 | 08:50Opening Address : Martin Laberge, Executive Cyber Security Director, CISO, Énergir |
 | 09:00 - Why are IT and OT still at odds when it comes to cyber security priorities, ownership, and risk tolerance?
- Has IT/OT convergence improved cyber security outcomes, or has it increased complexity and new exposure?
- How effective are current cyber security policies, governance models, and controls – including network segmentation – across IT and OT environments?
- How critical are clear policies in making IT/OT security work in practice, from culture and communication to operational trust and accountability?
– Moderator: CMichael Glenn, Vice President Security & IT Operations, KDC/ONE – Alex Charbonneau, CISO, Lassonde Industries – Hadis Karimipour, Associate Professor-Canada Research Chair (Tier II) in Secure and Resilient Cyber-Physical Systems, University of Calgary – Abu Thomas, IT Director, Contract Pharmaceuticals Limited – Adina Schoeneman, Sr. Product Marketing Manager, CrowdStrike – John Walsh, Field CTO, IGEL Technology . |
 | 09:40 As OT/IoT systems become more connected, securing Industrial Networks requires more than traditional defences. Join this session to learn about the best practices for protecting critical infrastructure through Zero Trust architecture (agentless secure access, and strong identity management), why Quantum-Safe (QS) encryption is essential for future-proofing long-lifecycle industrial assets and finally how to align with standards like IEC 62443 and Bill C-8. . – John Walsh, Field CTO, IGEL Technology
|
 | 10:20 Networking Break |
 | 11:00 - Understanding OT-specific disaster recovery and incident response challenges: legacy systems, downtime costs, and cyber threats
- How we can build a comprehensive OT disaster recovery strategy aligned with IT continuity and business objectives
- Best practices for data backup, failover systems, and recovery procedures in industrial environments
- Where we can integrate automation and monitoring to detect failures early and reduce recovery time
- The lessons learned from real-world OT disaster recovery scenarios
. |
 | 11:40 - How modern leaders manage security priorities, operational resilience, and business continuity
- How best to lead cyber strategy in an evolving threat and regulatory landscape
- Where you can build trust across executives, operators, partners, and stakeholders and what the CISOs role is
- How we are preparing critical infrastructure organisations for future cyber challenges
. |
 | 12:10 - How to create a cyber security strategy that ensures security across our IT and OT environments in line with your organisations risk profile
- How you can improve your IT/OT cyber security monitoring operation
- Lessons learned from the field
. – Senior Expert, WSP |
 | 12:20 - Understand the pivotal roles IT/OT systems play in managing industrial processes
- Explore the fundamental differences between IT and OT and why these distinctions matter
- Discover vulnerabilities that OT networks face and the potential impact of cyberthreats
- Discuss how we can best communicate the risks to our board level executives to ensure effective proactive threat detection
. |
 | 12:50Lunch hosted by IGEL |
 | 13:50- How we utilised advanced risk-modeling frameworks to identify hidden third-party threats, factoring in physical plant safety, operational downtime, and strict global compliance liabilities
- Where we implemented aggressive vendor due diligence protocols, airtight service level agreements (SLAs), and component integrity audits
- How a zero-trust network boundary controls, dedicated industrial jump servers, and multi-factor authentication controls monitored third-party risk
- Where shifting culture through targeted workforce training helped to prevent a major breach
. – Timothy Feeley, Lead, OT Cyber Risk & Security, Nova Scotia Power |
 | 14:20- Practical lessons from conducting OT risk assessments in industrial environments
- Insights from hands-on experience across differing critical infrastructure sectors
- Key successes and common pitfalls in OT risk management
- Actionable takeaways to improve risk assessment processes, identify vulnerabilities, and strengthen security posture
. |
 | 14:50- How we bridged IT and OT environments to create a secure, connected foundation for industrial transformation
- What we did to enhance visibility across critical assets, networks, and operations to improve security and resilience
- How we protected converged industrial ecosystems against evolving cyber threats while enabling innovation
- Where we empowered smarter, more resilient operations through integrated security and digital capabilities
. – Razi Farooqui, OT Cyber Security Lead, Greater Toronto Airports Authority . |
 | 15:20 Learn how critical industry organisations attest for compliance. See into a process that: - Proactively contributes to threat modeling and generation of security requirements
- Enables traceability and auditability for risk and security teams
- Provides actionable guidance for developers to build products that are compliant to industry regulations and secure by design
. |
 | 15:50Networking Break |
 | 16:00. T1. Evaluating The Effectiveness of the Cloud in OT Environments – Senior Expert, Claroty . T2. Utilising Effective Tools for our Patch Management Programmes – Dragos . T3. Overcoming Burnout & Mental Health Challenges in Security Teams . |
 | 17:00 Bill C‑8, An Act Respecting Cyber Security has been given royal assent and introduces new cybersecurity obligations for critical infrastructure operators across Canada. But what does the legislation mean in practice—and how prepared is your organisation?This interactive session helps CISOs and senior security leaders navigate Bill C‑8 by clarifying which provisions apply, how key terms are defined, the anticipated implementation timeline, and the practical steps organisations should take now to prepare for its operational implementation. The discussion will focus on the protection of critical cyber systems spanning ICS, OT, IT, and AI environments, including supply‑chain considerations and the detection and reporting of cybersecurity incidents as defined under the Critical Cyber Systems Protection Act (CCSPA).Tailored for leaders in energy, transportation, telecommunications, finance and other CI sectors, participants will leave with clear takeaways, practical guidance, and a realistic view of their organisation’s readiness in an evolving threat and regulatory landscape. . |
 | 17:40Closing Remarks: Martin Laberge, Executive Cyber Security Director, CISO, Énergir |
 | 17:45Drinks Reception |
 | 19:00Dinner Hosted by Nozomi Networks (Invite Only) |