Conference Description
Key Takeaways
- Eighth annual summit addressing operational technology security across Asia Pacific critical infrastructure sectors
- Focus on IT/OT convergence, supply chain risk management, and industrial control system protection
- Designed for senior cybersecurity leaders from energy, utilities, manufacturing, transportation, and government
- Explores artificial intelligence and machine learning applications in industrial threat detection
- Addresses geopolitical factors influencing critical infrastructure security posture
Introduction
The CS4CA APAC Summit returns to Singapore in April 2027 for its eighth edition, bringing together senior IT and OT security professionals responsible for protecting critical infrastructure across the Asia Pacific region. As industrial environments become increasingly connected and geopolitical tensions reshape threat landscapes, the summit addresses the urgent need for integrated approaches to securing operational technology systems that underpin essential services.
Critical infrastructure operators face a complex security environment where traditional IT threats now intersect with vulnerabilities in industrial control systems. The convergence of information technology and operational technology networks has expanded the attack surface considerably, while supply chain dependencies introduce risks that extend well beyond organisational boundaries. This summit provides a forum for security leaders to examine these challenges and share practical strategies for building resilient OT ecosystems.
About This Event
CS4CA APAC (Cyber Security for Critical Assets Asia Pacific) is an executive-level summit scheduled for 6–7 April 2027 in Singapore. The event convenes over 150 senior stakeholders from organisations responsible for critical assets, including those in energy production, utilities, manufacturing, transportation, and government sectors.
The summit format combines keynote presentations, panel discussions, networking sessions, and solution showcases. This structure enables participants to engage with both strategic perspectives and technical implementations, facilitating knowledge exchange between practitioners facing similar operational challenges across different industries and geographies.
IT/OT Convergence and the Expanding Attack Surface
The integration of IT and OT environments represents one of the most significant shifts in industrial cybersecurity. Historically, operational technology systems operated in isolation, protected by air gaps and proprietary protocols. Modern industrial operations increasingly require connectivity between enterprise IT networks and production systems, enabling real-time monitoring, predictive maintenance, and operational efficiency gains.
This convergence introduces substantial security implications. OT systems often run legacy software with extended lifecycles, making patching difficult without disrupting production. The protocols used in industrial control systems were designed for reliability and safety rather than security, leaving them vulnerable when exposed to network-based threats. Security teams must now develop unified strategies that account for the distinct requirements of both IT and OT environments while maintaining the availability and safety that industrial operations demand.
The summit examines practical approaches to managing this convergence, including network segmentation strategies, secure remote access implementations for industrial control systems, and governance frameworks that bridge traditionally separate IT and OT security functions.
Supply Chain Risk and Geopolitical Considerations
Critical infrastructure security extends beyond organisational perimeters into complex supply chain relationships. Industrial environments depend on hardware, software, and services from numerous vendors, each representing potential vectors for compromise. Recent years have demonstrated how supply chain attacks can propagate through trusted update mechanisms and third-party components, affecting organisations that maintain otherwise robust security postures.
Geopolitical dynamics add another dimension to these risks. State-sponsored threat actors increasingly target critical infrastructure for espionage, disruption, and pre-positioning for potential future conflicts. Organisations must assess not only technical vulnerabilities but also the geopolitical exposure inherent in their vendor relationships and technology choices. The Asia Pacific region, with its diverse political landscape and strategic importance, faces particular challenges in navigating these considerations.
Discussions at CS4CA APAC address frameworks for evaluating supply chain risk, strategies for vendor security assessment, and approaches to building resilience against disruptions that may originate outside direct organisational control.
Artificial Intelligence in Industrial Threat Detection
The application of artificial intelligence and machine learning to industrial cybersecurity represents an evolving area of practice. OT environments generate substantial volumes of operational data, and AI-based systems can establish baselines of normal behaviour to identify anomalies that may indicate compromise or impending equipment failure.
However, deploying AI in industrial settings presents distinct challenges. False positives in production environments can trigger unnecessary shutdowns with significant operational and financial consequences. The deterministic nature of many industrial processes requires security tools that understand the difference between genuine threats and legitimate operational variations. Security teams must also consider how adversaries might attempt to evade or manipulate AI-based detection systems.
The summit explores current implementations of AI and machine learning in OT security, examining both capabilities and limitations in real-world industrial deployments.
Building Incident Response Capabilities for Industrial Environments
Incident response in OT environments differs fundamentally from IT-focused approaches. The priority in industrial settings typically centres on maintaining safe operations and preventing physical consequences rather than immediately containing and eradicating threats. Responders must understand process safety implications before taking actions that might affect production systems.
Effective OT incident response requires collaboration between cybersecurity teams, process engineers, and operations personnel. Organisations need playbooks that account for the specific characteristics of their industrial processes and the potential consequences of various response actions. Regular exercises that involve both IT security staff and OT operators help build the cross-functional coordination necessary for effective response.
CS4CA APAC facilitates the sharing of incident response practices across sectors, enabling participants to learn from experiences in different industrial contexts and adapt approaches to their own operational environments.
Who Should Attend
The summit is designed for senior professionals with responsibility for cybersecurity, IT, OT, compliance, and risk management within critical infrastructure organisations. Typical attendees hold positions such as Chief Information Security Officer, Vice President of Security, Director of OT Security, and similar leadership roles.
Relevant industries include energy generation and distribution, water and wastewater utilities, manufacturing, transportation and logistics, and government agencies with critical infrastructure responsibilities. The event is particularly valuable for professionals navigating the intersection of IT and OT security, those developing strategies for legacy system protection, and leaders seeking to benchmark their approaches against peers in similar sectors.
Solution Providers and Technology Landscape
The summit features participation from technology vendors specialising in industrial cybersecurity. Sponsors and exhibitors include Darktrace, Claroty, Honeywell, Thales, LRQA, SensorFleet, Waterfall Security, Hoxhunt, SSH, SNOC, Goldilock, OneIdentity, and Zeroport. These organisations represent various segments of the OT security market, from network monitoring and asset visibility to secure remote access and unidirectional gateway technologies.
The presence of these vendors provides attendees with opportunities to evaluate current market offerings and understand how different technologies address specific operational challenges within industrial environments.

