Fortinet’s OT Cybersecurity Summit: Tackling Real-World Threats and Building Resilient Infrastructure

Operational technology environments face a rapidly escalating threat landscape. Ransomware groups now routinely target industrial control systems, and the convergence of IT and OT networks has expanded the attack surface for critical infrastructure operators across energy, manufacturing, water, and transportation. In this IIoT World analysis, we examine the most pressing OT cybersecurity challenges facing plant operators today, from legacy protocol vulnerabilities and flat network architectures to insufficient visibility into east-west traffic inside the Purdue model. You will find practical strategies for segmenting OT networks, deploying intrusion detection at the industrial demilitarized zone, and building an incident response plan that accounts for safety-critical processes.

On May 8, 2025, Fortinet is hosting the OT Thought Leadership Security Summit in Houston, a must-attend event for asset owners, cybersecurity professionals, and operational leaders across the energy, utilities, and critical infrastructure sectors.

As cyber threats targeting operational technology (OT) environments grow more sophisticated—driven by nation-state actors, hacktivism, and geopolitical instability—the need for collaboration, strategy, and modernized security is greater than ever. Fortinet’s Rod Locke, Director of Product Management, emphasizes the urgency: “We’re seeing real-world cyber impacts on operations, and this event is designed to provide guidance, perspective, and tools to prepare and respond.”

The summit agenda is packed with practical insights, starting with an overview of the industrial threat landscape and evolving risks (Sean Curry, Cavalry Solutions), followed by expert sessions on incident response war stories (John Simmons, Fortinet) and managing OT risk (Michael Freeman, Armis).

Key panels will explore:

  • Self-assessed risk and regulatory alignment with experts from Fortinet, Dragos, Honeywell, and Huntsman International.
  • Operationalizing OT resiliency with leaders from ExxonMobil, NOV, Waste Management, and the City of Euless.
  • Washington policy update with Patrick Miller from Ampyx Cyber, offering clarity on government expectations.

The day concludes with a fireside chat on cybersecurity maturity and a networking lunch—giving attendees a chance to connect with peers and thought leaders in the OT security space.

Who should attend: Asset owners, CISOs, plant managers, and OT security teams across the public and private sectors, especially in Texas and Oklahoma.

Location: Houston, TX
Time: 9:30 AM – 1:30 PM

Register here

Sponsored by Fortinet

Related articles:


FAQ

1. What are the most common cybersecurity threats to OT and ICS environments?

The top threats include ransomware that propagates from IT networks into OT zones, supply-chain compromises through infected firmware or software updates, and exploitation of unpatched legacy protocols such as Modbus and DNP3 that were designed without authentication. According to multiple threat intelligence reports, ransomware incidents targeting OT environments increased by more than 50% between 2022 and 2024. Nation-state actors also target ICS for espionage and pre-positioning, particularly in energy and water sectors. Phishing remains the most frequent initial access vector, underscoring the need for workforce training alongside technical controls.

2. How should manufacturers segment their OT networks to reduce cyber risk?

Best practice follows the Purdue Reference Architecture, placing firewalls and an industrial demilitarized zone (IDMZ) between enterprise IT (Levels 4 and 5) and process control networks (Levels 0 through 3). Within the OT zone, micro-segmentation isolates individual cells or lines so that a compromised HMI on one line cannot reach PLCs on another. Organizations should enforce allow-list policies that permit only known-good traffic patterns, such as specific Modbus function codes between specific source-destination pairs. Network monitoring tools designed for OT protocols can detect anomalies like unexpected configuration changes or new device connections in real time.

3. What should an OT incident response plan include that differs from a standard IT plan?

An OT incident response plan must prioritize human safety and process stability above data confidentiality. Unlike IT systems, shutting down an OT process abruptly can cause physical damage, environmental releases, or safety hazards. The plan should define safe shutdown procedures for each critical process, identify manual override capabilities, and establish communication channels that do not depend on the compromised network. Tabletop exercises should involve both cybersecurity staff and process engineers. Recovery procedures must include verified, offline backups of PLC logic and HMI configurations, because restoring from compromised backups can reintroduce the attacker.

Related from IIoT World: