Amanda Kollmorgan

Amanda Kollmorgan

Outrunning expectations in security, from the boardroom to the blue team.

Madison, Wisconsin, United States

Actions

Amanda Kollmorgan is the Security Architect for Veolia North America with almost twenty years of experience across federal and state government service, most recently as Deputy IT Director for the Wisconsin Department of Military Affairs and concurrently as Operations Manager of the WI Army National Guard's Defensive Cybersecurity Operations Element. That dual seat, building the compliance programs auditors sign off on while running the operations meant to survive a real attacker, taught her that the widest gaps in cyber rarely show up on paper. She has spent an equal amount of her career mentoring emerging leaders and building people-first teams as she has building architecture and running operations.

Area of Expertise

  • Business & Management
  • Energy & Basic Resources
  • Environment & Cleantech
  • Government, Social Sector & Education
  • Information & Communications Technology

Topics

  • Industrial Control Systems Cybersecurity
  • Operational Technology Security
  • Cybersecurity
  • Incident Response
  • Governance Risk and Compliance
  • Critical Infrastructure
  • Leadership
  • Leadership development
  • IT Leadership
  • Organizational Change Management
  • Organizational Strategy and IT Strategy Development
  • Organizational Development
  • Mentorship
  • Mentoring & Development Planning

The Logic Looked Fine: Reversing Safety-System Bypass in Critical Infrastructure PLCs

In 2026, Iranian-affiliated actors disrupted PLC operations across US water, energy, and local-government infrastructure, and they didn't need a new zero-day. They targeted misconfigured, internet-facing controllers, reached them with the manufacturers' own programming software, and exfiltrated device project files. CISA and the FBI then identified modification and deletion of project logic, including Rockwell Add-On Instructions, along with manipulation of HMI and SCADA display data. The changes disabled critical shutdown and alarm logic. At one US victim the malicious file kept the downstream ladder logic in place and added logic that overrode the safe-operating-parameter instructions, which meant the process kept running while the checks meant to stop it did nothing.

This talk goes through that campaign from the public reporting in joint advisory AA26-097A. I'll cover how the exposed PLCs were reached and how project files left through Studio 5000, EcoStruxure Control Expert, and TIA Portal. Most of the time goes to the reusable modules, because an AOI becomes a blind spot as soon as integrity review stops at the top-level ladder. I'll also put the display manipulation in ATT&CK for ICS terms; it reads as manipulation of view rather than loss of view, and that distinction changes what an operator can do about it. Each stage maps to the techniques the advisory cites.

The second half is defense on a normal budget. Validating running projects against known-good logic, with the AOIs and safety routines actually opened. RUN mode and programming protections where the platform has them. Monitoring the ports the advisory names. Monitored gateways in front of controllers that have no way to enforce any of this on their own. I'll finish with AA26-231A, a separate August advisory that names no actor, about AI-generated scripts targeting Siemens S7 PLCs. It lowers the effort to build the tooling, and none of the defenses above change because of it.

Rage Bait: Why women in cyber are tired of being "women in cyber"

Here's your rage bait: the way we do "women in cyber" is broken, and a lot of the people it's supposed to be helping are done pretending it isn't.

Most of us got into this to do the work. Then somewhere along the line the work came with a second job attached: being a woman in cyber. On a panel about it, in a mentorship track about it, available to talk about our gender at pretty much any event that'll have us. And the men who should be part of the actual conversation get told it isn't their room. We've been calling that inclusion. It isn't.

This talk is about the metric we got wrong. UNSCR 1325 and the Women, Peace and Security framework were never about counting how many women are in the room; the whole point was meaningful participation. So I want to make the operational case. What you bring to a security team isn't chromosomal, it's whether you can hold your end when an incident's live. Mixed teams catch more and decide better. And there's a contradiction most of us won't say out loud: we build the separation ourselves, our own events, our own tracks, our own rooms, and then we wonder why we feel stranded from the men we work next to every day.

You'll leave with a cleaner way to name individual barriers without turning identity into an obligation, a reason the men in this field are teammates and not the opposition, and something you can actually use when you get back to your org. Come for the title. Stay because you've been thinking it too.

Compliant and Compromised: Mapping the Gap Between Your Audit and Your Attacker

A clean audit and a successful breach are not contradictions; across NIS2, DORA, NIST, or CIS, they are frequently the same fiscal quarter at the same organization. This talk shows exactly where the paperwork and the adversary disagree, using evidence from environments where I both produce the compliance artifacts and run the defensive operations they describe.

We work through three control patterns that pass assessment while leaving attack paths open: account management that misses the stale service accounts enabling lateral movement, logging that meets retention requirements while nobody triages it, and configuration baselines that were true exactly once. Each is mapped to the ATT&CK techniques it fails to stop, and one gets a live demonstration: the control passes evidence collection on screen, then fails an atomic validation test sixty seconds later.

The back half is the fix: a threat-informed validation program a small team can run, with test cadence, evidence standards an adversary would respect, and the framing that keeps your auditors as allies. Attendees leave with the control-to-technique mapping and a starter test plan, regardless of which regulation is generating their paperwork.

Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills

Coaching a junior analyst. Translating between the SOC and the C-suite. Holding a team together through an incident. These are cyber skills, even if they never show up on a certification track. This talk reboots how we think about cyber culture by treating leadership, communication, and mentorship as core infrastructure rather than nice-to-haves. As the field grows more complex, the technicians who carry the work forward are the ones who also grow into collaborators, trusted advisors, and leaders.

Ctrl + Alt + Lead: Rebooting Cyber Culture with Human Skills

Target audiences: Everyone
Takeaways: Attendees will learn practical ways to foster teambuilding, conflict resolution, psychological safety, build mentorship pipelines, and communicate with clarity under pressure.
Session Description: Technical skills might open doors in IT & Cybersecurity, but leadership, communication, and mentorship sustain growth and impact. As the field becomes more complex and critical, we must rethink how we build and lead teams. This talk highlights the soft skills that turn strong technicians into effective collaborators, trusted advisors, and emerging leaders: from coaching junior analysts to translating between the SOC and the C-suite.

CypherCon 10 (2027) Sessionize Event Upcoming

March 2027 Milwaukee, Wisconsin, United States

GHI CON Sessionize Event Upcoming

December 2026

DefCamp 2026 Sessionize Event Upcoming

November 2026 Bucharest, Romania

2026 GOVIT Leadership Summit & Symposium Sessionize Event Upcoming

November 2026 Bloomington, Minnesota, United States

N00b Village Speaker Event! Sessionize Event

August 2026 Las Vegas, Nevada, United States

BSides312 2026 Sessionize Event

May 2026 Chicago, Illinois, United States

CypherCon 9 (2026) Sessionize Event

April 2026 Milwaukee, Wisconsin, United States

Amanda Kollmorgan

Outrunning expectations in security, from the boardroom to the blue team.

Madison, Wisconsin, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top