Event Agenda

November 3rd – 4th, 2026 // Montréal, Canada

Register Now

Theme: Securing Our Critical Operations Through Building Practical Cyber Resilience

Day 2 – November 4th 2026
Conference Chair: Martin Laberge, Executive Cyber Security Director, CISO, Énergir
08:50 – 17:30
08:50Opening Address : Martin Laberge, Executive Cyber Security Director, CISO, Énergir
09:00

  • Should organisations focus on eliminating vulnerabilities wherever possible, or accept that some risk is inevitable and instead prioritise resilience?
  • With limited resources and operational constraints, how should organisations prioritise which vulnerabilities to remediate, mitigate, or simply monitor?
  • What vulnerability management strategies and compensating controls provide the greatest improvement in cyber resilience?
  • What does effective vulnerability management look like in a truly cyber-resilient OT environment? Can we ever achieve it, or will resilience always be an ongoing balancing act?

Moderator: Razi Farooqui, OT Cyber Security Lead, Greater Toronto Airports Authority
Michael Glenn, Vice President Security & IT Operations, KDC/ONE
Renny Kochubaby, Specialist, OT Cyber Security, Air Canada
Amogh Bhosle, Global Lead OT & Cyber Security, Sanofi
.

09:40

  • What are the main tools when it comes to monitoring the 3rd party when giving them access to your infrastructure for management, maintenance, and even administration?
  • If the 3rd party got compromised, how confident are any of you that they will notify the organisation? And how can this be assured?
  • Does Zero Trust play a big role in the 3rd party management?
  • What features do you expect to be implemented when it comes to Zero Trust for Vendors management?

.

10:10Networking Break
10:50

  • Where we addressed the OT skills gap by developing the expertise needed to support modern, connected industrial environments.
  • How we strengthened workforce capabilities by combining IT security knowledge with OT operational experience.
  • What we did to enable teams to manage emerging technologies, cyber risks, and evolving industrial demands.
  • How we built a future-ready workforce to support secure and resilient digital transformation.

.
Caroline Turcotte, Section Head of Information Infrastructure (Water Section), Ville de Montréal
.

11:20

  • How structured training programs, supported by vendor platforms, can make security a daily habit
  • Where using simple, accessible messaging and vendor resources to improve awareness both at work and in daily life can help us build awareness internally
  • How we can help track engagement, compliance, and behaviour change across our organisations
  • How these cultural practices can be expanded to partners, suppliers, and the broader community

.

11:50

  • Are we overemphasising human behaviour in cyber security at the expense of technical and systemic controls?
  • Should IT systems be designed to be resilient to human error rather than relying on users as the first line of defence?
  • What lessons can we learn from different sectors in balancing human and technical security? How can we ensure we are getting the basics; right?

Jonathan Anderson, Associate Professor of Computer Engineering, Memorial University of Newfoundland
Ramzi Naouali, CISO, Hôpital Montfort
Dany Guimond-Valcourt, Cybersecurity Lawyer, LCM Avocats inc.
.

12:20

This session explores key challenges in securing industrial control systems and OT, using real-world insights. It covers organisations under attack, investing in prevention, and navigating regulations like Bill C-8. Learn practical strategies to manage evolving cyber risks, support digitalisation, and protect critical infrastructure in an increasingly connected environment.
.
12:30

T1. Adopting Effective Zero-Trust Controls to Heighten Our Security Posture
Copia Automation
.
T2. Creating Effective Training Tools For Next Generation Leaders
Acronis
.
T3. An Interactive Red Team vs. Blue Team Attack Breakdown
.
13:10Lunch
Track A
Overcoming Everyday Challenges to Ensure Effective Incident Response
14:10

  • Should operational uptime take priority over patching critical vulnerabilities in OT environments?
  • Is risk-based patching the future, or does every known vulnerability require immediate action?
  • Can automation safely transform OT patching, or does it introduce unacceptable operational risk?
  • Are organisations measuring patch management success by compliance rather than true cyber resilience?

Jonathan Anderson, Associate Professor of Computer Engineering, Memorial University of Newfoundland
George Hoaghea, Director of Applications, Architecture and Governance, JAMP Pharma Group
Osman Saleem, Program Manager – ICS & OT Cybersecurity, Greater Toronto Airports Authority
Amogh Bhosle, Global Lead OT & Cyber Security, Sanofi
.

14:40

.
This presentation details Hydro Ottawa’s strategic journey toward establishing an enterprise-wide Operational Technology (OT) Security Profile Model built on a foundation of rigorous systems engineering in the face of grid modernization. Recognizing that effective threat modeling and risk management require a deep, standardized understanding of operational environments and their baseline controls, Hydro Ottawa developed a multi-dimensional profiling framework across SCADA, substations, power generation, metering, EV charging, and smart grid automation. Acting as a universal bridge for key internal stakeholders, the model maps a comprehensive suite of architectural controls across all levels of the Purdue Reference Model. This structured approach demonstrates how domain profiles establish the essential baseline for threat modeling and cross-functional collaboration, showing how these domain-specific controls are applied to overcome specific cybersecurity challenges in diverse OT environments.
.
Jojo Maalouf, Director, Cybersecurity and IT Infrastructure, Hydro Ottawa & Abdelrahman Eldosouky, Supervisor, Cybersecurity, Hydro Ottawa
.
15:10

.

    • Overview of the project (replacement of 2 models of end-of-life RTU) and Energir
    • Description of the new security features available
      – DNP3 with Secure Authentication version 5 (SAv5)
      – Active Directory (AD) integration for centralized authentication
    • Compatibility issues with SAv5
    • Implementation differences of the same security features between the 2 vendors
    • Overview of the deployment efforts for both models (one went well, the other, not so much…)
    • Pain points we hit along the way and what to lookout for in similar projects (lessons learned to share with the community)

.
Martin Turgeon, Lead IT/ OT Security Architect, Énergir
.

Workshop
Hosted by Goran Novkovic, Director of Industrial Cybersecurity, Toronto Transit Commission (TTC)
14:00

An Executive Workshop Series on Industrial AI, Cybersecurity, and Operational Resilience
This is a set of focused, 2-hour sessions designed to provide practical, stakeholder-specific guidance on:

  • Adapting cyber defense for the age of AI
  • Building Industrial Cybersecurity Intelligence
  • Translating intelligence into measurable operational and business outcomes

Goran Novkovic, Director of Industrial Cybersecurity, Toronto Transit Commission (TTC)
.

15:40Networking Break
16:10

An Executive Workshop Series on Industrial AI, Cybersecurity, and Operational Resilience
This is a set of focused, 2-hour sessions designed to provide practical, stakeholder-specific guidance on:

  • Adapting cyber defense for the age of AI
  • Building Industrial Cybersecurity Intelligence
  • Translating intelligence into measurable operational and business outcomes

.
Goran Novkovic, Director of Industrial Cybersecurity, Toronto Transit Commission (TTC)

17:20Closing Remarks by Martin Laberge, Exec. Director Cyber Security, CISO, Energir
17:30End of Conference

Join the Line-Up

Submit a Proposal

Register Now

Choose Your Pass

Request a Sponsor Pack

Access Here