What's On At BSides Downunder ICS 2026
28 Aug-5:30 pmNetworking Event and Registration
3 HoursBSides TeamRob M Lee
Networking Event and Registration
Join us for a Social Networking and fireside chat with CEO and co-founder of Dragos Robert M Lee.
Also, collect your conference badge to make things run nice and smooth on Saturday!
29 Aug-9:00 amBSides ICS Downunder 2026 Opens!
10 MinutesBSides Team
BSides ICS Downunder 2026 Opens!
Welcome to BSides ICS Downunder 2026!
29 Aug-9:10 amResponding to Legacy Commodity Malware in OT Environments
50 minutesLesley Carhart
Responding to Legacy Commodity Malware in OT Environments
As cybersecurity visibility and maturity increases across industrial environments, an increasing number of organisations are discovering long-term, pervasive legacy malware infections in their process environments. Despite temptation to respond drastically, dealing with these incidents requires a measured, careful response. In most cases, an immediate upgrade of all impacted Windows hosts is not feasible. Conversely, haphazard forensic and cleanup efforts can also be futile and even cause a process disruption. Unfortunately, even infections that have been in place for a decade can eventually cause network and computing equipment to degrade in performance and fail in unpredictable ways. Commodity malware isn't a problem to be ignored, or respond to without careful forethought. This presentation will convey practical lessons learned for evaluating, scoping, and making practical decisions to ensure the safety and reliability of impacted process networks.
29 Aug-10:00 amYour OT Security Program Isn’t Working
40 minutesDr Christopher Beggs
Your OT Security Program Isn’t Working
Industrial cyber security programs often fail even after substantial investment not because organisations don’t care, but because the approach is wrong. Environments that look secure on paper can remain dangerously exposed in practice: dashboards show green, audits are passed, and major tools are deployed, yet critical weaknesses persist beneath the surface. These include blanket controls, fragmented ownership, poor sequencing, and weak alignment between business priorities and security decisions.
In many cases, the problem isn’t a lack of controls it’s that the controls don’t reflect how OT environments actually operate. This talk breaks down a practical six-step approach to planning, governing, delivering, and measuring OT security uplift. It is built around six principles: Be Business-Driven, Make Risk-Based Decisions, Take an Enterprise-Wide View, Work Methodically, Stay OT-Centric, and Stay Assurance-Focused. Together, they provide a structured way to improve security in real operating environments, rather than treating OT security as a collection of disconnected technical activities.
The session draws on patterns seen repeatedly across industrial programs. It anchors decisions in operational and business consequences not technical preference. It prioritises effort where failure would have the greatest impact. It scales across sites and functions to remove silos and blind spots. Most importantly, it addresses a common failure point: organisations often do the right things but in the wrong order leading to gaps, rework, and false confidence.
The approach keeps decisions OT-specific and treats assurance as evidence that controls actually work under real conditions not just on paper.
Strong OT security isn’t defined by more controls, more certifications, or more tools. It’s defined by the consistent ability to protect operations in the real world.
This isn’t about doing more it’s about doing the right things, in the right order, for the right reasons
29 Aug-10:45 amMorning Break
30 minutesBSides Team
Morning Break
Morning Break
29 Aug-11:15 amThe Tabletop Starts Before Game Day: Lessons from Planning Exercises That Actually Work
40 minutesGyle dela Cruz
The Tabletop Starts Before Game Day: Lessons from Planning Exercises That Actually Work
Everyone loves talking about tabletop exercises. Almost nobody talks about the work that happens beforehand.
Choosing the right scenario. Defining success. Finding the right participants. Writing injects that challenge without derailing the exercise. Managing personalities, competing priorities, and unrealistic expectations. The planning phase is where tabletop exercises are won or quietly doomed.
In this session, I'll pull back the curtain on what goes into preparing a cyber tabletop exercise, sharing practical advice and lessons learned from real exercises. Through stories of unexpected challenges, planning mistakes, and surprising successes, we'll explore what makes an exercise memorable for the right reasons.
Attendees will leave with a practical framework for planning tabletop exercises, common pitfalls to avoid, and ideas for creating exercises that generate meaningful discussion instead of awkward silence.
29 Aug-12:00 pmSecuring DNP3 a Better Way
40 minutesAndrew West
Securing DNP3 a Better Way
DNP3 is taking a new approach to securing SCADA messaging! This new method separates device identity from authorisation to communicate. It simplifies activities such as centrally managing and enforcing Role or Attribute Based Access and replacing failed devices... And it's post-quantum safe! Come and hear why this this better and easier than traditional methods such as using TLS.
