This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Panel – Energy

GoSec 2025Panel50 minEnglish
Download resources

About this session

Eric Rochette, CTO of GoSecure, moderates a panel of energy-sector security leaders: Byron Chubbs of Newfoundland Power, David Mason of Newfoundland and Labrador Hydro, and Michael Lavroff, co-founder of MSSP Nebiatek and former head of security at Hilo, a Hydro-Québec smart-energy subsidiary. They describe leaning on utility-sector and government threat feeds, noting the industry shares intelligence unusually well since a competitor's breach helps no one, though sharing specifics after an incident remains rare. On insider threat, they separate everyday negligence from harder fear-based coercion, extortion and deepfake impersonation. On OT security, all stress that segmentation and monitoring must pair with close collaboration with operators, since OT priorities are safety and reliability, not IT's confidentiality-first model. They cite a 2025 incident where actors opened a Norwegian dam's floodgate through an internet-exposed HMI as a warning for industrial IoT. On AI, they embrace it for IT and business use under governance, while ruling it out inside SCADA environments for now. The session closes with questions on legacy OT systems and lessons from the 2025 Nova Scotia Power breach.

Key takeaways

  • Diversify threat intelligence sources deliberately (government feeds, sector associations, parent-company networks) and treat corroboration across multiple feeds as a quality signal.
  • Address insider risk on two tracks: mandatory recurring training with escalating consequences for repeated phishing failures for ordinary negligence, and closer ties with law enforcement/intelligence agencies for fear-based coercion like extortion or foreign-actor influence.
  • Secure OT primarily through non-intrusive monitoring and segmentation, but treat embedding security staff with operators and engineers as equally essential; OT priorities (safety, reliability, integrity) are not the same as IT's confidentiality-first model.
  • Before exposing any OT system to the internet or IoT, separate 'read' access (telemetry, water levels) from 'write' access (control actions like opening a gate); the 2025 Norwegian dam floodgate incident, caused by a compromised internet-exposed HMI, is a concrete cautionary case.
  • Govern AI adoption explicitly rather than letting it spread unmanaged: pick an approved corporate provider, train staff on what not to upload, and keep generative AI out of SCADA/OT environments until trust and testing catch up.

Speakers

Michael Lavroff
Michael Lavroff
Co-Fondateur de Nebiatek · Nebiatek
Mickael Lavroff is Vice President and founder of Nebiatek, where he works as a virtual Chief Information Security Officer (vCISO) for several companies. Before starting Nebiatek, Mickael led cybersecurity efforts at Hilo, a subsidiary of… Read moreRead less

Mickael Lavroff is Vice President and founder of Nebiatek, where he works as a virtual Chief Information Security Officer (vCISO) for several companies. Before starting Nebiatek, Mickael led cybersecurity efforts at Hilo, a subsidiary of Hydro-Québec focused on smart energy solutions. His role there gave him hands-on experience with the security challenges tied to critical infrastructure and connected technologies in the energy sector. Today, through Nebiatek, he helps organizations build strong, practical cybersecurity strategies that fit their day-to-day operations. His work blends technical know-how with clear governance and team awareness.

Eric Rochette
Eric Rochette
CTO · GoSecure
Eric brings over 15 years of experience in information security and currently serves as CTO for GoSecure. Over the last few years he has led the company’s professional services, which includes offerings in advisory, pentesting and operational… Read moreRead less

Eric brings over 15 years of experience in information security and currently serves as CTO for GoSecure. Over the last few years he has led the company’s professional services, which includes offerings in advisory, pentesting and operational services. With a background in information security risk assessments, cybersecurity assessment and security architecture, his strong experience in service delivery has allowed him to help structure, organize and improve the organization’s offerings and ensure the delivery of high-value services. In addition, he has served as a security advisor to numerous boards in need of strategic guidance in cybersecurity.
Prior to leading professional services at GoSecure, Mr. Rochette built and led the company’s Advisory team where he managed the delivery of a variety of assessments, audits and security architecture design projects. He started his career as a security analyst having performed a multitude of security solution implementations for private and public sector organizations.

Eric holds a degree in Computer Engineering from Montreal’s Polytechnique University.

Byron Chubbs
Byron Chubbs
VP of Engineering & Energy Supply · Newfoundland Power
Byron Chubbs is Vice President, Engineering and Energy Supply at Newfoundland Power Inc., where he leads the company’s energy supply, system planning, engineering, information technology, and cybersecurity initiatives. With nearly two decades of… Read moreRead less

Byron Chubbs is Vice President, Engineering and Energy Supply at Newfoundland Power Inc., where he leads the company’s energy supply, system planning, engineering, information technology, and cybersecurity initiatives. With nearly two decades of leadership experience in the utility sector, Byron has held senior roles across operations, customer service, and technology. His strategic oversight includes advancing cybersecurity resilience and digital infrastructure across Newfoundland Power’s operations. Byron holds a Bachelor of Engineering (Electrical) from Memorial University and has completed executive programs at Memorial’s Gardiner Institute and Harvard Business School. He serves on the Canadian Electrical Association’s Distribution Council and is currently Chair of the Board of Trade.

David Mason
David Mason
Information Security Officer · Newfoundland & Labrador Hydro
David Mason, a native Newfoundlander, leverages over 30 years of IT expertise and a career that has encompassed a wide range of duties and responsibilities. He spent 27 years with the provincial government, holding key roles through the Office of… Read moreRead less

David Mason, a native Newfoundlander, leverages over 30 years of IT expertise and a career that has encompassed a wide range of duties and responsibilities. He spent 27 years with the provincial government, holding key roles through the Office of the Chief Information Officer, including Network and Security Lead, and Information Protection Consultant. For the past six years, he has served as the Information Security Officer at Newfoundland and Labrador Hydro, where he leads Hydro’s corporate-wide cybersecurity program. David is a trusted advisor in risk evaluation with deep experience managing operational teams, implementing strategic security practices and safeguarding critical information assets across complex environments.

Resources

Tags

More from GoSec 2025

Also from Michael Lavroff

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.