10.00 – 10.25 uur

From Regulation to Risk: Cyber Resilience in the Process Industry

Rob Everink, Process Control Lead at OCI Nitrogen, will discuss the challenges of implementing NIS2 and the potential impact of the Cyber Resilience Act (CRA) within his organisation. How do you balance regulatory requirements and risk in the process industry, where legacy systems are still common? NIS2, the CRA and IEC 62443 all aim to strengthen cyber resilience, but what does this mean in practice – and at what cost?

Spreker: Rob Everink, Process Control Lead bij OCI Nitrogen

Dit seminar zal in het Engels gegeven worden.

10.25 – 10.50 uur

Slimme fabriek, slimme aanvaller.

AI is hoogstwaarschijnlijk al onderdeel van jouw OT. Voorspellend onderhoud (predictive maintenance), beeldherkenning, een copiloot die PLC-code voorstelt. Tegelijk waarschuwden vijf Amerikaanse overheidsdiensten deze zomer voor aanvallers die met AI-gegenereerde scripts op Siemens S7-controllers jagen. Hoe ga je veilig met AI om in een OT omgeving en hoe wapen je de OT omgeving tegen aanvallen die met of door AI worden uitgevoerd? In deze sessie geeft Matthijs van der Wel – ter Weel, strategisch adviseur bij Orange Cyberdefense antwoord op deze vragen. Geen securityjargon, geen verkoop show, wel zeven concrete adviezen.

Spreker: Matthijs van der Wel-ter Weel, Strategic Advisor bij Orange Cyber Defense

10.50 – 11.15 uur

Responding to a Major NIS2-Regulated OT Cyber Incident

Join us for a 20-minute seminar where we will walk through the response to a significant cyber incident at a large European production, processing, and distribution organisation employing over 22,000 staff and operating critical OT environments.

We will examine how attackers exploited a critical SAP zero-day vulnerability (CVE-2025-31324), established persistence, moved laterally into a central production domain, and created a situation that threatened essential production operations. The session will cover the difficult decision to isolate an OT-supported production environment, the impact of limited monitoring visibility, and how enhanced detection capabilities enabled the rapid restoration of operations.

In addition to the technical response, we will discuss the practical implications of NIS2 regulation, including incident reporting considerations, stakeholder communication, and balancing operational continuity against the need for effective containment.

Key takeaways:

  • Lessons learned from responding to a large-scale OT cyber incident
  • Managing containment decisions in production-critical environments
  • Addressing monitoring gaps during active incident response
  • Supporting regulatory obligations under NIS2
  • Strategies for restoring operations while maintaining security oversight

This session is ideal for security leaders, incident responders, OT security professionals, and risk and compliance stakeholders from end-users and machine builders looking to better understand the intersection of cyber incident response, operational resilience, and regulatory requirements

Spreker: Marcel Hulsen, Orange Cyberdefense & Klaas Wijbenga, Weidmüller

Dit seminar zal in het Engels gegeven worden.

FHI, federatie van technologiebranches