As the industrial cybersecurity community converges in Tampa, Florida for the upcoming S4x25 and BSidesICS events, there is a palpable sense of excitement and anticipation. These gatherings offer industry experts, practitioners, and thought leaders a platform to tackle the distinct challenges faced by the industrial cybersecurity sector and prepare for rising adversarial targeting.
What drives S4 and BSidesICS events is the understanding that industrial cybersecurity demands different approaches. Unlike traditional IT security, industrial and operational systems often encompass legacy infrastructure, operational technology (OT), and complex supply chains. Such events are growing to meet the needs by providing tailored content such as deep dives into OT vulnerabilities, case studies on ransomware attacks, and discussions on regulatory compliance. Speakers with hands-on experience in industrial environments are increasingly prioritized, ensuring that insights are both practical and relevant.
Collaboration is another bedrock of these activities. Industrial cybersecurity thrives on shared knowledge, and S4 and BSidesICS foster a connection between the professionals, the vendors, and the researchers. Networking opportunities have been designed in such a manner that they provoke dialogue, seed partnerships, and bridge gaps between IT and OT teams. Besides, training and mentorship are gaining momentum. It equips the attendees to face emerging threats.
It’s what people take away from events and how they apply that which is the true measure of success. Executives and professionals are finding ways to take event insights and make them into effective strategies to fortify their defenses. From adopting new technologies to refining incident response plans, it is this knowledge gained at S4 and BSidesICS that drives real change.
However, such events have been identified to lack a clear focus to produce actionable outcomes, highlighting the need for a stronger sense of community to address these unique difficulties effectively. There is also a sense that the industrial cybersecurity sector needs practical content based on real-world experience, not just theoretical ideas. Also, collaborating with communities can attract a larger, more relevant audience and offer significant benefits. This approach could turn out far more effective than hosting frequent, disjointed events with limited engagement and relevance.
As the industrial cybersecurity landscape continues to evolve, S4 and BSidesICS, for instance, have to change their approaches to respond to the professionals’ needs. The events have taken on the mantle of promoting experience-based insights, fostering collaboration, and bringing home actionable outcomes to help further advance the field and build a more secure industrial future.
Focus on driving change at S4 and BSidesICS events
Industrial Cyber consulted with industrial cybersecurity experts to understand their expectations from events like S4 and BSidesICS regarding content, speakers, and networking opportunities. They also explored how such events can contribute to driving significant change and advancement in the field of industrial cybersecurity.

“I expect these events to attract thought leaders, outside-the-box thinkers and industry experts to help push industry frameworks, best practices and regulations further using new insights and techniques,” Keon McEwen, head of solutions development for global industrial cybersecurity at Black & Veatch, told Industrial Cyber. “They will enable attendees of various experience levels to discuss the same topic and I expect will be a catalyst to have experts promote innovative ideas.”

Jonathon Gordon, directing analyst at Takepoint Research, said that the S4 and BSidesICS offer a fascinating glimpse into the evolving priorities of the industrial cybersecurity community. “These events will convene the brightest minds and most forward-thinking practitioners, creating invaluable opportunities for knowledge sharing, innovation, and a collective assessment of the year ahead.”

Mike Holcomb, a cybersecurity fellow and ICS/OT cybersecurity global lead for Fluor, said that “when I go to a conference, I want to make sure I get the value (or more) I expect for the investment of my time and money. That value comes in the form of practical and educational content, the ability to connect with others and to feel inspired when I get back to work.”
Holcomb added that conferences have the opportunity to help hundreds and thousands of people at a time to not only learn more about defending ICS/OT environments, but to strengthen bonds across the community and increase the cyber strength of the industry.

“In general, industrial security events need to bring together solution providers and end users, along with other stakeholders such as government and consultants/integrators in order to promote information sharing between all parties in order to better secure critical infrastructure,” Marty Edwards, president and CEO at SiriusPPT, told Industrial Cyber. “Technical events such as S4 and BSides differentiate themselves by providing more technical ‘bleeding edge’ content rather than other events that may be better for novices in a field.”
Perspectives on industrial cybersecurity needs at S4 and BSidesICS events
The executives explore how events such as S4 and BSidesICS more effectively tackle the distinct challenges encountered by the industrial cybersecurity community. They also consider pressing topics, innovative formats, and other potential changes that could be introduced to increase their value.
