Conference Description
Key Takeaways
- Online summit addressing cybersecurity challenges specific to Critical National Infrastructure operators
- Focus on OT/IT convergence, asset visibility, and defending legacy systems connected to cloud environments
- Regulatory compliance coverage including DORA, NIS2, and the Cyber Assessment Framework
- Designed for CISOs, security architects, and compliance leaders in energy, transport, utilities, and telecommunications
- Emphasis on practical resilience strategies rather than checkbox compliance
Introduction
The e-Crime & Cybersecurity Securing CNI Summit is an online event bringing together senior cybersecurity professionals responsible for protecting Critical National Infrastructure. Aimed at CISOs, OT security analysts, and compliance leaders working in sectors such as energy, transport, and utilities, the summit addresses the operational and regulatory pressures that define CNI security today. With threat actors increasingly targeting industrial control systems and essential services, and with frameworks like NIS2 and DORA imposing stricter accountability, the timing reflects an industry grappling with how to achieve genuine resilience in complex, often legacy-dependent environments.
About This Event
The summit is structured around real-world case studies, technical sessions, and interactive discussions designed for executive-level participants. Rather than theoretical overviews, the programme prioritises actionable strategies that security leaders can apply within their own organisations. The online format enables participation from geographically dispersed teams while maintaining a focus on peer-to-peer learning and direct engagement with subject matter experts.
Notable sponsors supporting the event include Akamai, BeyondTrust, Claroty, Dragos, and Huntress, each bringing expertise in areas ranging from privileged access management to industrial cybersecurity and threat detection.
Operational Technology and Cloud Migration Challenges
A central theme of the summit is the convergence of operational technology and information technology environments. As CNI operators increasingly connect OT systems to cloud infrastructure, they inherit new attack surfaces while contending with equipment that was never designed with cybersecurity in mind. SCADA systems, industrial control networks, and legacy hardware present unique challenges for asset visibility and endpoint tracking.
Sessions explore how organisations can achieve continuous attack surface discovery across hybrid environments, implement network segmentation and zero trust architectures, and conduct penetration testing tailored to OT and SCADA systems. The practical difficulties of applying modern security controls to decades-old infrastructure receive particular attention, with discussions addressing what constitutes a realistic security posture when wholesale replacement is not feasible.
Regulatory Compliance and the Gap Between Policy and Practice
The regulatory landscape for CNI operators has grown considerably more demanding. The EU’s Digital Operational Resilience Act (DORA) imposes strict requirements on financial entities and their ICT providers, while NIS2 extends cybersecurity obligations across a broader range of essential and important entities. In the UK, the Cyber Assessment Framework provides a structured approach to evaluating organisational resilience.
The summit examines how security teams can move beyond compliance as a documentation exercise toward frameworks that deliver measurable improvements in defensive capability. This includes discussions on RegTech solutions that help automate compliance workflows and reduce the administrative burden on already stretched security teams. The recurring theme of achieving real resilience rather than superficial compliance reflects a broader industry recognition that regulatory adherence alone does not guarantee protection against sophisticated adversaries.
Threat Landscape and Defensive Technologies
Ransomware remains a persistent concern for CNI operators, where successful attacks can disrupt essential services and endanger public safety. The summit addresses defensive strategies against ransomware alongside other common threats including phishing, distributed denial-of-service attacks, and malware targeting industrial systems.
Technical sessions cover security automation through SOAR, SIEM, and EDR platforms, as well as threat intelligence integration and adversary simulation techniques. Behavioural analysis and security posture management feature as methods for identifying anomalies before they escalate into incidents. The programme acknowledges that many CNI organisations face skills shortages and resource constraints, making automation and prioritisation essential components of any viable security strategy.
Who Should Attend
The summit is designed for senior cybersecurity professionals and decision-makers within large CNI organisations, typically those with more than one thousand employees. Relevant roles include CISOs, CIOs, Heads of Information Security, Security Architects, OT Security Analysts, Compliance Managers, and SOC Managers. Attendees from energy, transport, telecommunications, utilities, and large-scale industrial operations will find the content most directly applicable to their operational contexts.
Conclusion
The e-Crime & Cybersecurity Securing CNI Summit offers a focused forum for security leaders navigating the intersection of legacy infrastructure, cloud adoption, and regulatory pressure. By emphasising practical strategies over theoretical frameworks, the event addresses the operational realities facing those responsible for keeping essential services secure in an increasingly hostile threat environment.

