The Schedule

What's On At BSides Downunder ICS 2026


28 Aug
-
5:30 pm

Networking Event and Registration

3 Hours
BSides Team
Rob M Lee

Join us for a Social Networking and fireside chat with CEO and co-founder of Dragos Robert M Lee.

Also, collect your conference badge to make things run nice and smooth on Saturday!

29 Aug
-
9:00 am

BSides ICS Downunder 2026 Opens!

10 Minutes
BSides Team

Welcome to BSides ICS Downunder 2026!

29 Aug
-
9:10 am

Responding to Legacy Commodity Malware in OT Environments

50 minutes
Lesley Carhart

As cybersecurity visibility and maturity increases across industrial environments, an increasing number of organisations are discovering long-term, pervasive legacy malware infections in their process environments. Despite temptation to respond drastically, dealing with these incidents requires a measured, careful response. In most cases, an immediate upgrade of all impacted Windows hosts is not feasible. Conversely, haphazard forensic and cleanup efforts can also be futile and even cause a process disruption. Unfortunately, even infections that have been in place for a decade can eventually cause network and computing equipment to degrade in performance and fail in unpredictable ways. Commodity malware isn't a problem to be ignored, or respond to without careful forethought. This presentation will convey practical lessons learned for evaluating, scoping, and making practical decisions to ensure the safety and reliability of impacted process networks.

29 Aug
-
10:00 am

Your OT Security Program Isn’t Working

40 minutes
Dr Christopher Beggs

Industrial cyber security programs often fail even after substantial investment not because organisations don’t care, but because the approach is wrong. Environments that look secure on paper can remain dangerously exposed in practice: dashboards show green, audits are passed, and major tools are deployed, yet critical weaknesses persist beneath the surface.  These include blanket controls, fragmented ownership, poor sequencing, and weak alignment between business priorities and security decisions.

In many cases, the problem isn’t a lack of controls it’s that the controls don’t reflect how OT environments actually operate. This talk breaks down a practical six-step approach to planning, governing, delivering, and measuring OT security uplift. It is built around six principles: Be Business-Driven, Make Risk-Based Decisions, Take an Enterprise-Wide View, Work Methodically, Stay OT-Centric, and Stay Assurance-Focused. Together, they provide a structured way to improve security in real operating environments, rather than treating OT security as a collection of disconnected technical activities.

The session draws on patterns seen repeatedly across industrial programs. It anchors decisions in operational and business consequences not technical preference. It prioritises effort where failure would have the greatest impact. It scales across sites and functions to remove silos and blind spots. Most importantly, it addresses a common failure point: organisations often do the right things but in the wrong order leading to gaps, rework, and false confidence.

The approach keeps decisions OT-specific and treats assurance as evidence that controls actually work under real conditions not just on paper.

Strong OT security isn’t defined by more controls, more certifications, or more tools. It’s defined by the consistent ability to protect operations in the real world.

This isn’t about doing more it’s about doing the right things, in the right order, for the right reasons

29 Aug
-
10:45 am

Morning Break

30 minutes
BSides Team

Morning Break

29 Aug
-
11:15 am

The Tabletop Starts Before Game Day: Lessons from Planning Exercises That Actually Work

40 minutes
Gyle dela Cruz

Everyone loves talking about tabletop exercises. Almost nobody talks about the work that happens beforehand.

Choosing the right scenario. Defining success. Finding the right participants. Writing injects that challenge without derailing the exercise. Managing personalities, competing priorities, and unrealistic expectations. The planning phase is where tabletop exercises are won or quietly doomed.

In this session, I'll pull back the curtain on what goes into preparing a cyber tabletop exercise, sharing practical advice and lessons learned from real exercises. Through stories of unexpected challenges, planning mistakes, and surprising successes, we'll explore what makes an exercise memorable for the right reasons.

Attendees will leave with a practical framework for planning tabletop exercises, common pitfalls to avoid, and ideas for creating exercises that generate meaningful discussion instead of awkward silence.

29 Aug
-
12:00 pm

Securing DNP3 a Better Way

40 minutes
Andrew West

DNP3 is taking a new approach to securing SCADA messaging! This new method separates device identity from authorisation to communicate. It simplifies activities such as centrally managing and enforcing Role or Attribute Based Access and replacing failed devices... And it's post-quantum safe! Come and hear why this this better and easier than traditional methods such as using TLS.