“I think the importance of OT in IT. The past has been heavily focused on IT and recently we have seen a shift to being heavily focused on OT,” McEwen said. “I think the next critical step is to converge those two topics into one that addresses the criticality of OT using the lessons learned from IT experts. This can include lessons around implementation or technology selection.”
Gordon said that the BSidesICS looks set to emphasize practical, boots-on-the-ground insights for securing OT. Sessions on incident response, ransomware in critical infrastructure, and hands-on workshops signal the urgent need to prepare for persistent, sophisticated attacks.
“I’m especially looking forward to the immersive environment, where the focus will be on actionable strategies such as network segmentation, vulnerability prioritization, and real-world incident recovery,” he added. “With attacks increasingly targeting smaller utilities and manufacturers, I’m keen to hear practical lessons learned from underfunded yet high-risk environments. Cost-effective approaches to improving resilience—even in smaller industrial enterprises—will be particularly timely.”
On the flip side, Gordon noted that S4 continues to live up to its reputation as the ‘TED Talks of OT cybersecurity.’ “The 2025 agenda promises a focus on the intersection of innovation and scalability, with topics ranging from next-gen zero trust architectures to securing AI-driven industrial processes. The emphasis on forward-looking strategies is clear.”
Holcomb identified that most ICS/OT environments don’t have big budgets to send team members to expensive conferences and training. “Conferences must deliver value, and then even more value, for what they charge attendees. Attendees need help understanding how to do their jobs more effectively while also getting help to become better ICS/OT cyber security defenders, overall better team members, leaders and a part of the community.”
He also noted a growing trend in conferences incorporating more dedicated training sessions and workshops, in addition to the usual talk format. These additions are well-received by attendees and enhance their engagement and learning experience.
Edwards observed that S4 and BSidesICS are typically oriented towards a very technical audience. “There are other events in this space that would appeal to other stakeholders. I think both S4 and BSides are well organized around their objectives.”
Collaboration key to industrial cybersecurity advancements
The executives examine the crucial importance of community engagement and collaboration in advancing industrial cybersecurity. They also explore the role that events like S4 and BSidesICS play in fostering these connections, and how training and mentorship programs fit into this equation.
“Industrial cybersecurity is impacting our culture and way of life. A massive industrial cyberattack can have consequences that can negatively affect the lives of many, our communities and the environment,” McEwen said. “The drive to include technology in helping the world advance should not be stopped due to the threat. There needs to be impactful growth in methods and techniques that are available to the industrial cybersecurity community to allow advancements in a safe manner.”
Identifying that these industry events open the door for all walks of life to come together to discuss the impacts and drivers, McEwen noted that it also fosters an atmosphere of collaboration through training and mentorship. “This collaboration is what provides the industry with new ideas and allows cross-industry adoption.”
“Collaboration amongst stakeholders is key in securing critical infrastructure. No one can secure these environments solely on their own,” Edwards said. “It takes significant public – private partnership work between governments, regulators, industry end users, original equipment manufacturers, academia, etc to make this work. It is truly a team effort. Training and other efforts certainly also play key roles in these efforts.”
Gordon pointed out that he is expecting thought leadership to revolve around the convergence of IT/OT, the promise of AI-driven anomaly detection, and the realities of harmonizing global security standards. “The spotlight on automation, software supply chain security, and digital twins echoes the wider transformation of the industrial landscape. Both events look set to underscore the necessity of stronger collaboration among vendors, OEMs, and end users.”
“Community engagement and collaboration are critical to not only advancing industrial cyber security for individuals and the field as a whole, but also in helping organizations with less mature ICS/OT cybersecurity programs ‘catch up,’” Holcomb said. “Conferences like S4 and BSidesICS act as catalysts to not only act as a home for the experts and leaders of the field to ‘hang out’ for a few days, but allow attendees to learn more while being immersed in the ICS/OT cybersecurity community which is second to none.”
Meeting evolving needs of industrial cybersecurity professionals
The executives emphasize the types of speakers and content that most effectively engage the industrial cybersecurity community. They also explore how these events can consistently provide actionable insights that address the changing needs of professionals in the field.
McEwen said that the topics that are meaningful for the industry are ones that are not the norm, those that provide alternative approaches to the same problem. “There’s also a place for industry leaders to share what has been successful and where that success is guiding them. This is why panel discussions are so relevant. They allow conversations about the same issue with different perspectives. Seeing a problem from many facets allows for a greater level of collaboration and insight. These events can promote this by having people that would not normally discuss a topic come together,” he added.
