10.00 – 10.25 am

From Regulation to Risk: Cyber Resilience in the Process Industry

Rob Everink, Process Control Lead at OCI Nitrogen, will discuss the challenges of implementing NIS2 and the potential impact of the Cyber Resilience Act (CRA) within his organization. How do you balance regulatory requirements and risk in the process industry, where legacy systems are still common? NIS2, the CRA and IEC 62443 all aim to strengthen cyber resilience, but what does this mean in practice – and at what cost?

Speaker: Rob Everink, Process Control Lead at OCI Nitrogen

This seminar will be held in English.

10:25 – 10:50

Smart factory, smart attacker.

AI is most likely already part of your OT. Predictive maintenance, image recognition, a co-pilot suggesting PLC code. At the same time, five US government agencies warned this summer about attackers targeting Siemens S7 controllers with AI-generated scripts. How do you handle AI safely in an OT environment, and how do you arm the OT environment against attacks carried out with or by AI? In this session, Matthijs van der Wel – ter Weel, Strategic Advisor at Orange Cyberdefense, answers these questions. No security jargon, no sales pitch, just seven concrete pieces of advice.

Speaker: Matthijs van der Wel-ter Weel, Strategic Advisor at Orange Cyber Defense

10:50 – 11:15

Responding to a Major NIS2-Regulated OT Cyber Incident

Join us for a 20-minute seminar where we will walk through the response to a significant cyber incident at a large European production, processing, and distribution organization employing over 22,000 staff and operating critical OT environments.

We will examine how attackers exploited a critical SAP zero-day vulnerability (CVE-2025-31324), established persistence, moved laterally into a central production domain, and created a situation that threatened essential production operations. The session will cover the difficult decision to isolate an OT-supported production environment, the impact of limited monitoring visibility, and how enhanced detection capabilities enabled the rapid restoration of operations.

In addition to the technical response, we will discuss the practical implications of NIS2 regulation, including incident reporting considerations, stakeholder communication, and balancing operational continuity against the need for effective containment.

Key takeaways:

  • Lessons learned from responding to a large-scale OT cyber incident
  • Managing containment decisions in production-critical environments
  • Addressing monitoring gaps during active incident response
  • Supporting regulatory obligations under NIS2
  • Strategies for restoring operations while maintaining security oversight

This session is ideal for security leaders, incident responders, OT security professionals, and risk and compliance stakeholders from end-users and machine builders looking to better understand the intersection of cyber incident response, operational resilience, and regulatory requirements

Speaker: Marcel Hulsen, Orange Cyberdefense & Klaas Wijbenga, Weidmüller

This seminar will be held in English.

FHI, federatie van technologiebranches