After the success of the first Ibero-American Industrial Cybersecurity Congresses held in Madrid (Spain) on October 2nd and 3rd, 2013, and in Bogotá (Colombia) on 27th and 28th May 2014, with almost 350 attendees from different sectors of the industry, that have become the most relevant international reference in industrial cybersecurity, the Industrial Cybersecurity Center (CCI) organizes the III Ibero-American Industrial Cybersecurity Congress, as a reference event for the Spanish speaking market of industrial cybersecurity, and as a meeting point for interchange of knowledge and experiences and for building relationships among every stakeholder in this environment.
This third edition will be held in Hotel Meliá Avda. de América in Madrid (Spain) with pre and post congress workshops intended to supplement the addressed topics.
First level international speakers will be presenting the state of the art, experiences and case studies about Industrial Cybersecurity from all over the world (USA, Latin-America, The Netherlands, Middle East or Japan, among others). All actors will be represented: industrial and cybersecurity vendors, engineering and EPC companies, consultants, integrators, end-users and critical infrastructures will be in Madrid discussing their different perceptions of today’s Industrial Cybersecurity reality.
The Congress is the best opportunity to know the last news, updates and experiences from the international leaders in each area and to establish valuable relationships that enable the collaboration with key national and international organizations.
Simultaneous translation service will be available during the congress. All presentations and contents will be available after the event through exclusive recordings for attendees.
Samuel Linares is Director at Industrial Cybersecurity Center, European Commission Independent Evaluator, ENISA (European Network and Information Security Agency) CIIP Expert and member of ISACA Cybersecurity Task Force. With 2 decades of security, system integration and multinational and multicultural projects management experience, he has been the main promoter of the “Industrial Cybersecurity” concept in Spanish, being recognized as one of the key Spanish and Latin-american experts in the area and participating as speaker, chairman and teacher in different events all over the world (including Spain, UK, USA, Belgium, Qatar, United Arab Emirates, Mexico, Cuba or Argentina, among others).
He holds various cybersecurity certifications including GICSP (Global Industrial Cyber Security Professional), CRISC (Certified in Risk and Information Systems Control), CGEIT (Certified in Governance of Enterprise IT), CISM (Certified Information Security Manager), CISA (Certified Information Security Auditor), CISSP (Certified Information Systems Security Professional), GIAC Assessing Wireless Networks (GAWN), Systems and Network Auditor (GSNA), and Google Hacking & Defense (SSP-GHD), BSI BS 25999 & BS 7799 Lead Auditor (since 2002), and several additional vendor specific technical certifications. He holds a B.S. in Computer Science from the Univ. de Oviedo and is University Specialist in Data Protection by the Colegio Universitario Escorial Maria Cristina.
Richard is a technologist and industry analyst. He was an ethical hacker for PricewaterhousCoopers early in his career. Now he focuses on industry trends, global cybersecurity policy, and threatscape.
Richard Stiennon is Chief Research Analyst for IT-Harvest, the firm he founded in 2005 to cover the booming IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and UP and to the RIGHT: Strategy and Tactics of Analyst Influence (IT-Harvest Press, 2012). He writes the Cyber Domain column for forbes.com and is frequently quoted as a cyber security expert in mainstream media. He advises his clients on cybersecurity strategy.
He is also the Executive Editor of securitycurrent.com and the Senior Fellow at the International Cybersecurity Dialogue. He was Chief Marketing Officer for Fortinet, Inc. and VP Threat Research at Webroot Software. Prior to that he was VP Research at Gartner, Inc. Stiennon has presented on cyber security threats and defenses in 28 countries on six continents. He is known for his iconoclastic analysis of the security industry and always challenges his audience to question accepted practices in the face of changing cyber threats. He has a B.S. in Aerospace Engineering and is writing his thesis for an MA in War in the Modern World from King’s College, London.
Adrian Pauna is a NIS Expert at ENISA, working in the “Secure Infrastructure & Services” department. His main activity is related to the topics of ICS/SCADA security. In the previous years he managed several projects which finalized with a set of recommendations on the subject of patching, testing and ex-post analysis of SCADA systems. Previously working to ENISA, he was a member of the Romanian Governmental CERT, entity designated to prevent and respond to security incidents related to information and communications systems of the Special Telecommunications Service and its clients. He has a Master in Information Security and several certification programs followed (CISSP, CEH, ISO27001:2005 Lead Auditor).
Pablo currently works as Control Systems Information Security and Telecommunications Professional for the Transport department (VIT) of ECOPETROL. He is electrical engineer, specializes in automatic and industrial computer science and certified SCADA Security Architect.
Since 2010, he is responsible for the information security and control systems program of the VIT, where he defines and ensures compliance with control systems guidelines and implementation of controls under international standards. Additionally, he is responsible for securing the control systems communications architecture, under the principle of defense in depth.
