Session

Cybersecurity Commissioning: The OT Discipline Nobody Owns

Industrial organizations have significantly matured their approach to operational technology (OT) cybersecurity over the past decade. Manufacturers, utilities, and critical infrastructure operators perform risk assessments, deploy segmentation architectures, implement monitoring platforms, and align programs to recognized frameworks. Yet many still face the same operational problem: systems that appear “secure by design” fail to become operationalized.

The gap is rarely caused by technology alone. More often, it exists because OT cybersecurity lacks a formally owned assurance and commissioning discipline.

In industrial projects, commissioning bridges the transition between design, integration, testing, and operations. Mechanical, electrical, and safety systems are commissioned before operational handover. OT cybersecurity, however, is often treated as documentation review or post-deployment validation rather than an engineered operational assurance process.

This presentation introduces “Cybersecurity Commissioning at Scale” as a digital assurance discipline for industrial cybersecurity programs and capital projects.

The session explores why cybersecurity failures frequently emerge during integration and operational handover. Modern industrial environments involve interactions between OEM equipment, industrial networks, remote access platforms, MES systems, cloud integrations, safety systems, and operational workflows. While components may independently meet security requirements, integrated environments often introduce unmanaged trust relationships, insecure interfaces, undocumented dependencies, temporary engineering access paths, unsupported recovery assumptions, and operational workarounds not fully validated before startup.

The presentation examines how cybersecurity commissioning can establish repeatable operational acceptance criteria across the project lifecycle:

* Design validation
* Procurement requirements
* SFAT and SSAT activities
* Integration testing
* Operational readiness reviews
* Recovery and resilience validation
* Security gate reviews before handover

Rather than focusing solely on vulnerabilities or policy alignment, cybersecurity commissioning validates whether operational environments can safely and reliably function under realistic conditions while maintaining cyber resilience objectives.

Key discussion areas include:

* Cybersecurity acceptance criteria for OT
* Integrating cybersecurity into commissioning workflows
* Aligning engineering, operations, and security stakeholders
* Common failures in brownfield and greenfield projects
* Recoverability and operational resilience testing

As industrial organizations pursue digital transformation and AI-enabled infrastructure, cybersecurity can no longer remain a post-deployment validation activity. Like safety and reliability, it must become a formally engineered discipline.

Cybersecurity assurance at scale represents the next evolution in OT cybersecurity maturity.

Jagannathan Raghunathan

Director, Cyber-Physical Security @ Bureau Veritas

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top