Webinar Description
Key Takeaways
- Explores threat detection strategies for industrial control systems and operational technology environments
- Demonstrates Wazuh deployment architectures tailored to critical infrastructure requirements
- Covers alert development using the MITRE ATT&CK for ICS framework
- Relevant for cybersecurity professionals responsible for industrial networks and OT security
Introduction
Industrial ICS/OT Alerts with Wazuh — Detection for Critical Infrastructure is a webinar scheduled for August 2026 that addresses the growing need for specialised threat detection in industrial environments. The session targets cybersecurity practitioners working with industrial control systems and operational technology, focusing on how open-source security monitoring can be adapted for critical infrastructure protection. As attacks against industrial systems become more sophisticated and regulatory scrutiny intensifies, organisations operating critical infrastructure face mounting pressure to implement detection capabilities that account for the unique characteristics of OT networks.
About This Event
This technical webinar will be presented by Sebastián Vargas, a Wazuh Ambassador and Instructor of the Cybersecurity Diploma Program at USACH (Universidad de Santiago de Chile). The session is structured to provide both conceptual foundations and practical implementation guidance for deploying Wazuh in industrial settings. A dedicated question-and-answer segment will allow participants to explore specific deployment scenarios and technical challenges.
Why ICS/OT Detection Requires a Different Approach
Traditional IT security monitoring tools and methodologies often prove inadequate when applied directly to industrial environments. ICS and OT networks operate under fundamentally different constraints than enterprise IT infrastructure. These systems frequently run legacy protocols, require continuous availability, and cannot tolerate the latency or disruption that conventional security scanning might introduce. The webinar will examine why detection strategies must be adapted to account for these operational realities, including the prevalence of proprietary protocols, the sensitivity of real-time control processes, and the extended lifecycle of industrial equipment.
Wazuh Architecture for Industrial Environments
Wazuh is an open-source security platform that provides unified extended detection and response capabilities, including log analysis, file integrity monitoring, and threat detection. The webinar will explore how Wazuh can be architected specifically for industrial deployments, addressing considerations such as network segmentation between IT and OT zones, agent deployment on industrial endpoints, and integration with existing industrial network monitoring infrastructure. Proper architectural planning is essential to ensure that security monitoring does not compromise the availability or performance of critical control systems.
Building Detection Rules with MITRE ATT&CK for ICS
A significant portion of the session will focus on developing high-fidelity alerts using the MITRE ATT&CK for ICS framework. This specialised knowledge base catalogues adversary tactics and techniques observed in attacks against industrial control systems, providing a structured approach to threat modelling and detection engineering. By mapping Wazuh detection rules to ATT&CK for ICS techniques, security teams can build alerts that are specifically tuned to recognise behaviours associated with threats targeting industrial processes, from initial access through to manipulation of control systems.
Who Should Attend
This webinar is designed for security operations centre analysts, OT security engineers, and cybersecurity professionals responsible for protecting industrial control systems in sectors such as energy, manufacturing, water treatment, and transportation. Those evaluating open-source alternatives to commercial OT security platforms or seeking to extend existing Wazuh deployments into industrial network segments will find the content particularly relevant. Familiarity with basic security monitoring concepts and industrial network fundamentals will help participants gain maximum value from the technical discussions.