Chris Blask has a career that spans the breadth of the industrial control system cybersecurity space. From beginnings as a control system engineer he soon saw invented one of the first commercial firewall products. Joining Cisco Systems he resurrected the company’s firewall business and built it to a position of global leadership, a legacy that continues to this day. In 2006 he recognized the need for shared situational awareness to secure cyber-physical infrastructure and has been a driving force behind this effort since.
Today Mr. Blask is actively involved with a wide range of domestic and international efforts. He is Founder and CEO of ICS Cybersecurity, Inc.; Chair of the Industrial Control System Information Sharing and Analysis Center (ICS-ISAC) and adviser to several key information security firms.
Marc has spent more than 15 years assisting some of the world’s top energy producers, financial institutions, and governments worldwide defend their critical assets from cyber threats.
His technical background in information technology engineering, security operations, and IT governance, risk, and compliance, brings a unique perspective to addressing the threats facing critical infrastructure today.
Patrick Miller has dedicated his career to the protection and defense of critical infrastructures as a trusted independent advisor. He is a Partner and Managing Principal at The Anfield Group, as well as the founder, director and president emeritus of EnergySec, a 501(c)(3) nonprofit organization focusing on information sharing, situational awareness and security workforce development. Patrick’s diverse background includes positions with regulatory agencies, private consulting firms as well as organizations in the Energy, Telecommunications and Financial Services verticals.
Marina is a Research Assistant at Hamburg University of Technology (Germany), where she is teaching security subjects and pursuing PhD in ICS security. Marina is working on the fundamentals of the secure process control: development of process-aware risk assessment and defining process-oriented security properties. She is also modeling cyber-physical attacks on the physical processes to understand attackers’ strategies and develop detection and reaction solutions. In the course of her research career she gave talks at S4 (Digital Bond), NIST and at the industrial events.
Marina has maintained her industry-oriented research focus through collaborations with several industrial partners, participation in the EU projects and research internship at Shell in the area of process automation, control and optimization. She also worked part time an ICS Security Engineer at Compass Security AG. She holds MBA in Technology Management, MSc in Telecommunications, MSc in Information and Communication Systems.
Claudio is currently the Chief Security Ambassador for Eleven Paths in Argentina. He is founder of Root-Secure SRL, and as a consultant, he specializes in Information Security and holds various international certifications. He is the President of ISSA Argentina (2011-2013 and 2013-2015), Coordinator for the CCI in Argentina, Member of associations like ISSA International, OWASP, Usuaria, Argentina Cibersegura, Member of the academic committee of Segurinfo since 2007. Renowned speaker at multiple national and international events like TEDxUTN 2012 ( http://holename.wordpress.com/2012/07/13/tedxutn-de-las-emociones-a-las-experiencias/ ), LatinCACS 2012 and 2013, Isaca Lima Full Day, Campus Party Ec 2011, Owasp Latam Tour 2011/12 and 13, Segurinfo 2007-2013, 8dot8 (2011-2013) among other big events.
Claudio is a teacher on subjects related to Ethical Hacking, Defense Methodologies, Platform Hardering, Web security, Anti-Forensics Techniques. Passionate about Social Engineering. Together with his partners at Root-Secure he is author of “”Ethical Hacking, un enfoque metodológico”” (Ethical Hacking, a methodological approach), published by Editorial Alfaomega with ISBN-13: 978-9871609017. He co-organizes the event MS Doing Blue.
José Valiente is manager of Coordination and Communication at the Industrial Cybersecurity Center. B.S. on Computer Science by the Universidad Pontificia of comillas, is a specialist in Security and Technology Consultancy. With more than 20 years of experience in consulting firms as Davinci Consulting and Tecnocom involved in projects related to IT and security for big companies and public enterprises he holds multiple certifications from security and IT vendors (Cisco CCNA y CCDA, System Security Mcafee, Security Specialist Juniper, Websense Certified Enginer, F5 Bigip Specialist y Radware certified security Specialist) as well as CISM from ISACA.
José is an expert in project management and has lead ISMS deployment projects for IBEX35 companies and public enterprises working with security top level teams. He has wide knowledge on ITIL and PMI and experience in providing training to industrial sectors companies and public enterprises.
María Pilar is currently the manager of cyber security projects at Everis Aerospace and Defense. After almost 11 years with the company, she has vast experience in large IT projects. She spent 5 years in the public sector in Spain, 3 in the public sector of the Mexican office of Everis and finally, 3 years ago, she assumed the responsibility of developing the Security division of Everis Aerospace and Defense, leveraging the services that the Everis Group already offers to small and medium-sized niche companies.
