimes uncomfortable, lessons that defenders can act on. Lesley Carhart, Principal Industrial Incident Responder Nicholas Tangey, Senior Manager, OT Threat Hunting | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 10:30 AM - 11:00 AM | Networking Break | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 11:00 AM - 11:45 AM | Inside the Five ICS Cybersecurity Critical Controls: Origins and Field Reality
In this session, SANS Fellow Tim Conway walks through the Five ICS Cybersecurity Critical Controls from the ground up. As SANS ICS Curriculum Lead and co-author of the controls with Robert M. Lee, he explains why they were created, what each one means, and the implementation diversity you should expect. Tim shows how analysis of real-world attacks against critical infrastructure exposed a consistent set of gaps, and how that evidence shaped the five controls that matter most: an ICS-specific incident response plan, a defensible architecture, ICS network visibility and monitoring, secure remote access, and risk-based vulnerability management. He breaks down what each control requires in an OT environment and where operators most often fall short. Tim Conway, SANS Fellow & Technical Director of the SANS ICS & SCADA Program | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 11:45 AM - 12:45 PM | OT Maturity: Benchmarking Your Journey With a clear picture of the threat landscape in place, this session turns to the question of program readiness. Attendees work through a structured self-assessment of their OT cybersecurity program against the SANS ICS 5 Critical Controls. Starting with a practical overview of the Five Critical Controls and the OT Maturity framework, participants will benchmark where their program stands today. The goal is give you an honest picture of where progress is being made, where gaps exist, and what to prioritise next — and a foundation for the sessions that follow, where those insights will be put to work. Rowan Macfarlane, Senior Manager, Consulting | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 12:45 PM - 1:45 PM | Networking Lunch | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 1:45 PM - 2:30 PM | Real Clients. Real OT Journeys. Warts & All Hear directly from Dragos customers as they share their OT cybersecurity journey—the challenges they faced, the lessons they learned, and the successes they achieved along the way. This candid discussion and live Q&A delivers real-world insights into securing industrial environments, with practical takeaways from organisations that have navigated the complexities of OT security firsthand. Moderated by Volven D'Souza, Director - CX APAC | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 2:30 PM - 3:00 PM | Government Panel Moderated by Hayley Turner, VP APAC Sales | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3:00 PM - 3:30 PM | Networking Break | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3:30 PM - 3:55 PM | The Camera That Encrypted the Network: Inside an Akira Attack on xOT When EDR blocked Akira on the servers, the affiliate didn't give up — it pivoted to an unmanaged IP camera, mounted the company's file shares to it, and ran the encryption from a device no one was watching. This session walks the kill chain step by step, then asks the uncomfortable question - does your security program reflect the environment you're actually running? We'll show how Dragos and Phosphorus now close the gap that made this attack possible. alex nehmy, field CTO | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3:55 PM - 4:50 PM | The Dragos Platform: Built for the Realities of OT Environments Whether you are building the foundations of your OT security program or looking to accelerate an established one, this session takes participants inside the Dragos Platform to explore its purpose-built capabilities for OT environments. Attendees will see how the platform turns raw industrial data into actionable intelligence, powered by the Dragos Intelligence Fabric and how new AI capabilities help security teams investigate threats faster and prioritize with confidence. The session closes with a forward look at the product roadmap and where the platform is headed to meet the evolving requirements of securing OT infrastructure. Nick Shaw, VP, Product | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 4:50 PM - 5:15 PM | When the Cost of Doing Nothing Becomes Calculable - Fireside Chat - Rob Lee & Marsh For years, OT cybersecurity has lived in the grey zone between technical risk and business consequence. That changes here. In this session, Dragos CEO Robert M. Lee and Marsh McLennan's Cyber Risk Intelligence Centre bring together threat intelligence and a decade of insurance claims data to put a dollar figure on what's at stake — and a clear framework for what to do about it. This is not a conversation about whether OT risk is real. It's a conversation about how much it costs, why most organisations are less prepared than they think, and what the SANS ICS 5 Critical Controls can do — measurably — to change that equation. Robert M. Lee, Co-Founder & CEO | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 5:15 PM - 5:30 PM | Open Q&A Session Open Q&A session with speakers from the day. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 5:30 PM - 6:15 PM | Optional - Inside Tour of MCG - register at registration desk by lunchtime | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 6:30 PM - 9:00 PM | Networking Event at Australian Sports Museum, MCG hosted by Dragos & SANS | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Thursday, August 27, 2026 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 9:00 AM - 11:00 AM | Technical Stream: Implementing OT Cyber Workshop | Business Stream: Dragos Capability Showcase | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 11:15 AM - 1:15 PM | Business Stream Benchmarking Deep Dive | Technical Stream: Scenario based Platform Training | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 1:15 PM - 2:15 PM | Networking Lunch | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 2:00 PM - 5:00 PM | Technical Stream : SANS hosted Table Top Exercise Join a hands-on tabletop exercise led by SANS Institute on Day 2 of the Forum led by Tim Conway. This interactive session is designed for technical practitioners, as well as senior leaders, operational planners, and communications stakeholders, and will walk participants through a realistic OT cyber incident scenario, challenging you to assess, respond, and make critical decisions in real time. Guided by SANS experts, you’ll gain practical experience in incident response, strengthen your understanding of OT-specific threats, and explore how different functions coordinate during a crisis, leaving with actionable insights to enhance your organisation’s security posture. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||

COPYRIGHT © 2026 DRAGOS, INC., ALL RIGHTS RESERVED.
For information about how we collect, use, share or otherwise process information about you, please see our privacy policy.