United We TransformCreate teamsGrade your agenda
Atlas/Events/Industrial Control Systems (ICS)...
action-oriented convening agenda analysis

Industrial Control Systems (ICS) Cybersecurity Conference - The ...

This action-oriented convening in Technology / AI / Startup shows 80 visible agenda rows from icscybersecurityconference.com and scores 49/100: a moderate design signal with incomplete evidence. The clearest public signals sit in Learning Transfer and Problem Specificity; the main limits are Follow Through and Participation Architecture. Visible mechanisms include Participant work, Follow-up, Feedback, and Network design. Follow-through or tracking is at least visible enough to inspect, though causal proof still... A practical reading: For a reader, this is a useful but still incomplete public example: it reads as an action-oriented convening, with the strongest visible signal in learning transfer and problem specificity and the biggest open question around follow through and participation architecture. The practical test is whether the published agenda connects the room to execution quality beyond the public agenda. This page is an original public-evidence analysis, not a copy of the source agenda or an endorsement of the event. The score places the visible agenda in the moderate design signal band. The strongest visible pillars are Learning Transfer, Problem Specificity, and Future-of-Work Fit; the thinnest visible pillars are Follow Through, Participation Architecture, and Network Design. Visible mechanisms include Participant work, Follow-up, Feedback, Network design, and Learning transfer. The extracted agenda preview includes 127 visible rows. The most common formats are Unknown, Presentation, and Workshop; the most common inferred purposes are Unknown, Knowledge Transfer, and Skill Building.

Primary source evidence: icscybersecurityconference.com ↗ · Archived copy (2026-05-21)

Eight-pillar fingerprint

Hover any pillar to see what it measures and, where it scored low, what the agenda is missing.

Participation Architecture?30
Participation Architecture - 30/100. Participant work, contribution, interaction, and alternatives to passive broadcast.Missing: Turn passive airtime into participant work: practice, sensemaking, decisions, critique, or artifact creation.
Follow Through?19
Follow Through - 19/100. Owners, dates, commitments, progress checks, and accountability after the room.Missing: Add named owners, dates, implementation checkpoints, and a visible post-event continuation path.
Problem Specificity?54
Problem Specificity - 54/100. A clear costly problem, objective, decision, or performance target.
Personalization?46
Personalization - 46/100. Role, path, goal, preparation, or connection tailoring for participants.
Network Design?34
Network Design - 34/100. Structured weak ties, bridge-building, mixers, and relationship persistence.Missing: Replace generic networking blocks with designed introductions, ask-offer exchanges, peer groups, or bridge-building rituals.
Learning Transfer?79
Learning Transfer - 79/100. Applied practice, feedback, workplace use, refreshers, and 30-90 day transfer.
Evidence Maturity?45
Evidence Maturity - 45/100. Baseline, comparison, follow-up, isolation, and attribution confidence.
Future-of-Work Fit?52
Future-of-Work Fit - 52/100. Value against time, hybrid reality, accessibility, AI, and meeting load.

Fix the gaps

Field-tested exercises matched to this agenda's weakest pillars, from the exercise library.

Follow Through (19/100)

Exercises that strengthen it: Mental Toughness Workshop • WorkshopBank · 15% Solutions • WorkshopBank · Network Patches

Participation Architecture (30/100)

Exercises that strengthen it: Make A World · Awestruck 3 Minutes · Spectrum Mapping

Post-event evidence

  • Organizer claim The 2024 ICS Cybersecurity Conference featured over 80 sessions and brought together hundreds of critical infrastructure stakeholders to discuss strategies for securing industrial control systems. Source ↗

Found by searching the public web for what happened after this gathering, then classified and screened by our pipeline. Evidence labels describe who is making the claim, not whether the event succeeded.

Agenda Preview

The actual agenda we captured. Every block is classified by format and purpose. Open any block to see how we read it; the colored edge shows whether it is participant work, broadcast, logistics, or a showcase.

Room vs wrapper

21 percent of the 127 classified blocks put participants to work; the rest broadcast, show, or handle logistics. That mix is what drives the participation score.