She has executed projects related to Security Master Plans, in Spain and Europe and within the company she is promoting protection campaigns against malware; privacy and personal data; the use of cyber attack simulators for training at critical infrastructures; analysis of necessary certifications for Security directors of critical infrastructures; cyber security in Smart Grids; monitoring infrastructures in networks; Finally, she is participating in several projects related to cyber security roadmaps aimed at contributing to the main European investment and innovation programs.
Belisario Contreras is the Cyber Security Program Manager at the Secretariat of the Inter-American Committee against Terrorism (CICTE) of the Organization of American States (OAS). As Program Manager he provides programmatic and management support to the CICTE Secretariat in the planning, organization and execution of cyber security initiatives in the Americas including the Creation and Development of Computer Emergency Response Teams (CERTs); Provision of Technical Training; Implementation of Crisis Management Exercises; Capacity building on Industrial Control Systems (ICS), and coordinating outreach and collaboration with other international and regional organizations working on cyber issues.
Since 2007, Mr. Contreras has played a part in the growth and improvement of Computer Security Incident Response Teams (CSIRTs) in the Americas, and has worked closely with Latin American governments on the development and adoption of National Cyber Security Strategies and Policies. He has spearheaded liaison and promoted strategic partnerships between the OAS and key international actors.
Mr. Contreras is a Colombian citizen, and prior to joining the CICTE Secretariat worked at the Young American Business Trust (YABT), and he was a fellow of the Department of National Planning of Colombia in 2011. He holds a Bachelor in Business Administration from the Universidad Francisco de Paula Santander, and a Master’s Degree in Latin American Studies from the School of Foreign Service at Georgetown University.
Fernando Sevillano has a degree in Economic and Business Science (1995), a Master´s degree in Business Communication Management and Research (2008) and he is a Doctor from the Superior Technical School of I.T. Engineering (ETSII) of the Rey Juan Carlos University in Madrid (2010). His thesis with a Doctoral Thesis on real time corporate management. He has also done several modules of the CPIM (Certified in Process and Inventory Management) from APICS and managerial competences courses at EADA Business School.
With almost 20 years of experience, his professional career has developed in the sphere of IT, in particular, in the area of corporate management solutions (ERP, BI, CRM) and industrial management (SCADA, MES, energy efficiency, industrial Cloud Computing, etc).
Currently, Fernando works at the Logitek´s Madrid office, as Industrial Cybersecurity Manager. As such, he is responsible for developing this business area.
Senior Manager of the Tecnological Risks department of PWC. He has more than 14 years of experience in IT Security consulting and specializes in the energy sector, and has executed projects in different securtity environments within the main national and international companies. Jorge holds several security certifications, such as CISSP, CISM, CISA y CSSLP.
Colin Blou is the VP Sales NA and EU at Waterfall Security Solutions. His main focus of activities is within the Critical National Infrastructure sector, with particular interests in the electric utility and the oil and gas markets. Colin was instrumental in implementing unidirectional connectivity as the primary electronic perimeter security in over 50% of the current 66 commercial nuclear operating power plants in the United States. In addition, he initiated the recent installations of Waterfall’s unidirectional connectivity platform at both off-shore and on-shore O&G facilities. Colin has a BA Economics from the University of the Witwatersrand and MA Politics from the Hebrew University.
As a 19 years of experienced information security practitioner, Javier has been leading different departments at several Spanish security services providers, heading the Business Development Management at GMV, Unitronics and SIA, performing strategic security analysis at CERN and spreading security knowledge at Universidad Camilo José Cela in Madrid. Javier is BsC in Computer Science by Universidad Politécnica de Madrid and Private Security Director by UNED and currently he is defining and leading GMV business development strategy regarding CIIP and IACS Cybersecurity.
Filippo Cassini is Vice President of systems engineering for the EMEA and APAC at Fortinet. He has more than a decade of experience in the network security industry, with an extensive expertise in product development and consulting. Since 2005, Cassini has been managing Fortinet’s consulting teams dedicated to large enterprises and ISPs. He previously held various engineering positions in EMEA for Fortinet and Alasso, a formerly leading pan-European security distributor.
Ayman has over 20 years of experience in the fields of Automation, Information Technology, and Cyber Security. He has graduated with a Bachelor’s degree in Electronics Engineering and verse in different backgrounds like industrial control systems, systems engineering, and building cyber security strategies, designs and models. Ayman has a wide-ranging experience in protecting critical infrastructures, and he is an information contributor to the ISA99/IEC62443 international standard and currently the Co-Chairman of Workgroup1 .
Ayman is currently the CCI Chief Technology Advisor in the Middle East and Asia, and he is an energetic member in the Cyber Security advisory boards of a number of the top worldwide universities that are exploiting researches for improving industrial cyber security, and he is an active member in different international Security Innovation Alliances that are focused in a worldwide program for improving the security of industrial control systems by the close collaboration of the leading IT Security vendors and leading industrial automation and control system vendors. Realizing that security measures are always behind the emerging cyber risks, he developed an ICS defense-in-depth industrial cyber security model that aims to early detection of threats based on security-through-vision-and-integration.
Ayman has over 20 years of experience in the fields of Automation, Information Technology, and Cyber Security. He has graduated with a Bachelor’s degree in Electronics Engineering and verse in different backgrounds like industrial control systems, systems engineering, and building cyber security strategies, designs and models.
Ayman has a wide-ranging experience in protecting critical infrastructures, and he is an information contributor to the ISA99/IEC62443 international standard and currently the Co-Chairman of Workgroup1 .
Ayman is currently the CCI Chief Technology Advisor in the Middle East and Asia, and he is an energetic member in the Cyber Security advisory boards of a number of the top worldwide universities that are exploiting researches for improving industrial cyber security, and he is an active member in different international Security Innovation Alliances that are focused in a worldwide program for improving the security of industrial control systems by the close collaboration of the leading IT Security vendors and leading industrial automation and control system vendors. Realizing that security measures are always behind the emerging cyber risks, he developed an ICS defense-in-depth industrial cyber security model that aims to early detection of threats based on security-through-vision-and-integration.
Marc has spent more than 15 years assisting some of the world’s top energy producers, financial institutions, and governments worldwide defend their critical assets from cyber threats.
His technical background in information technology engineering, security operations, and IT governance, risk, and compliance, brings a unique perspective to addressing the threats facing critical infrastructure today.
Colin Blou is the VP Sales NA and EU at Waterfall Security Solutions. His main focus of activities is within the Critical National Infrastructure sector, with particular interests in the electric utility and the oil and gas markets. Colin was instrumental in implementing unidirectional connectivity as the primary electronic perimeter security in over 50% of the current 66 commercial nuclear operating power plants in the United States. In addition, he initiated the recent installations of Waterfall’s unidirectional connectivity platform at both off-shore and on-shore O&G facilities. Colin has a BA Economics from the University of the Witwatersrand and MA Politics from the Hebrew University.
Claudio is currently the Chief Security Ambassador for Eleven Paths in Argentina. He is founder of Root-Secure SRL, and as a consultant, he specializes in Information Security and holds various international certifications. He is the President of ISSA Argentina (2011-2013 and 2013-2015), Coordinator for the CCI in Argentina, Member of associations like ISSA International, OWASP, Usuaria, Argentina Cibersegura, Member of the academic committee of Segurinfo since 2007.
Renowned speaker at multiple national and international events like TEDxUTN 2012 ( http://holename.wordpress.com/2012/07/13/tedxutn-de-las-emociones-a-las-experiencias/ ), LatinCACS 2012 and 2013, Isaca Lima Full Day, Campus Party Ec 2011, Owasp Latam Tour 2011/12 and 13, Segurinfo 2007-2013, 8dot8 (2011-2013) among other big events.
Claudio is a teacher on subjects related to Ethical Hacking, Defense Methodologies, Platform Hardering, Web security, Anti-Forensics Techniques. Passionate about Social Engineering. Together with his partners at Root-Secure he is author of “”Ethical Hacking, un enfoque metodológico”” (Ethical Hacking, a methodological approach), published by Editorial Alfaomega with ISBN-13: 978-9871609017. He co-organizes the event MS Doing Blue.
Filippo Cassini is Vice President of systems engineering for the EMEA and APAC at Fortinet. He has more than a decade of experience in the network security industry, with an extensive expertise in product development and consulting. Since 2005, Cassini has been managing Fortinet’s consulting teams dedicated to large enterprises and ISPs. He previously held various engineering positions in EMEA for Fortinet and Alasso, a formerly leading pan-European security distributor.
Belisario Contreras is the Cyber Security Program Manager at the Secretariat of the Inter-American Committee against Terrorism (CICTE) of the Organization of American States (OAS). As Program Manager he provides programmatic and management support to the CICTE Secretariat in the planning, organization and execution of cyber security initiatives in the Americas including the Creation and Development of Computer Emergency Response Teams (CERTs); Provision of Technical Training; Implementation of Crisis Management Exercises; Capacity building on Industrial Control Systems (ICS), and coordinating outreach and collaboration with other international and regional organizations working on cyber issues.
Since 2007, Mr. Contreras has played a part in the growth and improvement of Computer Security Incident Response Teams (CSIRTs) in the Americas, and has worked closely with Latin American governments on the development and adoption of National Cyber Security Strategies and Policies. He has spearheaded liaison and promoted strategic partnerships between the OAS and key international actors.
