This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Cybersecurity for the IT and OT Environments

Download resources

About this session

An OT/IT security consultant argues that almost every sector, from mining and food production to healthcare research and financial services, touches Canada's critical infrastructure, whether or not the people working in it realize it. She traces how Industry 4.0 automation, digital twins, and physical AI are pulling previously air-gapped operational technology onto the internet, widening the threat surface just as nation-state actors build malware purpose-built for OT. She walks through recurring causes of OT vulnerability: weak vendor supply chains, unknown asset inventories, default configurations, and remote access that spreads control weaknesses outward from head office. Rather than porting IT security programs wholesale into OT, she recommends a dedicated OT risk program built around understanding the environment and its specific threat landscape, engaging OT-specialist experts instead of promoting IT staff into the role, and starting with foundational controls even at organizations that have none in place. Audience questions cover Bill C-26, provincial reporting requirements such as Ontario's OCSF, and how to handle legacy assets that genuinely cannot be patched: isolate and document the exception rather than force an upgrade.

Digitization in the manufacturing sector, rise of smart factories and the desire for AI and automation is pressing the need for a concrete Cybersecurity plan addressing the IT/OT threats facing our critical infrastructure and Canada's leading industries. Talk addresses the following: Production-safe assessments Sustainable Security Risk Management Practices across the enterprise Support from the Canadian Government Security compliance challenges Factory 4.0 Technologies IT OT Convergence

Key takeaways

  • Map whether your organization touches critical infrastructure directly or indirectly (energy, finance, healthcare research, food, mining, transportation) before assuming it doesn't apply to you.
  • Treat vendors as accountable for OT product security from concept to operation; ask for proof of compliance rather than accepting a checkbox certificate.
  • Build a dedicated OT risk management program instead of porting IT frameworks over; start by understanding the actual assets and threat landscape before implementing controls.
  • Bring in OT-specialist security expertise rather than reassigning IT security staff without training, since the two environments tolerate downtime and testing very differently.
  • When a legacy asset genuinely cannot be patched, document a formal risk exception and compensate with isolation and perimeter controls instead of forcing an upgrade.

Speakers

Sarah Qureshi
Sarah Qureshi
Director Cybersecurity · QSI Security
Sarah Qureshi is a globally recognized Cybersecurity expert with demonstrated success in leading investigations during high-profile breach situations and achieving resilience against cyber attacks targeting Canada’s critical infrastructure. Ms… Read moreRead less

Sarah Qureshi is a globally recognized Cybersecurity expert with demonstrated success in leading investigations during high-profile breach situations and achieving resilience against cyber attacks targeting Canada’s critical infrastructure. Ms. Qureshi is a broadly experienced individual who has developed a bespoke Cybersecurity Program Implementation Framework that expedites public and private sector’s IT and OT compliance journeys. She is known for promoting a security-first culture within organizations through her enthusiasm for innovation in automation and proactive risk management. Neryl is a Cybersecurity Analyst currently serving the IT and OT sectors as a Level II SOC Analyst.

Neryl Denosta
Neryl Denosta
Cybersecurity Analyst · QSI Security

Neryl is a Cybersecurity Analyst currently serving the IT and OT sectors as a Level II SOC Analyst.

Resources

Tags

More from GoSec 2025

Also from Sarah Qureshi

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.