27
95
5
Participant workBroadcastShowcaseLogistics
all eventTrainingTrainingSkill building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisParticipant work is implied by the formatInferred from format
9AM - 4PMIndustrial Cybersecurity Launchpad ( )PresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventTrippe Room (Breakouts)PresentationPacing+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
8:30 AM - 9:00 AMDebbie LayPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
9:00 AM - 9:45 AMClint BodungenPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventICS/OT Cybersecurity Incident Preparedness & Response WorkshopWorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
all eventFull Workshop DescriptionWorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
9:00 AM - 4:55 PMDavid FormbyPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventApplied ICS Security Training LabWorkshopSkill building+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
9:00 AM - 4:55 PMJey Krishnan PandurenganPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
9:45 AM - 10:30 AMMackenize MorrisPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
10:45 AM - 11:30 AMAhmik HindmanPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
11:30 AM - 12:15 PMSachin MohanPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
1:15 PM - 2:00 PMShibu ThomasPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
2:00 PM - 2:45 PMRandy PetersenPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
2:45 PM - 3:30 PMRoger HillPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
3:45 PM - 4:30 PMTuesday, October 28, 2025PresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
8:10 AM - 8:55 AMBrian SchleiferPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventPanel: OT Security Successes, Failures, and the Road AheadPanelDiscussion+
Format · BroadcastPanelExperts discuss while the audience watches. Surfaces perspective but rarely creates participant work.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventTraining: Cyber Attack Methods for Cyber-Physical Systems (Day 1)TrainingSkill building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisParticipant work is implied by the formatInferred from format
all eventUS ONLY: This training is available for United States Citizens only. (Workshop Registration Fee: $3995)WorkshopParticipant work+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisParticipant work is implied by the formatInferred from format
9:00 AM - 5:00 PMVivek PonnadaPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
9:45 AM - 10:30 AMBrad NashPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventNavigating Complexities in Global Oil and Gas Projects: A Fireside Chat on ICS SecurityFireside chatDiscussion+
Format · BroadcastFireside chatA conversational stage format. Engaging to watch, still a broadcast format for the audience.
Evidence basisNo participant output visible from this rowRead from source, no work signal
10:45 AM - 11:30 AMKevin HolcombPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
10:45 AM - 11:15 AMMike HolcombPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
11:30 AM - 12:15 PMBrian DekenPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
11:30 AM - 12:00 PMBen CallawayPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
12:30 PM - 1:15 PMCarlos SanchezPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventWindsor C (Strategy Breakout)PresentationPacing+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
1:30 PM - 2:15 PMJohn FilitzPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventWindsor DE (Technical Breakout)PresentationPacing+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
1:30 PM - 2:15 PMMelanie HutchesonPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
2:20 PM - 2:55 PMMatthew RogersPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
2:20 PM - 2:55 PMGlen CombePresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
2:20 PM - 2:50 PMJoe CodyPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
3:00 PM - 3:30 PMAdam MaruyamaPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
3:00 PM - 3:30 PMMassimo NardonePresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
3:00 PM - 3:30 PMWilliam DonohuePresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
3:45 PM - 4:20 PMGreg HouserPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
4:20 PM - 5:00 PMWednesday, October 29, 2025PresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventTraining: Cyber Attack Methods for Cyber-Physical Systems (Day 2)TrainingSkill building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisParticipant work is implied by the formatInferred from format
9:00 AM - 12:30 PMPaul InnellaPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
9:45 AM - 10:15 AMTom SegoPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
9:45 AM - 10:15 AMDavid MazaryPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
9:45 AM - 10:15 AMSanjay KumarPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
10:20 AM - 10:50 AMKelli SchwalmPresentationKnowledge transfer+
Format · BroadcastPresentationSpeakers present, the audience receives. Awareness only unless paired with practice or follow-up.
Evidence basisNo participant output visible from this rowRead from source, no work signal
all eventUSA 2026UnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventTrainingTrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventPrevious eventsUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventAgenda 2024UnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventSpeakers 2024UnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventMike LennonUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
9AM - 4PMIndustrial Cybersecurity Launchpad ( )UnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all event(Workshop Registration Fee: $395) Navigating the complex world of industrial cybersecurity can be daunting for those new to the field. With emerging threats targeting Operational Technology (OT), there has never been a more critical time to understand and secure your industrial systems.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventWhether you’re new to the field or looking to fill gaps in your existing knowledge, these Launchpad sessions will provide an overview of various elements of industrial cybersecurity. Equip yourself with the foundational tools and skills to secure your industrial systems in today’s ever-evolving cyber landscape. Join us for a full day of learning, practical exercises, and networking opportunities.NetworkingRelationship Building+
Format · LogisticsNetworkingUnstructured mixing. Can carry incidental connection, but is not scored as designed network work.