Mr. Contreras is a Colombian citizen, and prior to joining the CICTE Secretariat worked at the Young American Business Trust (YABT), and he was a fellow of the Department of National Planning of Colombia in 2011. He holds a Bachelor in Business Administration from the Universidad Francisco de Paula Santander, and a Master’s Degree in Latin American Studies from the School of Foreign Service at Georgetown University.
Marina is a Research Assistant at Hamburg University of Technology (Germany), where she is teaching security subjects and pursuing PhD in ICS security. Marina is working on the fundamentals of the secure process control: development of process-aware risk assessment and defining process-oriented security properties. She is also modeling cyber-physical attacks on the physical processes to understand attackers’ strategies and develop detection and reaction solutions. In the course of her research career she gave talks at S4 (Digital Bond), NIST and at the industrial events.
Marina has maintained her industry-oriented research focus through collaborations with several industrial partners, participation in the EU projects and research internship at Shell in the area of process automation, control and optimization. She also worked part time an ICS Security Engineer at Compass Security AG. She holds MBA in Technology Management, MSc in Telecommunications, MSc in Information and Communication Systems.
Samuel Linares is Director at Industrial Cybersecurity Center, European Commission Independent Evaluator, ENISA (European Network and Information Security Agency) CIIP Expert and member of ISACA Cybersecurity Task Force. With 2 decades of security, system integration and multinational and multicultural projects management experience, he has been the main promoter of the “Industrial Cybersecurity” concept in Spanish, being recognized as one of the key Spanish and Latin-american experts in the area and participating as speaker, chairman and teacher in different events all over the world (including Spain, UK, USA, Belgium, Qatar, United Arab Emirates, Mexico, Cuba or Argentina, among others).
He holds various cybersecurity certifications including GICSP (Global Industrial Cyber Security Professional), CRISC (Certified in Risk and Information Systems Control), CGEIT (Certified in Governance of Enterprise IT), CISM (Certified Information Security Manager), CISA (Certified Information Security Auditor), CISSP (Certified Information Systems Security Professional), GIAC Assessing Wireless Networks (GAWN), Systems and Network Auditor (GSNA), and Google Hacking & Defense (SSP-GHD), BSI BS 25999 & BS 7799 Lead Auditor (since 2002), and several additional vendor specific technical certifications. He holds a B.S. in Computer Science from the Univ. de Oviedo and is University Specialist in Data Protection by the Colegio Universitario Escorial Maria Cristina.
Patrick Miller has dedicated his career to the protection and defense of critical infrastructures as a trusted independent advisor. He is a Partner and Managing Principal at The Anfield Group, as well as the founder, director and president emeritus of EnergySec, a 501(c)(3) nonprofit organization focusing on information sharing, situational awareness and security workforce development. Patrick’s diverse background includes positions with regulatory agencies, private consulting firms as well as organizations in the Energy, Telecommunications and Financial Services verticals.
Pablo currently works as Control Systems Information Security and Telecommunications Professional for the Transport department (VIT) of ECOPETROL. He is electrical engineer, specializes in automatic and industrial computer science and certified SCADA Security Architect.
Since 2010, he is responsible for the information security and control systems program of the VIT, where he defines and ensures compliance with control systems guidelines and implementation of controls under international standards. Additionally, he is responsible for securing the control systems communications architecture, under the principle of defense in depth.
Ignacio Paredes has a M.S. in Computer Science and works as manager of Studies and Research at the Industrial Cybersecurity Center. Since 1999 he has been involved in different projects related to information security for important enterprises mainly from the telecommunications field. He is an expert in the design and deployment of technical and administrative security solutions, including topics such as applications security, secure network design, critical infrastructure protection, ethical hacking, business continuity planning, implementation of ISO/27001 based ISMSs and risk assessment and management.
Among others he holds the following professional certifications: ISACA: CRISC, CISM, CISA; (ISC)2 Certified Information Systems Security Professional (CISSP); PMI Project Management Professional (PMP), GIAC Systems and Network Auditor (GSNA); GIAC Assessing Wireless Networks (GAWN); BS 7799 Lead Auditor by BSI (British Standards Institution); EC-Council Certified Ethical Hacker (CeH); Optenet Certified Systems Engineer (OCSE); Sun SCNA and Sun SCSA.
Senior Manager of the Tecnological Risks department of PWC. He has more than 14 years of experience in IT Security consulting and specializes in the energy sector, and has executed projects in different securtity environments within the main national and international companies. Jorge holds several security certifications, such as CISSP, CISM, CISA y CSSLP.
