Keep the Lights On: Inside CS4CA USA 2026

Twenty-nine practitioners from the water, rail, energy and industrial sectors convene in Houston to defend the systems the rest of the country never thinks about.
Nobody writes a headline when the water comes out of the tap. That’s the whole problem with critical infrastructure security — the job is invisible when it works, and catastrophic the moment it doesn’t. There’s no partial credit and no graceful degradation. The pumps run or they don’t.
CS4CA USA — held in Houston on March 10 and 11 — skipped the vendor theater and went straight at the practitioner’s problem. Across sixteen sessions, the people who actually run these environments worked through one question: when the threat is a nation-state and the asset is a thirty-year-old controller that can’t be taken offline, what does a real defense look like?
The answer came together as one connected story. It starts with who’s knocking.
The Threat
Before anything else, the room got honest about what’s actually aimed at these networks — and it isn’t opportunistic ransomware.
- Tatyana Bolton, Peter Fletcher, Joseph Couture, Dylan Coiro, Gustavo Arias and Christopher Trifiletti opened with nation-state threats and public-private defense models, making the case that OT security investment is no longer discretionary.
- Andrew Ginter of Waterfall Security surveyed the shifting landscape — AI-driven attacks, cloud pivot risk — and argued for consequence-driven, engineering-grounded defense over checkbox controls.
- Christopher Trifiletti returned with FBI and energy-sector experience to show how teams get from intelligence overload to targeted threat intel that actually changes the architecture.
The reframe: stop asking what could get breached and start asking what happens to the physical world if it does.
Knowing What You Have
You can’t prioritize what you haven’t inventoried — and in OT, the inventory is usually the hardest part of the whole program.
- John Filitz of Cisco laid out the zero trust blueprint for industrial environments, built on deep asset visibility and network-native segmentation.
- Syed Belal of Octave combined asset inventory, NIST NVD data and operational context into vulnerability prioritization that reflects what a device actually does, not just its CVSS score.
- Brian Deken of Rockwell Automation offered a remediation framework for turning that raw vulnerability data into prioritized, board-level risk decisions at scale.
- Jason Lee of Honeywell tackled the least glamorous problem in the field — building patch strategies that balance operational continuity, regulators, and risk across wildly diverse plants.
- Oliver Yates of AMDT closed the loop with enterprisewide backup, version control and configuration governance, bridging the gap between what each site knows and what headquarters can see.
Nobody sells “asset inventory” on a conference banner. It remains the single largest determinant of whether the rest of the program works.
When It Happens
Assume the perimeter fails, because eventually it does. This track was about what the organization can still do on that day.
- Ian Bramson of Black & Veatch showed how meshing operational data with cyber data gives OT teams the context to validate incidents faster instead of guessing whether an anomaly is an attack or a Tuesday.
- Carlos Sanchez of Fortinet pushed practitioners to think like the adversary, move past compliance, and operationalize resilience across their environments.
- Jason Cook of Rubrik introduced the Minimum Viable Facility — defining, in advance, the smallest set of systems that must keep running so essential operations survive during and after an attack.
Resilience isn’t a slower version of prevention. It’s a separate discipline, and it has to be designed before you need it.
The Program
Tools and frameworks only hold when people, vendors and budgets line up behind them — which is where most OT programs actually live or die.
- Jim Betzhold of South Florida Water Management District walked through the real journey of unifying IT and OT security, including the cultural and organizational lessons that don’t fit in an architecture diagram.
- Anthony Perry, Michael Tetto, Scott Rosenberger, Andy Krapf and Bemi Anjous shared hard-won lessons on selecting, integrating and — the hard part — proving the value of OT security tooling.
- Danielle Caruso, Reynaldo Gonzalez, Ryan Subers, Roger Caslow and Justin Powell rethought supply chain risk through continuous monitoring, SBOMs and deeper vendor partnerships.
- Brad Nash of ExxonMobil and Jake Margolis of Metropolitan Water District cut through the AI hype to describe what practical adoption looks like for operators at genuine scale.
- Arturo Santos of Amtrak grounded it all in one sector’s reality, covering IEC 63452, OT modernization and where targeted AI fits into rail’s 2026 security strategy.
The maturity signal across every session: these programs are being run as engineering disciplines with budgets and owners, not as projects waiting on the next incident.
CS4CA USA 2026, By the Numbers
Sixteen sessions. Here’s what that adds up to:
- 7 hours, 50 minutes of practitioner instruction — 470 minutes, none of it keynote filler
- 29 speakers across 16 sessions: 12 solo briefings and 4 multi-expert panels
- 13 named organizations, from asset owners like ExxonMobil, Amtrak, Metropolitan Water District and South Florida Water Management District to Rockwell Automation, Honeywell, Cisco, Fortinet, Rubrik, Waterfall Security, Black & Veatch, Octave and AMDT
- 5 critical infrastructure sectors represented — energy, water, rail, industrial manufacturing and federal
- A dozen-plus topic tracks: zero trust and segmentation, asset visibility, vulnerability prioritization, patch management, threat intelligence, supply chain and SBOMs, detection and response, backup and configuration governance, cyber resilience, AI in OT, regulation and IEC 63452, and IT/OT culture
- Sessions from 15 to 55 minutes — averaging under half an hour, built to fit between meetings
Get Every Session — and Every ISMG Event
These sessions are just the beginning. Security Insights by CyberEd puts the entire ISMG events experience — virtual and in person — in one on-demand library, with global event replays, expert-led masterclasses, and CPE credits on demand, featuring the CISOs, regulators, and security leaders defining the field. The scale speaks for itself — 400 events annually, 75,000+ attendees, 500 expert speakers, and 1,000+ sessions.
And the math is hard to argue with. A single conference can run into the thousands once you add flights, hotels, and tickets — plus the days away from your team. Security Insights delivers all of it for just $495 a year, on your schedule, without leaving your desk.
▶ Stop choosing which event to attend. Get them all.