News

The Inaugural Level Zero Industrial Control System and Operational Technology Conference

May 13, 2025
Atlanta text

By Richard Hawes

I recently had the pleasure of representing Idenhaus at the inaugural Level Zero Operation Technology Cybersecurity Conference on the Georgia Tech Campus in Atlanta. It was an extremely informative and worthwhile experience with an incredible array of speakers that opened the floodgates on the subject of Operational Technology/Industrial Control System (OT/ICS) cybersecurity. 

The people who organize these events will tell you that the first one is always the hardest to get a full room for. The Level Zero conference hit it out of the park, and my advice to everyone is don’t sleep on a good thing. This inaugural event exceeded my expectations with its remarkable lineup of expert speakers, making it a must for anyone interested in IT/OT cybersecurity. As someone who works indirectly in an operational environment, it was eye-opening to hear from senior industry professionals, academics, and government subject matter experts on the finer points of what securing these environments entails.

Operational and Control cybersecurity, unlike other domains, is unique in its real-world implications. These systems control physical processes, which include the essential infrastructure that delivers our water, our power, and supports our supply chains. In the modern United States, we are fortunate to live in an environment where we’re conditioned to take these services for granted. This is understandable given our experience, but recent events such as The Colonial Pipeline ransomware attack (May 2021) which disrupted 45% of the East Coast’s fuel supply, and the Oldsmar Water Treatment Plant attack (February 2021) remind us of how broadly disruptive and even deadly incidents in these environments can be. 

The broad gains in efficiency from the increasing amount of digital technology, automation, and, more recently, AI in our systems have been staggering, but they have come with a commensurate amount of cyber risk that must be dealt with. This proliferation in the OT/ICS space has lagged behind “traditional” IT to some degree due to its special requirements, prioritizing reliability and stability over new technology adoption, but has accelerated in recent years with the Industrial Internet of Things (IIoT) and Industry 4.0, introducing more automation and network connectivity such as smart sensors and remote monitoring. This requires a specialized body of knowledge with a rigorous set of practices to address them, and the speakers at Level Zero delivered this with verve throughout the day. 

One of the most significant and most salient topics covered throughout Level Zero was the creep of digital tech into critical infrastructure and how, with legislation specific to cybersecurity in the sector lagging and the traditionally different set of priorities than standard IT, it is incumbent upon industry cybersecurity professionals to incorporate and adapt cybersecurity tools, practices and methodologies into their environments and processes. Additionally, there is the issue of the different types of risk these organizations bear and how that plays into their strategic planning as well as their relationships with their stakeholders, including insurance companies. This territory is not well explored as it is in the data-centric, digital-only world, and working all this out in the industries that supply our fundamental services is of vital importance.

An adjacent and equally important topic was mitigating the risks from hostile nation states and combating cyber warfare. We know from the war in Ukraine and the recent infiltration of United States infrastructure by Chinese threat actors that civilian critical infrastructure is a target in the cyber as well as the physical realm. Hearing the retired CEO of Southern Company and a former Assistant Secretary of Defense discuss strategies for government-private sector collaboration to strengthen our infrastructure’s cyber defenses was both fascinating and reassuring.

My biggest takeaway from Level Zero was that many OT environments still rely on legacy systems that lack modern security features and are rarely updated or patched. These systems are especially vulnerable to cyberattacks, as they often have weak authentication and outdated protocols. When combined with the increased convergence of information technology (IT) and operational technology (OT) systems, the problem gets larger. The drive for data-driven insights, automation, and Industry initiatives has led to tighter integration between these domains (IT/OT). This convergence expands the attack surface significantly, as vulnerabilities in IT systems can now be leveraged to compromise OT environments, potentially disrupting production lines or overriding safety systems. Understanding these trends is key to mitigating the risk and is one of the reasons the Level Zero Conference was so successful.

More News

Subscribe To Our Newsletter

Please send me the following content from Idenhaus:*
Select as many boxes as you'd like!
Idenhaus needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.