Adrian Pauna is a NIS Expert at ENISA, working in the “Secure Infrastructure & Services” department. His main activity is related to the topics of ICS/SCADA security. In the previous years he managed several projects which finalized with a set of recommendations on the subject of patching, testing and ex-post analysis of SCADA systems. Previously working to ENISA, he was a member of the Romanian Governmental CERT, entity designated to prevent and respond to security incidents related to information and communications systems of the Special Telecommunications Service and its clients. He has a Master in Information Security and several certification programs followed (CISSP, CEH, ISO27001:2005 Lead Auditor).
Fernando Sevillano has a degree in Economic and Business Science (1995), a Master´s degree in Business Communication Management and Research (2008) and he is a Doctor from the Superior Technical School of I.T. Engineering (ETSII) of the Rey Juan Carlos University in Madrid (2010). His thesis with a Doctoral Thesis on real time corporate management. He has also done several modules of the CPIM (Certified in Process and Inventory Management) from APICS and managerial competences courses at EADA Business School.
With almost 20 years of experience, his professional career has developed in the sphere of IT, in particular, in the area of corporate management solutions (ERP, BI, CRM) and industrial management (SCADA, MES, energy efficiency, industrial Cloud Computing, etc).
Currently, Fernando works at the Logitek´s Madrid office, as Industrial Cybersecurity Manager. As such, he is responsible for developing this business area.
Richard is a technologist and industry analyst. He was an ethical hacker for PricewaterhousCoopers early in his career. Now he focuses on industry trends, global cybersecurity policy, and threatscape.
Richard Stiennon is Chief Research Analyst for IT-Harvest, the firm he founded in 2005 to cover the booming IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and UP and to the RIGHT: Strategy and Tactics of Analyst Influence (IT-Harvest Press, 2012). He writes the Cyber Domain column for forbes.com and is frequently quoted as a cyber security expert in mainstream media. He advises his clients on cybersecurity strategy.
He is also the Executive Editor of securitycurrent.com and the Senior Fellow at the International Cybersecurity Dialogue. He was Chief Marketing Officer for Fortinet, Inc. and VP Threat Research at Webroot Software. Prior to that he was VP Research at Gartner, Inc. Stiennon has presented on cyber security threats and defenses in 28 countries on six continents. He is known for his iconoclastic analysis of the security industry and always challenges his audience to question accepted practices in the face of changing cyber threats. He has a B.S. in Aerospace Engineering and is writing his thesis for an MA in War in the Modern World from King’s College, London.
María Pilar is currently the manager of cyber security projects at Everis Aerospace and Defense. After almost 11 years with the company, she has vast experience in large IT projects. She spent 5 years in the public sector in Spain, 3 in the public sector of the Mexican office of Everis and finally, 3 years ago, she assumed the responsibility of developing the Security division of Everis Aerospace and Defense, leveraging the services that the Everis Group already offers to small and medium-sized niche companies.
She has executed projects related to Security Master Plans, in Spain and Europe and within the company she is promoting protection campaigns against malware; privacy and personal data; the use of cyber attack simulators for training at critical infrastructures; analysis of necessary certifications for Security directors of critical infrastructures; cyber security in Smart Grids; monitoring infrastructures in networks; Finally, she is participating in several projects related to cyber security roadmaps aimed at contributing to the main European investment and innovation programs.
José Valiente is manager of Coordination and Communication at the Industrial Cybersecurity Center. B.S. on Computer Science by the Universidad Pontificia of comillas, is a specialist in Security and Technology Consultancy. With more than 20 years of experience in consulting firms as Davinci Consulting and Tecnocom involved in projects related to IT and security for big companies and public enterprises he holds multiple certifications from security and IT vendors (Cisco CCNA y CCDA, System Security Mcafee, Security Specialist Juniper, Websense Certified Enginer, F5 Bigip Specialist y Radware certified security Specialist) as well as CISM from ISACA.
José is an expert in project management and has lead ISMS deployment projects for IBEX35 companies and public enterprises working with security top level teams. He has wide knowledge on ITIL and PMI and experience in providing training to industrial sectors companies and public enterprises.
As a 19 years of experienced information security practitioner, Javier has been leading different departments at several Spanish security services providers, heading the Business Development Management at GMV, Unitronics and SIA, performing strategic security analysis at CERN and spreading security knowledge at Universidad Camilo José Cela in Madrid. Javier is BsC in Computer Science by Universidad Politécnica de Madrid and Private Security Director by UNED and currently he is defining and leading GMV business development strategy regarding CIIP and IACS Cybersecurity.
9:00 a 13:00h: Applying ISA99 to Protect Industrial Infrastructures
o Teacher(s): Samuel Linares, Nacho Paredes, José Valiente (all CCI)
o Registration fee: 150 €
Description pending
15:00 a 19:00h: Beyond the Firewall of the Control System: Physical Damage and Process Exploitation
o Teacher(s): Marina Krotofil
o Registration fee: 150 €
Current approaches to securing Industrial Control Systems are cyber-oriented (generic IT security defenses of the infrastructure). Impact on the physical world only used to stress the importance of security. As a result, nearly all ICS security presentations ignore the complexities after an attacker has achieved code execution (I got past the firewall so I win). Little information is available on what the attacker does after she gains control of the process. The answer to that question is often specific to the process, but there are a number of generic techniques that can be discussed.
By addressing process exploitation techniques, the workshop will demonstrate the challenges an attacker faces while trying to practically achieve her goal along with coverage of the attack success factors. This will enable attendees to develop a firm understanding of what it takes to actually design an attack on a physical process or equipment. Such knowledge is gaining particular relevance in the light of the current IoT vision of a massively instrumented world of intelligent sensors.
In order to keep the presentation real and understandable, the workshop will walk through real-life attacks, public cyber-physical exploits, accident reports as well as studies conducted by the workshop presenter. The session will conclude with lessons on how processes can be made inherently more robust and secure, how the exploitation can be made much harder and how the attacks can be detected.
By attending this workshop you will:
• Obtain knowledge on safety and security relationship; process-aware security properties; crucial importance of timing parameters; unconventional attack vectors; process-aware security and risk assessment.
• Develop a workable knowledge of the anatomy of cyber-physical attack, particularly reconnaissance and discovery process, process exploitation techniques and classes of physical damage, understand what practices can be implemented to restrict and detect attacks.
• Understand why it takes a multidisciplinary team (IT, security, control engineers and operators) to create workable security solutions for industrial control systems.
Marina Krotofil ( Researcher, Hamburg University of Technology )
Marina is a Research Assistant at Hamburg University of Technology (Germany), where she is teaching security subjects and pursuing PhD in ICS security. Marina is working on the fundamentals of the secure process control: development of process-aware risk assessment and defining process-oriented security properties. She is also modeling cyber-physical attacks on the physical processes to understand attackers’ strategies and develop detection and reaction solutions. In the course of her research career she gave talks at S4 (Digital Bond), NIST and at the industrial events.
Marina has maintained her industry-oriented research focus through collaborations with several industrial partners, participation in the EU projects and research internship at Shell in the area of process automation, control and optimization. She also worked part time an ICS Security Engineer at Compass Security AG. She holds MBA in Technology Management, MSc in Telecommunications, MSc in Information and Communication Systems.
09:00h a 13:00h: The Effective Approach for Protecting Oil and Gas Critical Infrastructures from the Emerging Cyber Threats
o Teacher: Ayman Al-Issa
o Registration fee: 300 €
While there were heaps of talks during the last few years about the increase in emerging threats that are targeting Industrial Control Systems (ICS), the major challenge that needs more focus is how to practically improve cyber security within these heterogeneous industrial environments while maintain safe operation. The workshop will give a comprehensive overview of the practical approach for designing and implementing cyber security for the new Industrial Control Systems from Front End Engineering Design (FEED) Stage to the EPC (Engineering, Procurement and Construction). It will also discuss how to address the challenges faced for securing the existing new and legacy control systems in the brown oil fields.
Why you should attend
• Learn how to embed industrial cyber security technical assurance in project lifecycle
• Discuss ways to resolve the human IT and OT conflicts. Who should do what?
• Develop ideas on implementing a defense in depth model for protecting the critical infrastructure
• Evaluate the important aspects that you need to consider before implementing cyber security in the existing ICS systems
Program
9.30 Registration & Coffee
10.00 Session 1
11.45 Morning Coffee
12.00 Session 2
14.00 End of workshop
Workshop main bullets
• Understanding the Evolving nature of Industrial Cyber Threats
• Protecting critical infrastructures from the emerging cyber threats
• Understanding the ISA99/IEC62443, and understanding the SILs and SALs
• Implementing Industrial Cyber Security by Design
• Resolving the human conflict. Who is going to lead the Industrial Cyber Security task? IT or Control staff?
• What are the key first things to consider before implementing industrial cyber security?
• The importance of realizing the Industrial cyber security big picture. Understand the big picture first then zoom in
• ICS cyber security risk assessment. Is it done right?
• Before implementing an Industrial Cyber Security solution, find the answer on “how is cyber security going to be supported for the long-term life of the plant (20 to 30 years or more)?”
• What are the obstacles faced by the customer at the plant floor to protect new/existing (old) diverse types of IACS from the emerging cyber threats.
o Securing the green field
o Securing the brown field
• “Why an effective cyber-security DID model failed to be implemented so far in a Critical Infrastructure having multi/diverse/old/new Automation Systems, and the way forward?”
• The MAC and the MCSC. The value of the partnership between the Automation vendors and cyber security vendors.
