TechnologySeptember 21, 2026

Practical Takeaways from 2026 ISA OT Cybersecurity Summit

Sensor-rich devices and the operational demands of always-on infrastructure, along with the emergence of AI, are making organizations across critical sectors rethink how they manage cyber risk. This report shows how ISA brought together regulators, engineers, vendors and policymakers to tackle some of the toughest challenges.

Sensor-rich devices and the operational demands of always-on infrastructure, along with the emergence of AI, are making organizations across critical sectors rethink how they manage cyber risk. This report shows how ISA brought together regulators, engineers, vendors and policymakers to tackle some of the toughest challenges.

With the rise of artificial intelligence, sensor-rich devices and operational demands of always-on infrastructure, organizations across critical sectors are rethinking how they manage cyber risk. The International Society of Automation (ISA) brought together regulators, engineers, vendors and policymakers to tackle some of the toughest challenges in operational technology (OT) cybersecurity at the 2026 ISA OT Cybersecurity Summit (OTCS) in Prague.

Through keynotes, forums, training sessions and in hallways and conference rooms, I saw so many great discussions bear fruit. Managing cybersecurity across connected industrial environments can often mean conflicting priorities, and I was glad to see so many people sharing their thoughts on how best to keep the world’s critical infrastructure safe and secure. I’d like to share a few of the overarching takeaways I gathered from attending and speaking at OTCS this year.

Fund and Operationalize Existing Frameworks

At the Cyber Empowerment Forum, moderated by Megan Samford, VP, Product & Supply Chain Security at Schneider Electric, Tatyana Bolton of the Operational Technology Cybersecurity Coalition identified funding and adoption, not a shortage of frameworks, as the limiting factor in OT security progress. The ISA/IEC 62443 series of standards, for example, is already widely adopted all over the world. Bolton’s recommendation was to embed baseline cybersecurity expectations directly into contracts, supply-chain relationships and industry guidance, giving asset owners, suppliers and system integrators a consistent minimum standard of care from which to work.

Build Cybersecurity into Engineering Practice

Cheri Caddy of Savannah River National Laboratory, also speaking at the Cyber Empowerment Forum, focused on the engineering workforce. Electrical, mechanical, civil, nuclear and software engineers all make design decisions that shape security posture. Caddy suggested building cyber-informed engineering education and disciplined processes into workforce development, treating cybersecurity as an engineering problem set rather than a function handled solely by IT.

Use International Cooperation as a Resilience Tool

Berta Jarošová, speaking then in her role as cyber attachée to the United States and Canada at the US Embassy of the Czech Republic, highlighted the Czech Republic’s cooperation with US agencies on ransomware notification, using rapid target identification and indicator-sharing to help defenders act before incidents escalate. Her keynote on transatlantic cyber cooperation added another point: organizations should apply the joint advisories developed by US, European, Indo-Pacific and Five Eyes partners directly to their own defenses, since these advisories provide actionable, publicly available threat intelligence. She also pointed to Prague and Brno as a growing cybersecurity ecosystem linking national cyber capabilities, universities, AI labs and industry investment.

Cybersecurity panel at the 2026 ISA OT Cybersecurity Summit (OTCS) in Prague.

Cybersecurity panel at the 2026 ISA OT Cybersecurity Summit (OTCS) in Prague.

Apply Secure-by-Design Principles Early, and Test AI

Panelists at the Cyber Empowerment Forum agreed that AI and sensors are expanding the number of systems organizations must secure. Their guidance was to apply secure-by-design principles from the earliest stages of system planning, rather than retrofitting security once systems are deployed.

As Bolton recommended, organizations should actively test how AI affects their own OT systems and client environments, since AI both strengthens defensive capability and speeds up adversary activity. The panel also recommended refreshing legacy practices such as annual risk assessments and static vulnerability scoring, and building resilient OT architectures around segmentation, secure remote access and rapid detection.

Distinguish NIS2 from CRA Before Building Compliance Plans

The European Union’s Cyber Resilience Act (CRA) remains top of mind for suppliers. At the “From Compliance to Execution” forum, moderated by Steve Mustard of au2mation, with Ilja David of Iron OT, Gustav Martin Bartel of Robert Bosch GmbH, Dr. Lukasz Kister (CRA Expert Group member, representing Honeywell) and Petr Kopřiva of BDO Consulting s.r.o., the panel’s first recommendation was to treat NIS2 and the CRA as separate instruments with distinct obligations. NIS2 governs day-to-day risk management for operators of essential and important services. The CRA governs manufacturers of digital products across the full product lifecycle, from design through end of life, requiring secure-by-default delivery and continuous vulnerability management.

Start Compliance Work with Risk Assessment, and Negotiate Security Terms

The compliance forum panelists recommended anchoring compliance work in a risk assessment, since both NIS2 and the CRA are risk-based frameworks. Organizations that base their compliance programs on actual operational risk are best-positioned to hold up to regulatory review.
Furthermore, organizations should review their procurement contracts carefully. As the panelists stated, security clauses and SLAs should be negotiated at the contract stage, and operational staff should understand those terms once contracts are signed, as well as legal teams.

Track Upcoming Legislation for Alignment

In a keynote on the operational threat environment and cyber legislation in Europe, UK Parliament CISO Mark Harbord framed cybersecurity as a matter of operational resilience, mandatory governance and supply-chain assurance. He recommended that organizations track upcoming legislation such as the UK’s forthcoming Cyber Security and Resilience Bill, which he emphasized will be more aligned with NIS2, the Digital Operational Resilience Act (DORA) and the CRA. In a world where cybersecurity is a geopolitical concern, organizations should prepare their own programs accordingly.

Build from Standards as the Foundation

As ISA’s CEO, I used my time at the podium at OTCS to point to ISA’s cybersecurity work going back to the establishment of the ISA99 committee in 2001. ISA99 developed the ISA/IEC 62443 series, which is relied upon all over the world and anchors initiatives like the ISASecure® conformity assessment and the ISA Global Cybersecurity Alliance (ISAGCA), in addition to ISA’s cybersecurity training and certification programs. I emphasized in my keynote that industrial cybersecurity depends on sustained collaboration among technology providers, asset owners, governments, educators and cybersecurity professionals. Consensus-based globally relevant standards are the foundation from which we can build a safer and more secure world.

With OT Cybersecurity, Collaboration Is Key

As the speakers at the 2026 OT Cybersecurity Summit made clear, industrial cybersecurity is now well past the point of being just a strategic concern for some distant future. Organizations need to focus on execution, and they need to do it today.

The takeaways from Prague point to a common thread: standards, workforce development, procurement practices and regulatory readiness all need to move in step as IT and OT systems continue to converge. Organizations that anchor their programs in proven standards like ISA/IEC 62443, build cybersecurity into engineering practice, test AI against their own OT environments and negotiate security expectations into contracts will be better positioned as NIS2 and CRA obligations take full effect.

With vulnerability and incident reporting requirements under the CRA now in place as of September 2026, and the 2027 deadline for full essential cybersecurity requirements quickly approaching, speakers at OTCS offered a practical roadmap. The organizations that treat these recommendations as immediate operational priorities will be those best-equipped to manage risk across an increasingly connected industrial landscape.

For anyone interested in joining these conversations around the future of OT cybersecurity, the next OTCS will be hosted in Athens, Greece 16-17 June 2027.

Claire Fallon, Chief Executive Officer, ISA

Free Subscription

Receive email with each new issue of Industrial Ethernet, plus a weekly email digest of industry news, technology features and new products. Subscribe today!

Subscribe for Free