Evidence basisMediumRead from source
all eventThe Industrial Cybersecurity Launchpad workshop consists of several sessions that will help you take the next step towards becoming an industrial cybersecurity pro!WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventTrippe Room (Breakouts)BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
8:30 AM - 9:00 AMDebbie LayUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
9:00 AM - 9:45 AMClint BodungenUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventICS/OT Cybersecurity Incident Preparedness & Response WorkshopWorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventIt is critical to understand how to effectively train, prepare for, and response to a cyber incident effectively to minimize the impacts to your safety, production, and business. This workshop is designed to equip you with the essential skills and knowledge to effectively create, implement, and manage an incident response plan in the realm of ICS and OT.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventFull Workshop Description:WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventhttps://www.icscybersecurityconference.com/training/ics-ot-cybersecurity-incident-preparedness-response-workshop/WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
9:00 AM - 4:55 PMDavid FormbyUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventApplied ICS Security Training LabTrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventFull Course Description: https://www.icscybersecurityconference.com/training/applied-ics-security-training-lab/TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
9:00 AM - 4:55 PMJey Krishnan PandurenganUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventHarminder SinghUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
9:45 AM - 10:30 AMMackenize MorrisUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
10:45 AM - 11:30 AMAhmik HindmanUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
11:30 AM - 12:15 PMSachin MohanUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
1:15 PM - 2:00 PMShibu ThomasUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventEffective insider risk programs don’t just give analysts insight to what happened, but also why it may have happened. The reason behind the event could mean the difference between the costly and time-consuming option of separating an employee from the organization and re-training a replacement and simply reminding the employee to not to upload files to an unsecure server. By understanding the root cause, effective insider risk programs can provide business value to the organization through a reduction in the mean time to investigate (MTTI) and meant time to remediate (MTTR) an employee or organization behavior.TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
2:00 PM - 2:45 PMRandy PetersenUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
2:45 PM - 3:30 PMRoger HillUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
3:45 PM - 4:30 PMTuesday, October 28, 2025UnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventKeith CaseyUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventOver breakfast, Keith Casey will compare real intrusions to federal best practices in 2025 and show a pragmatic approach to detect and block advanced persistent threats earlier - before they reach our sensitive systems.MealWellbeing+
Format · LogisticsMealA pacing block. Can carry unstructured networking, not scored as participant work.
Evidence basisMediumRead from source
8:10 AM - 8:55 AMBrian SchleiferUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventBenjamin StirlingUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventKyle RobinsonUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventChris WiwczaroskiUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventPanel: OT Security Successes, Failures, and the Road AheadPanelDeliberation+
Format · BroadcastPanelExperts discuss while the audience watches. Surfaces perspective but rarely creates participant work.
Evidence basisMediumRead from source
all eventThis panel brings together seasoned veterans of the industrial cybersecurity community who have witnessed the field’s evolution firsthand. Together, they will reflect on where we’ve been, highlight both the successes and shortcomings along the way, and discuss the most pressing challenges for the future of securing critical infrastructure.PanelDeliberation+
Format · BroadcastPanelExperts discuss while the audience watches. Surfaces perspective but rarely creates participant work.
Evidence basisMediumRead from source
all eventTraining: Cyber Attack Methods for Cyber-Physical Systems (Day 1)TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
all eventUS ONLY: This training is available for United States Citizens only. (Workshop Registration Fee: $3995)WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
all eventNote: This hands on training will take place Tuesday, October 28th - Thursday, October 30th. Day 1 will be a full day, and Day 2 and 3 will be half days. Students will be able to attend sessions of the core ICS Cybersecurity Conference and access instructors event when the workshop is not in session. Access to all conference meals and networking events is also included.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
9:00 AM - 5:00 PMVivek PonnadaUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
9:45 AM - 10:30 AMBrad NashUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventRon AhasanUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventDusty CourtneyUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventJason ThompsonUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventNavigating Complexities in Global Oil and Gas Projects: A Fireside Chat on ICS SecurityFireside ChatDeliberation+
Format · BroadcastFireside ChatA conversational stage format. Engaging to watch, still a broadcast format for the audience.
Evidence basisMediumRead from source
all eventIn the dynamic landscape of the oil and gas industry, managing large-scale projects across diverse sectors - midstream, upstream, unconventional, LCS, downstream, and manufacturing - presents unique challenges. This fireside chat will bring together key leaders from our organization to discuss how we navigate conflicting business needs while ensuring robust ICS security.Fireside ChatDeliberation+
Format · BroadcastFireside ChatA conversational stage format. Engaging to watch, still a broadcast format for the audience.
Evidence basisMediumRead from source
10:45 AM - 11:30 AMKevin HolcombUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventSecurity is the foundation of every conversation in today's industrial landscape. As operational technology (OT) environments grow increasingly complex, organizations require a comprehensive security and networking solution that delivers asset visibility, access control, and context-level security. In this demo, we will showcase how Cisco's integrated portfolio-including Cyber Vision, Secure Equipment Access (SEA), Splunk, Identity Services Engine (ISE), and Firewall Management Center (FMC)-enables organizations to secure their industrial operations from the ground up.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
10:45 AM - 11:15 AMMike HolcombUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
11:30 AM - 12:15 PMBrian DekenUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
11:30 AM - 12:00 PMBen CallawayUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventSandeep LotaUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
12:30 PM - 1:15 PMCarlos SanchezUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventWindsor C (Strategy Breakout)BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
1:30 PM - 2:15 PMJohn FilitzUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventWindsor DE (Technical Breakout)BreakWellbeing+
Format · LogisticsBreakA pacing or recovery block between sessions.
Evidence basisMediumRead from source
1:30 PM - 2:15 PMMelanie HutchesonUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
2:20 PM - 2:55 PMMatthew RogersUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
2:20 PM - 2:55 PMGlen CombeUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventJoin this demonstration to understand the risks associated with unsecured remote access, the impact of regulations and security standards related to remote access requirements, and key security considerations when implementing remote access in OT environments.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
2:20 PM - 2:50 PMJoe CodyUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
3:00 PM - 3:30 PMAdam MaruyamaUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
3:00 PM - 3:30 PMMassimo NardoneUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
3:00 PM - 3:30 PMWilliam DonohueUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventHands-on experience is critical for developing real-world OT security skills, but access to ICS hardware and realistic testbeds is often prohibitively expensive. GRFICS v3 helps close this gap by providing a lightweight, open-source platform for simulating industrial environments in software. Fully containerized for faster deployment and easier scaling, GRFICS v3 supports affordable training, repeatable testing, and research on ICS attacks and defenses. This session will cover what is new in v3, practical examples of how it is being used, and lessons learned in building modern OT security labs. Whether you are new to GRFICS or looking to enhance your existing training and testing efforts, this talk will give you tools and ideas to take back to your own environments.WorkshopCo Creation+
Format · Participant workWorkshopParticipants work on a problem and produce something. The strongest signal of participation architecture.
Evidence basisMediumRead from source
3:45 PM - 4:20 PMGreg HouserUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventThis panel addresses the very real, very messy cyber gremlins that can introduce vulnerabilities into critical Operational Technology (OT) environments. Using examples Such as SolarWinds, NotPetya, and the 2024 Lebanon electronic device attacks, we’ll discuss real-world challenges and best practices to secure each link of the supply chain, including threat modeling for vendors, zero-trust approaches for third-party vendors, and compliance with frameworks such as NIST 800-161, IEC 62443, and Executive Order 14028.PanelDeliberation+
Format · BroadcastPanelExperts discuss while the audience watches. Surfaces perspective but rarely creates participant work.
Evidence basisMediumRead from source
4:20 PM - 5:00 PMWednesday, October 29, 2025UnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventBlake GilsonUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisLowRead from source
all eventTraining: Cyber Attack Methods for Cyber-Physical Systems (Day 2)TrainingSkill Building+
Format · Participant workTrainingGuided skill building where participants practice. Counts as participant work and learning transfer.
Evidence basisMediumRead from source
9:00 AM - 12:30 PMPaul InnellaUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventCyber threats targeting Industrial Control Systems (ICS) are rapidly evolving, placing critical infrastructure - utilities, manufacturing plants, and transportation networks - under increased risk. Despite investments in cybersecurity, many ICS operators still rely heavily on traditional activity-based metrics such as patches deployed or alerts acknowledged. These metrics often fail to demonstrate actual security resilience or meaningful risk reduction.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
all eventThis session will equip attendees with a practical understanding of CPM implementation in ICS environments, demonstrating real-world case studies and best practices. Paul Innella, with over three decades of cybersecurity experience advising high-stakes organizations such as DARPA, Deutsche Bank, and the U.S. Navy, will outline methods to accurately measure ICS cybersecurity performance, communicate strategic insights clearly to executive leadership, and ensure cybersecurity investments deliver demonstrable operational impact and ROI.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
9:45 AM - 10:15 AMTom SegoUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
9:45 AM - 10:15 AMDavid MazaryUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
9:45 AM - 10:15 AMSanjay KumarUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source
all eventThis session will present a case study of ransomware operators abusing remote management tools to demonstrate how IT intrusions can cascade into OT impact. We will also show how threat intelligence can uncover early warning signs - spam floods, anomalous RMM usage, or low-severity alerts - and map them against MITRE ATT&CK for ICS to guide risk-based defenses.DemoShowcase+
Format · Participant workDemoA hands-on or applied walkthrough that invites attendee questions and direct engagement.
Evidence basisMediumRead from source
10:20 AM - 10:50 AMKelli SchwalmUnknownUnknown+
Format · BroadcastUnknownFormat not classified from the source; treated as a broadcast block by default.
Evidence basisMediumRead from source