• Why failing to consider Cyber Security needs at the procurement phase of the ICS systems shall not happen anymore?
Ayman Al- Issa ( Digital Oil Fields Cyber Security Advisor, Abu Dhabi Marine Operating Company )
Ayman has over 20 years of experience in the fields of Automation, Information Technology, and Cyber Security. He has graduated with a Bachelor’s degree in Electronics Engineering and verse in different backgrounds like industrial control systems, systems engineering, and building cyber security strategies, designs and models.
Ayman has a wide-ranging experience in protecting critical infrastructures, and he is an information contributor to the ISA99/IEC62443 international standard and currently the Co-Chairman of Workgroup1 .
Ayman is currently the CCI Chief Technology Advisor in the Middle East and Asia, and he is an energetic member in the Cyber Security advisory boards of a number of the top worldwide universities that are exploiting researches for improving industrial cyber security, and he is an active member in different international Security Innovation Alliances that are focused in a worldwide program for improving the security of industrial control systems by the close collaboration of the leading IT Security vendors and leading industrial automation and control system vendors. Realizing that security measures are always behind the emerging cyber risks, he developed an ICS defense-in-depth industrial cyber security model that aims to early detection of threats based on security-through-vision-and-integration.
09:00h a 13:00h: Introduction to Industrial Control Systems for IT professionals
o Teacher(s): José Valiente (CCI)
o Registration fee: 150 €
Although the Industrial Control Systems (OT) over the last years are applying COTS systems to operate, there are still major differences with IT systems (the foremost importance of the availability, performance and reliability requirements, Operating System settings and applications, architectures, etc..), so that countermeasures used in traditional IT systems may be inappropriate for an OT system.
This workshop will introduce the participants to an industrial control system and its various components, including instrumentation and sensors, control devices (PLCs, RTUs, DCS …), control networks specific industrial protocols (OPC, DNP3, Profibus, etc …), SCADA systems, historians and MES systems according to levels 0-3 of the ISA. Also we will go into aspects of cybersecurity and how these OT devices are tailored to the needs of security and high availability. For the workshop will use industrial control equipment and real networks.
José Valiente ( Manager of Coordination and Communication, CCI )
José Valiente is manager of Coordination and Communication at the Industrial Cybersecurity Center. B.S. on Computer Science by the Universidad Pontificia of comillas, is a specialist in Security and Technology Consultancy. With more than 20 years of experience in consulting firms as Davinci Consulting and Tecnocom involved in projects related to IT and security for big companies and public enterprises he holds multiple certifications from security and IT vendors (Cisco CCNA y CCDA, System Security Mcafee, Security Specialist Juniper, Websense Certified Enginer, F5 Bigip Specialist y Radware certified security Specialist) as well as CISM from ISACA.
José is an expert in project management and has lead ISMS deployment projects for IBEX35 companies and public enterprises working with security top level teams. He has wide knowledge on ITIL and PMI and experience in providing training to industrial sectors companies and public enterprises
15:00 a 19:00h: Smart Grid Security. International State and Progress
o Teacher(s): CCI, INTECO, Tecnalia, Gas Natural (pending confirmation)
o Registration fee: 150 €
Description pending
15:00h a 19:00h: Introduction to Cybersecurity for Automation and Instrumentation Professionals
o Teacher(s): Ignacio Paredes (CCI)
o Registration fee: 150 €
The purpose of this workshop is to prepare the staff responsible of control and automation systems for facing the challenges posed by the application of new information and communication technologies to industrial facilities. During the workshop, key issues will be discussed such as why we have reached this situation, how to solve the emerged problems and mitigate the impact of potential incidents and available tools for helping in this task.
Nacho Paredes ( Manager of Studies and Research, CCI )
Ignacio Paredes has a M.S. in Computer Science and works as manager of Studies and Research at the Industrial Cybersecurity Center. Since 1999 he has been involved in different projects related to information security for important enterprises mainly from the telecommunications field. He is an expert in the design and deployment of technical and administrative security solutions, including topics such as applications security, secure network design, critical infrastructure protection, ethical hacking, business continuity planning, implementation of ISO/27001 based ISMSs and risk assessment and management.
Among others he holds the following professional certifications: ISACA: CRISC, CISM, CISA; (ISC)2 Certified Information Systems Security Professional (CISSP); PMI Project Management Professional (PMP), GIAC Systems and Network Auditor (GSNA); GIAC Assessing Wireless Networks (GAWN); BS 7799 Lead Auditor by BSI (British Standards Institution); EC-Council Certified Ethical Hacker (CeH); Optenet Certified Systems Engineer (OCSE); Sun SCNA and Sun SCSA
October 7 and 8, 2014
Hotel Meliá Avda. de América, Calle Juan Ignacio Luca de Tena, 36 Madrid (España)