Conference Description
Key Takeaways
- The 21st EnergySec Security AND Compliance Summit addresses cybersecurity and regulatory compliance challenges facing the energy sector
- Programme includes Monday Mini Summits for deep-dive sessions and a dual-track agenda covering security and compliance topics
- Designed for cybersecurity professionals, NERC compliance staff, OT and IT teams, risk managers, auditors, utility leaders and state regulators
- Participants may earn up to 20 Continuing Professional Education credits
- Takes place 17–19 August 2026 in Anaheim, California
Introduction
The 21st EnergySec Security AND Compliance Summit brings together cybersecurity and compliance professionals from across the energy industry for three days of focused discussion on protecting critical infrastructure. Scheduled for 17–19 August 2026 in Anaheim, California, the event serves practitioners responsible for securing operational technology environments while meeting regulatory obligations under frameworks such as NERC CIP. As grid modernisation accelerates and threat actors increasingly target utilities, the intersection of security operations and compliance programmes has become a defining challenge for the sector.
About the EnergySec Security AND Compliance Summit
EnergySec has convened this annual summit for more than two decades, establishing it as a recognised gathering point for energy sector security and compliance professionals. The event emphasises practical knowledge exchange, with sessions led by industry practitioners sharing operational experience rather than theoretical concepts alone. The 2026 programme introduces structural changes intended to offer attendees greater flexibility and depth in their learning experience.
The summit opens on Monday with Mini Summits—three-hour immersive sessions concentrating on specific topics and emerging challenges. These extended formats allow for more detailed exploration of complex subjects and direct engagement with subject matter experts. Tuesday and Wednesday follow a dual-track agenda, enabling participants to select sessions aligned with their professional focus, whether that lies primarily in security operations, compliance management, or the integration of both disciplines. A vendor track in the Expo Hall runs concurrently, providing opportunities to evaluate relevant technologies and services.
The Convergence of Security and Compliance in Energy
Energy utilities operate under a distinctive regulatory environment where cybersecurity is not merely a best practice but a mandatory requirement. The North American Electric Reliability Corporation’s Critical Infrastructure Protection standards impose specific obligations on bulk electric system operators, covering everything from electronic security perimeters to incident response planning. Meeting these requirements demands close coordination between security teams implementing technical controls and compliance staff documenting adherence and managing audit processes.
This convergence creates both operational challenges and opportunities. Security professionals must design controls that satisfy compliance requirements without introducing unnecessary complexity, while compliance teams benefit from understanding the technical realities that shape implementation decisions. The summit’s dual emphasis reflects this interdependence, recognising that effective protection of energy infrastructure requires expertise spanning both domains.
Audience and Professional Development
The summit draws a broad cross-section of energy sector professionals. Technical roles represented include cybersecurity specialists, operational technology engineers, and IT professionals working in utility environments. Compliance-focused attendees include NERC compliance staff, auditors, and risk managers responsible for maintaining regulatory standing. Leadership positions such as Chief Technology Officers, Chief Security Officers, and Chief Information Officers attend alongside programme managers, analysts, state regulators, and national laboratory personnel.
Participants may earn up to 20 Continuing Professional Education credits through attendance, supporting ongoing certification requirements for credentials commonly held in the field. This professional development component adds tangible value beyond the knowledge gained through sessions and peer discussions.
Event Format and Structure
The three-day programme balances structured learning with networking opportunities. Monday’s Mini Summits provide concentrated exploration of selected topics before the main programme begins. The dual-track format on subsequent days allows attendees to customise their experience, moving between sessions as their interests dictate. This flexibility acknowledges that professionals attending from different organisational roles will have varying priorities and knowledge gaps to address.
The combination of technical sessions, compliance-focused discussions, and vendor presentations creates multiple touchpoints for learning and connection throughout the event.