29 Aug
-
12:45 pm

Lunch Break

1 hour
BSides Team

1 Hour Lunch Break.

Note - Lunch is not provided by BSides ICS Downunder.

29 Aug
-
1:45 pm

Let's Build an Actionable and Threat-Led ICS Threat Model

40 minutes
Heath Moodie

The volume and technical requirements for organisations to action Cyber Threat Intelligence (CTI) has grown exponentially, especially for Critical National Infrastructure(CNI) organisations. Overwhelmed by corporate & intelligence jargon, AI buzzwords, and endless streams of Indicators of Compromise (IOCs), we often forget that CTI is a capability meant to solve real problems, not just a tool. Furthermore, tracking specific threat actors often forces analysts to collect trivia rather than produce actionable intelligence. It is time for a new approach.

In this interactive, workshop-style presentation, attendees will be guided on a collaborative journey to create a simple, highly actionable threat model tailored to the most relevant threats facing Australian ICS operators. We will strip away complex intelligence jargon and translate cyber threats directly into the governance, risk, and impact language that business and Cyber leaders care about most.

This session is designed to put decision-makers in a position to succeed by focusing on practical application rather than theory.

Note - this will be an Interactive Workshop format event.

29 Aug
-
2:30 pm

OT Range in the Backyard

40 minutes
Christian Azuero

Most OT security training occurs in two ways: costly commercial cyber ranges that few people can access, or free virtual testbeds that mimic protocols but not physical processes. Neither option allows learners to see how a poor PLC decision can actually drain a battery, trip a relay, or cause a historian to fail. This talk focuses on bridging that gap with a range built in an actual backyard.

I will explain the OT Cyber Range: a real off-grid solar setup that generates and stores actual power. It is designed with a fully segmented Purdue Level 0 to Level 5 architecture, including field devices, a PLC, a supervisory layer, an Industrial DMZ, and a cloud-hosted detection layer. Academic testbeds like SWaT and EPIC have shown how valuable physical process fidelity is for research. This project explores what this looks like when scaled down to something a single person can build in their backyard for a few thousand dollars.

The session will cover three key takeaways for attendees. First is the architecture itself: how each Purdue level was implemented using real (not simulated) hardware, and the firewall logic that maintains the IDMZ’s integrity by ensuring no inbound connection exists from IT to OT. Second is the detection engineering: how field-layer telemetry turns into KQL analytic rules mapped to MITRE ATT&CK for ICS, and what it looks like when a rule activates in response to a live attack on the physical process instead of a synthetic dataset. Third is the practical and financial aspects of accomplishing this at home, including choices of components, costs, mistakes made, and safety measures that prevented it from becoming a fire hazard or electrical issue.

The goal is not to sell a product or course; instead, it is to provide the audience with a replicable blueprint. Attendees will leave with a clear understanding of what it takes to build a small, functional, physical OT range for training or research and which design decisions are most important when the ""plant"" consists of real hardware rather than a Docker container.

29 Aug
-
3:15 pm

Afternoon Break

15 minutes
BSides Team

Afternoon break

29 Aug
-
3:30 pm

Monitoring in ICS and what we all do wrong

40 minutes
Chris Henne

When implementing a monitoring solution, we want to monitor everything. More data equal better decisions, right? So, every box is pointed at the monitoring solution and gigabytes upon gigabytes a day of logs are collected. We now have heaps of data, but what are we doing with it? How do we create value from the collection of data we have? When looking for a needle in a haystack, does adding more hay help or hinder the search? We need to ask questions of our data (analysis), learn something new based on the questions (insight) and then do something based on what we learned (action). Turning data into action is hard. What if we start with an action we would make and then look for the right data that tells us to act, wouldn't this be a smarted approach?

29 Aug
-
4:15 pm

Beyond Backups: A Practitioner's Approach to OT Disaster Recovery

40 minutes
Mike Hoffman

Most OT disaster recovery plans stop at "restore from backup." For industrial environments, that's not a plan, it's a hope. When a cyber incident takes down a PLC, DCS, or SCADA-based system, recovery isn't an IT restore job. It's a sequenced, dependency-aware process with real process-safety implications, with an MTD measured in minutes to hours, not days.

This talk walks through a practical, threat-informed framework for OT DR, from mapping cyber attack scenarios to shutdown levels, through dependency analysis, RTO/RPO sequencing, and reconstitution of the production process itself. Based on real-world experience in OT environments, attendees will leave with a structured approach they can take back and apply.