From risk to resilience: Navigating OT security in a converged world

In this session, Rob King (runZero) is joined by Patrick Gillespie and Mary Gannon from GuidePoint Security to explore the complex world of Operational Technology (OT) security in an increasingly converged environment. The discussion focuses on the unique challenges of securing industrial systems — such as those found in manufacturing and mining — where legacy hardware like Windows 98 and even Windows 3.1 is still in active use. The speakers emphasize that while convergence offers business benefits like real-time data and remote work capabilities, it also introduces significant safety risks that must be managed through a shared responsibility model between IT and OT teams.

A key takeaway is the critical importance of asset discovery and inventory. Many OT organizations lack a clear understanding of what is on their networks, a problem often rooted in cultural divides where the teams responsible for security do not own the physical assets. The experts highlight that in OT, priorities are flipped: whereas IT focuses on data confidentiality, OT prioritizes safety and availability. This means traditional IT practices like immediate patching are often impossible, as shutting down a system could have life-or-death consequences for the people on the plant floor.

Watch more sessions from runZero Day

Session TitleGuests
Watch SessionA CVE quagmire:
Quality versus quantity
Jerry Gamblin, RogoLabs
Watch SessionPredicting exploitation:
A practitioner's guide
Jay Jacobs, Empirical Security
Watch SessionSignal vs slop:
Journalists on the evolution of research-driven reporting
Bill Brenner, CYBER.SEC.Community
Dennis Fisher, Decipher
Steve Ragan, 1Password
Watch SessionOn the frontlines of investigative journalism in cybersecurity:
An insider's perspective
Joseph Menn, Author & Investigative Journalist
Watch SessionFrom risk to resilience:
Navigating OT security in a converged world
Mary Gannon, GuidePoint Security
Patrick Gillespie, GuidePoint Security
Watch SessionForce multiplied:
Community-powered vuln detection
Rishi Sharma, ProjectDiscovery
Watch SessionMute the sirens:
Prioritizing vulnerability noise
Mark Lambert, ArmorCode
Watch SessionThe network edge:
EOL and exploitation
Kimber Duke, VulnCheck
Patrick Garrity, VulnCheck
Watch SessionBug bounties in the age of AICasey Ellis, Bugcrowd
Watch SessionPerimeters and pathways:
Protecting the complete attack surface
HD Moore, runZero
Jared Atkinson, SpecterOps
Zakir Durumeric, Censys
Watch SessionThe infinite eye:
How AI threat intelligence gives defenders an asymmetric edge
HD Moore, runZero
Jonathan Cran, Mallory

Meet Our Speakers

Rob King

Director of Applied Research, runZero

Patrick Gillespie

OT Practice Lead - Guidepoint Security

Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Related Resources

Podcasts
Past, Present & Future of Offensive Security w/ HD Moore
HD explores how his deep technical roots helped him build runZero to $1M ARR as a solo operation, his past, and the future of offensive security.
Podcasts
The infinite eye: How AI threat intelligence gives defenders an asymmetric edge
Tod Beardsley, HD Moore, and Jonathan Cran discuss how AI-powered threat intelligence is providing defenders with a much-needed advantage.
Podcasts
Perimeters and pathways: Protecting the complete attack surface
Tod Beardsley, Jared Atkinson, Zakir Durumeric, and HD Moore discuss the perimeters and pathways that connect internal networks to the global...
Podcasts
Bug bounties in the age of AI
In this session, Tod Beardsley and Casey Ellis explore the evolving role of bug bounties in a world increasingly shaped by artificial intelligence.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.