“As the industrial sector faces increasingly complex risks, partnerships and shared intelligence are critical,” Gordon said. “While S4 thrives on visionary thinking, its technical deep dives balance bold ideas with actionable guidance. Meanwhile, BSidesICS’ intimate, grassroots format ensures participants can tackle their most pressing challenges right away.”
He added that from keynotes to panels, these events are poised to highlight new voices challenging conventional thinking and advocating fresh approaches to workforce development, vendor accountability, and incident response.
Holcomb evaluates that authentic, knowledgeable, enthusiastic and inspiring speakers resonate the most with attendees. “Conferences can work to ensure that their speakers and content deliver actionable insights by making sure speakers understand that each speaker is expected to provide content that makes these available. Some conferences provide pre-made templates, or other requirements, that include at least one slide for actionable insights to help,” he added.
“Speaking more broadly now than just S4 or BSides, I believe that the various stakeholders in the industrial security community want to hear things that are relevant to them,” Edwards identified. “Although new ideas or pitches from startup companies have merit – for the most part I think the community wants and needs to hear the most efficient ways for them to implement needed security controls for their particular application in order to get ‘the most bang for the buck.’”
Power of experience-based insights in industrial cybersecurity
The executives address the importance of speakers sharing real-world experiences and case studies. They also identify specific topics or themes they hope to see addressed in keynote sessions or panel discussions.
McEwen noted that real-world experiences highlight the stress test that solutions have gone through. “They provide the due diligence that others need to know. There’s substance behind the words, backed up by implementation and field work.”
He also added topics that highlight regulation and the ways that industry experts are interpreting them. “Topics helping entry-level professionals become more proficient and topics helping the experts hone their skills. These could include themes that resonate among the industry, lessons learned from others that are putting forth the effort to challenge the status quo or have done the implementation at a big scale.”
“Real-world experiences, and case studies, not only help participants connect with the content, but at the same time, can provide lessons that are relevant to their own environments,” according to Holcomb. “Additionally, each can provide practical steps that the attendee can take back to the plant and immediately put into action.”
He added that he hoped to see more content that helps bring new blood into the ICS/OT cyber community, especially more women and other underrepresented groups. “I would also love to see more content which stresses cyber resiliency in ICS/OT and on how small- to medium-sized environments can improve their ICS/OT cyber security posture on limited budgets.”
Identifying this as imperative, Edwards noted that there are far too many ‘sales pitches’ that are product centric. “Show the community actual success stories with real world implementations and real world data from those successes. Panels can be used to have input from the wide range of stakeholders that were involved including the product vendor – but the subject matter should be solution and results based – not product based,” he added.
Highlighting need to turn event insights into industrial cybersecurity strategies
The executives explore ways for attendees to apply the knowledge and insights acquired at these events into effective strategies that enhance their organization’s industrial cybersecurity defenses.
“The one vision I have for attendees is to put the ideas to practical use. Test the information and challenge the knowledge learned. Build a home lab and test them. If possible, work on solutions at your job,” according to McEwen. “Take the ideas and knowledge back to others and share what you have learned. The further the information goes the more robust our solutions become.”
He added that sharing lessons learned and knowledge should be a cornerstone of the industrial cybersecurity community. “This is not an area where a competitive advantage exists. This is an area that helps protect the many people we call community, family and friends.”
Gordon said that looking ahead, 2025 is shaping up to be the year of scaling what works. “The industrial cybersecurity sector has matured substantially over the last decade, progressing from piecemeal solutions to integrated, strategic approaches. But with growing global attention on critical infrastructure security—driven by geopolitical tension, supply chain vulnerabilities, and high-profile attacks—our industry must remain vigilant and stay ahead of adversaries. These and similar events are vital forums for forward-thinking practitioners. I can’t wait to engage with peers, glean new insights, and contribute to the critical conversations that will shape our collective approach to industrial cybersecurity in the year to come.”
“It’s important that attendees realize that, while conferences can provide practical and educational content, as well as inspiration, it is up to the individual to take action,” according to Holcomb. “Back at the office or plant, attendees are responsible for taking the information they learned, with the connections that they made, and distill everything down to what is relevant to themselves and their environment. And then, translate that new knowledge and inspiration into action.”
Edwards concluded that if the event uses real world examples that are relevant to the attendees – then it should be simple for folks to take home and begin their journey towards implementing better cybersecurity around industrial systems.