Cette session est réservée aux membres.

Abonnez-vous ou connectez-vous pour regarder toutes les sessions GoSec.

S'abonner Connexion

Cet enregistrement n'est pas encore disponible.

Panel – Energy

GoSec 2025Panel50 minAnglais
Télécharger les ressources

À propos de cette session

Eric Rochette, CTO de GoSecure, anime un panel de responsables de la sécurité du secteur énergétique : Byron Chubbs de Newfoundland Power, David Mason de Newfoundland and Labrador Hydro, et Michael Lavroff, cofondateur du MSSP Nebiatek et ancien responsable de la sécurité chez Hilo, filiale d'Hydro-Québec. Ils décrivent leur appui sur les flux de renseignement du secteur et du gouvernement, notant que l'industrie partage bien l'information, la brèche d'un concurrent n'avantageant personne, même si le partage après un incident réel reste rare. Sur la menace interne, ils séparent la négligence courante de la coercition par la peur, extorsion et hypertrucage, plus difficile à contrer. En OT, tous insistent sur la nécessité de coupler segmentation et surveillance à une collaboration étroite avec les opérateurs, les priorités OT étant la sécurité physique et la fiabilité, non la confidentialité d'abord comme en IT. Ils citent un incident de 2025 où des acteurs ont ouvert la vanne d'un barrage norvégien via une interface exposée sur Internet. Sur l'IA, ils l'adoptent pour les usages IT et d'affaires sous gouvernance, tout en l'excluant des environnements SCADA. La session se termine sur les systèmes OT hérités et les leçons de la brèche chez Nova Scotia Power.

À retenir

  • Diversifier délibérément ses sources de renseignement sur les menaces (flux gouvernementaux, associations sectorielles, réseau de la société mère) et considérer la corroboration entre plusieurs flux comme un signal de qualité.
  • Traiter le risque interne sur deux axes : formation récurrente obligatoire avec conséquences croissantes en cas d'échecs répétés aux tests d'hameçonnage pour la négligence ordinaire, et liens plus étroits avec les forces de l'ordre et le renseignement pour la coercition par la peur comme l'extorsion ou l'influence d'acteurs étrangers.
  • Sécuriser l'OT d'abord par une surveillance non intrusive et la segmentation, mais considérer l'intégration de personnel de sécurité auprès des opérateurs et ingénieurs comme tout aussi essentielle; les priorités OT (sécurité physique, fiabilité, intégrité) diffèrent du modèle IT axé d'abord sur la confidentialité.
  • Avant d'exposer un système OT à Internet ou à l'IoT, séparer l'accès en lecture (télémétrie, niveaux d'eau) de l'accès en écriture (actions de contrôle comme ouvrir une vanne); l'incident de 2025 où une vanne de barrage norvégien a été ouverte via une interface exposée et compromise en est un exemple concret.
  • Encadrer explicitement l'adoption de l'IA plutôt que de la laisser se répandre sans gouvernance : choisir un fournisseur d'entreprise approuvé, former le personnel sur ce qu'il ne faut pas y téléverser, et garder l'IA générative hors des environnements SCADA/OT tant que la confiance et les tests ne sont pas au rendez-vous.

Conférenciers

Michael Lavroff
Michael Lavroff
Co-Fondateur de Nebiatek · Nebiatek
Mickael Lavroff is Vice President and founder of Nebiatek, where he works as a virtual Chief Information Security Officer (vCISO) for several companies. Before starting Nebiatek, Mickael led cybersecurity efforts at Hilo, a subsidiary of… Lire la suiteRéduire

Mickael Lavroff is Vice President and founder of Nebiatek, where he works as a virtual Chief Information Security Officer (vCISO) for several companies. Before starting Nebiatek, Mickael led cybersecurity efforts at Hilo, a subsidiary of Hydro-Québec focused on smart energy solutions. His role there gave him hands-on experience with the security challenges tied to critical infrastructure and connected technologies in the energy sector. Today, through Nebiatek, he helps organizations build strong, practical cybersecurity strategies that fit their day-to-day operations. His work blends technical know-how with clear governance and team awareness.

Eric Rochette
Eric Rochette
CTO · GoSecure
Eric brings over 15 years of experience in information security and currently serves as CTO for GoSecure. Over the last few years he has led the company’s professional services, which includes offerings in advisory, pentesting and operational… Lire la suiteRéduire

Eric brings over 15 years of experience in information security and currently serves as CTO for GoSecure. Over the last few years he has led the company’s professional services, which includes offerings in advisory, pentesting and operational services. With a background in information security risk assessments, cybersecurity assessment and security architecture, his strong experience in service delivery has allowed him to help structure, organize and improve the organization’s offerings and ensure the delivery of high-value services. In addition, he has served as a security advisor to numerous boards in need of strategic guidance in cybersecurity.
Prior to leading professional services at GoSecure, Mr. Rochette built and led the company’s Advisory team where he managed the delivery of a variety of assessments, audits and security architecture design projects. He started his career as a security analyst having performed a multitude of security solution implementations for private and public sector organizations.

Eric holds a degree in Computer Engineering from Montreal’s Polytechnique University.

Byron Chubbs
Byron Chubbs
VP of Engineering & Energy Supply · Newfoundland Power
Byron Chubbs is Vice President, Engineering and Energy Supply at Newfoundland Power Inc., where he leads the company’s energy supply, system planning, engineering, information technology, and cybersecurity initiatives. With nearly two decades of… Lire la suiteRéduire

Byron Chubbs is Vice President, Engineering and Energy Supply at Newfoundland Power Inc., where he leads the company’s energy supply, system planning, engineering, information technology, and cybersecurity initiatives. With nearly two decades of leadership experience in the utility sector, Byron has held senior roles across operations, customer service, and technology. His strategic oversight includes advancing cybersecurity resilience and digital infrastructure across Newfoundland Power’s operations. Byron holds a Bachelor of Engineering (Electrical) from Memorial University and has completed executive programs at Memorial’s Gardiner Institute and Harvard Business School. He serves on the Canadian Electrical Association’s Distribution Council and is currently Chair of the Board of Trade.

David Mason
David Mason
Information Security Officer · Newfoundland & Labrador Hydro
David Mason, a native Newfoundlander, leverages over 30 years of IT expertise and a career that has encompassed a wide range of duties and responsibilities. He spent 27 years with the provincial government, holding key roles through the Office of… Lire la suiteRéduire

David Mason, a native Newfoundlander, leverages over 30 years of IT expertise and a career that has encompassed a wide range of duties and responsibilities. He spent 27 years with the provincial government, holding key roles through the Office of the Chief Information Officer, including Network and Security Lead, and Information Protection Consultant. For the past six years, he has served as the Information Security Officer at Newfoundland and Labrador Hydro, where he leads Hydro’s corporate-wide cybersecurity program. David is a trusted advisor in risk evaluation with deep experience managing operational teams, implementing strategic security practices and safeguarding critical information assets across complex environments.

Ressources

Mots-clés

Autres sessions GoSec 2025

Aussi de Michael Lavroff

Sur le même thème

Ce site est enregistré sur wpml.org comme site de développement. Passez à une clé de site de production pour remove this banner.