29 Aug-12:45 pmLunch Break
1 hourBSides Team
Lunch Break
1 Hour Lunch Break.
Note - Lunch is not provided by BSides ICS Downunder.
29 Aug-1:45 pmLet's Build an Actionable and Threat-Led ICS Threat Model
40 minutesHeath Moodie
Let's Build an Actionable and Threat-Led ICS Threat Model
The volume and technical requirements for organisations to action Cyber Threat Intelligence (CTI) has grown exponentially, especially for Critical National Infrastructure(CNI) organisations. Overwhelmed by corporate & intelligence jargon, AI buzzwords, and endless streams of Indicators of Compromise (IOCs), we often forget that CTI is a capability meant to solve real problems, not just a tool. Furthermore, tracking specific threat actors often forces analysts to collect trivia rather than produce actionable intelligence. It is time for a new approach.
In this interactive, workshop-style presentation, attendees will be guided on a collaborative journey to create a simple, highly actionable threat model tailored to the most relevant threats facing Australian ICS operators. We will strip away complex intelligence jargon and translate cyber threats directly into the governance, risk, and impact language that business and Cyber leaders care about most.
This session is designed to put decision-makers in a position to succeed by focusing on practical application rather than theory.
Note - this will be an Interactive Workshop format event.
29 Aug-2:30 pmOT Range in the Backyard
40 minutesChristian Azuero
OT Range in the Backyard
Most OT security training occurs in two ways: costly commercial cyber ranges that few people can access, or free virtual testbeds that mimic protocols but not physical processes. Neither option allows learners to see how a poor PLC decision can actually drain a battery, trip a relay, or cause a historian to fail. This talk focuses on bridging that gap with a range built in an actual backyard.
I will explain the OT Cyber Range: a real off-grid solar setup that generates and stores actual power. It is designed with a fully segmented Purdue Level 0 to Level 5 architecture, including field devices, a PLC, a supervisory layer, an Industrial DMZ, and a cloud-hosted detection layer. Academic testbeds like SWaT and EPIC have shown how valuable physical process fidelity is for research. This project explores what this looks like when scaled down to something a single person can build in their backyard for a few thousand dollars.
The session will cover three key takeaways for attendees. First is the architecture itself: how each Purdue level was implemented using real (not simulated) hardware, and the firewall logic that maintains the IDMZ’s integrity by ensuring no inbound connection exists from IT to OT. Second is the detection engineering: how field-layer telemetry turns into KQL analytic rules mapped to MITRE ATT&CK for ICS, and what it looks like when a rule activates in response to a live attack on the physical process instead of a synthetic dataset. Third is the practical and financial aspects of accomplishing this at home, including choices of components, costs, mistakes made, and safety measures that prevented it from becoming a fire hazard or electrical issue.
The goal is not to sell a product or course; instead, it is to provide the audience with a replicable blueprint. Attendees will leave with a clear understanding of what it takes to build a small, functional, physical OT range for training or research and which design decisions are most important when the ""plant"" consists of real hardware rather than a Docker container.
29 Aug-3:15 pmAfternoon Break
15 minutesBSides Team
Afternoon Break
Afternoon break
29 Aug-3:30 pmMonitoring in ICS and what we all do wrong
40 minutesChris Henne
Monitoring in ICS and what we all do wrong
When implementing a monitoring solution, we want to monitor everything. More data equal better decisions, right? So, every box is pointed at the monitoring solution and gigabytes upon gigabytes a day of logs are collected. We now have heaps of data, but what are we doing with it? How do we create value from the collection of data we have? When looking for a needle in a haystack, does adding more hay help or hinder the search? We need to ask questions of our data (analysis), learn something new based on the questions (insight) and then do something based on what we learned (action). Turning data into action is hard. What if we start with an action we would make and then look for the right data that tells us to act, wouldn't this be a smarted approach?
29 Aug-4:15 pmBeyond Backups: A Practitioner's Approach to OT Disaster Recovery
40 minutesMike Hoffman
Beyond Backups: A Practitioner's Approach to OT Disaster Recovery
Most OT disaster recovery plans stop at "restore from backup." For industrial environments, that's not a plan, it's a hope. When a cyber incident takes down a PLC, DCS, or SCADA-based system, recovery isn't an IT restore job. It's a sequenced, dependency-aware process with real process-safety implications, with an MTD measured in minutes to hours, not days.
This talk walks through a practical, threat-informed framework for OT DR, from mapping cyber attack scenarios to shutdown levels, through dependency analysis, RTO/RPO sequencing, and reconstitution of the production process itself. Based on real-world experience in OT environments, attendees will leave with a structured approach they can take back and apply.
