Program Sikkerhetsfestivalen 2026

Operational Technology

Safety is No Longer Enough: Why Modern OT Risk Assessment Needs CyLOPA to Survive 2026

Tirsdag 2 · Home hotel Hammer, moen nede

EnglishDetailed 40 min

Marco Antonio Agnese

Marco Antonio Agnese

Principal OT/ICS Cybersecurity Advisor – TÜV Rheinland Safetec

Marco Antonio Porto d’Ave Agnese is a Principal OT/ICS cybersecurity advisor with more than 30 years of experience securing industrial systems across energy, maritime, FPSOs, utilities, manufacturing, and transportation. He specializes in ICS/OT network architecture, IEC 62443 SLx implementations, industrial CSMS governance, vulnerability assessments, and cyber‑physical risk analysis.

Marco has led OT security programs for organizations operating complex industrial environments such as FPSOs, offshore platforms, battery production facilities, maritime fleets, and critical infrastructure. Marco specializes in bridging process safety and cybersecurity, applying methodologies like CyLOPA to help operators understand and mitigate modern cyber‑physical risks. He currently works with TÜV Rheinland Safetec, focusing on OT security strategy, industrial risk management, and building resilience in safety‑critical operations.

David Allen

David Allen

UK OT Cyber Security Team Leader - TÜV Rheinland

David is a Chartered Engineer with over 16 years of experience specialising in Industrial Automation and Cyber Security. Throughout his career, he has played a pivotal role in every phase of project management, from initial consulting to after-care services, demonstrating a comprehensive understanding of the entire project life-cycle.

As a certified Cyber Security Specialist and course tutor for TÜV Rheinland's Cyber Security training courses, David has made significant contributions to various global sectors, including Oil & Gas, Chemicals, Energy, and Offshore assets. His expertise spans the development of network architectures, IEC-62443 compliance, Cyber Security gap and risk assessments, as well as providing governance support across numerous industrial standards and guidelines.

David has supported many high-profile companies worldwide, including BP, TANAP, SOCAR, Shell, Nexen, Uniper, RWE, Johnson Matthey, and Imperial College London, among others.

In addition to his professional achievements, David has authored and published a number of peer-reviewed papers, as he works towards becoming a known thought leader in the field of Industrial Automation and Cyber Security.

Industrial systems have become hyper connected, data driven, and dependent on digital control — yet most OT risk assessments still rely on methods built for random, unintentional failures. When a compromised PLC, sensor, or HMI can mimic a process deviation, the line between safety and cybersecurity disappears. Cyber initiated events now trigger the same cascades traditionally associated with equipment faults, but conventional LOPA cannot model attacker behavior, capability, or intent.

This session introduces CyLOPA, a specialized methodology aligned with TÜV Rheinland standards that merges cyber-threat modeling with the familiar, rigorous logic of LOPA. CyLOPA extends classical risk analysis by evaluating Security Levels (SL1–SL4), identifying vulnerabilities within control layers, and mapping cyber-initiated deviations through operational and physical consequence paths.

Through real world cases from FPSOs, offshore assets, battery factories, maritime fleets, and Nordic critical infrastructure, participants will see how cyber incidents bypass traditional safeguards — and how CyLOPA quantifies, visualizes, and prioritizes these emerging cyber physical risks. Attendees will leave equipped to meet the industrial realities of 2026 with a framework that treats cybersecurity as an integral component of process safety.

  1. Testing API Business Logic With AI Agents: What We Got Wrong First 1 · Frimurerlosjen, rom 1
  2. TeamFiltration GOes Brrr 1 · Frimurerlosjen, rom 2
  3. Internet voting in Estonia 10 · HeartBox ,Teatersalen
  4. A deeper dive in the Mjøsa uh ESA lake 10 · HeartBox, Byscenen
  5. Fra kontraktsinngåelse til exit – hvordan tilrettelegge for en gjennomførbar exit-strategi 11- Breiseth, Storlon
  6. Når risikoen er fysisk – svaret er digitalt: Navs nye verktøy for tryggere møter 2 · Home hotel Hammer, moen oppe
  7. "Du ser det ikke før du tror det" 3 · Hvelvet, Gullsalen
  8. Hvordan lykkes med tredjeparts risikostyring (TPRM)? 4 · Kommunestyresalen, Lillehammer rådhus
  9. BankID: En falsk trygghet? 5 · Kulturhuset Banken, Expedisjon
  10. Suverenitet uten digital selvskading 5 · Kulturhuset Banken, Festsalen
  11. Endringsevne i skyen: fra risiko til robusthet 5 · Kulturhuset Banken, Holbøsalen
  12. Analyzing Ransomware Exfiltration Infrastructure 5 · Kulturhuset Banken, Kafeen
  13. Å bygge sikkerhet fra dag en: Styringssystem og sikkerhetsorganisasjon i et nytt direktorat 6 · Lillehammer kino, sal 2
  14. Å styre det usynlige: psykososial risiko i sikkerhetsarbeidet 6 · Lillehammer kino, sal 4
  15. Når angrepet er ekte nok: Lærdom fra TIBER‑NO 9 · Victoria Scandic, sal 1+2
  16. Hvorfor deteksjonene dine suger og hva du kan gjøre med det 9 · Victoria Scandic, sal 3