The Full Reading

Why It Ranks This Way +

Calibrated from GES design 45/100 and verified 45/100 with no fourth-loop cap.

Reader Takeaway. For a reader, this is a useful but still incomplete public example: it reads as an action-oriented convening, with the strongest visible signal in learning transfer and problem specificity and the biggest open question around follow through and participation architecture. The practical test is whether the published agenda connects the room to execution quality beyond the public agenda.

Strongest signals: Learning Transfer, Problem Specificity, and Future-of-Work Fit. Weakest signals: Follow Through, Participation Architecture, and Network Design.

How This Agenda Could Improve +
  • Add named owners, dates, implementation checkpoints, and a visible post-event continuation path.
  • Turn passive airtime into participant work: practice, sensemaking, decisions, critique, or artifact creation.
  • Replace generic networking blocks with designed introductions, ask-offer exchanges, peer groups, or bridge-building rituals.

Fastest next move: Add named owners, dated next steps, and a visible continuation path before treating the event as outcome-ready.

Role-Specific Reading +

Event owner lens

Use this record to benchmark whether a comparable event makes the work after the room visible. The score is 49/100, so the next move is to benchmark the weakest pillars before repeating the format.

Sponsor lens

Look beyond exposure. Strong sponsor value would show qualified interaction, problem work, buyer learning, customer evidence, or follow-up. The practical sponsor move is to look for structured introductions, buyer-seller fit, and relationship persistence.

Designer lens

The agenda is useful as a pattern sample from icscybersecurityconference.com. Redesign attention should go first to the lowest-scoring pillars; in practice, turn the thinnest agenda blocks into participant work.

Executive lens

Treat the visible agenda as an operating plan. The executive move is to ask whether the follow-up evidence connects to the business or mission outcome. If owners, proof, and follow-through are not visible, the public record does not yet prove strategic movement.

Aggregator lens

Treat the source URL as evidence, not decoration. The data-product move is to label the source boundary clearly before ranking the record before ranking or syndicating the record.

What GES Means Here +

The Gathering Effectiveness Score is a strict 0-100 public-evidence reading of the agenda across eight pillars. It rewards visible participant work, follow-through, transfer, network design, and proof mechanisms more than polish, speaker fame, attendance, or satisfaction.

Visible mechanisms: Participant work, Follow-up, Feedback, Network design, Learning transfer, Personalization.

Evidence boundary: Scores reflect visible agenda/source evidence and should not be read as proof of causal event impact.

Limitations, Score Caps, and Review Flags +

Limitations

  • Passive stage formats dominate the visible agenda.
  • No baseline measurement is visible.

Score caps

  • No fourth-loop score cap applied.

Review flags

  • No tracking, validation, feedback, or impact measurement found in the visible source text.
  • High cleanup rate: many extracted rows were hidden or merged as fragments.
Is this proof the event worked? +

No. This is a strict public-evidence reading of the agenda. Proof would require baseline, comparison, follow-up, attribution, and impact evidence beyond the listing.

What should a reader inspect first? +

Start with the source URL, then compare the eight pillar scores against the agenda rows. The biggest opportunities usually sit in follow-through, evidence maturity, and participant work.

Why publish weak records? +

Weak records are part of the map. They show where public agendas still describe sessions and speakers more often than outcomes, commitments, transfer, or proof.

How should I use the rows? +

Read the agenda rows as the visible design trace: formats, purposes, and evidence labels show what the public source made inspectable, not everything that happened in the room. This is a source-grounded interpretation of the public agenda record, not a copy of the source, and not an endorsement of the event.

Embed the verified badge +

This record is in the hand-verified gold set. Copy the snippet below to embed the verified badge on your own site.

<a href="https://unitedwetransform.com/events/evt_2024_www_icscybersecurityconference_com_agenda_2024_full_session_list_icscyberse"><img src="https://unitedwetransform.com/badge/ges-verified.svg" alt="GES verified by United We Transform" height="40"></a>

Where To Go Next

Compare this agenda against other Technology / AI / Startup events scored on the same eight pillars.